Skip to main content
There’s a myriad of services allowing you to launch simulated cyber attacks against your organization and measure its awareness of email-borne threats. To make sure that simulated emails reach the inbox of your staff, consult the documentation of a respective service and include its infrastructure, sender address, or sender domain in the Simulation lists. xorlab Security Platform will mark simulated attacks with verdict:simulation if the distinctive mark of a service is known. Log in to xorlab, navigate to Settings → Lists → Simulation, and add the distinctive mark of your simulation service to the appropriate list.
Emails matching a Simulation list entry are treated as benign, bypassing all other threat analysis. Sender address, sender domain, MTA EHLO, and x-mailer header are all values an attacker can forge, so configuring simulation matching on these increases your attack surface to impersonation. We recommend using MTA IP (regex) wherever your simulation service supports it, since the connecting IP is much harder for an attacker to spoof than a header value.