mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-07-20 06:20:58 +03:00
- Add validated mitre_attack frontmatter to all 754 skills (286 distinct techniques), verified against MITRE ATT&CK v19.1 via the official mitreattack-python library: 0 revoked, deprecated, or invalid IDs - Curate precise per-skill technique IDs for forensics, malware-analysis, threat-intel, and red-team skills (e.g. DCSync -> T1003.006, Kerberoasting -> T1558.003, Pass-the-Ticket -> T1550.003) - Reconcile v19.1 tactic restructuring: Defense Evasion split into Stealth (TA0005) and Defense Impairment (TA0112); revoked T1562.* family and T1070.001/.002 remapped to active equivalents (T1685.*) - Normalize word-split tags across 35 skills (remove filename-derived stopword tags, add semantic cybersecurity tags) - Add api-reference.md for 3 skills that were missing it - Update README ATT&CK section with accurate v19.1 tactic distribution
106 lines
4.2 KiB
Markdown
106 lines
4.2 KiB
Markdown
---
|
|
name: implementing-anti-phishing-training-program
|
|
description: Security awareness training is the human layer of phishing defense. An
|
|
effective anti-phishing training program combines regular simulations, interactive
|
|
learning modules, metric tracking, and positiv
|
|
domain: cybersecurity
|
|
subdomain: phishing-defense
|
|
tags:
|
|
- phishing
|
|
- email-security
|
|
- social-engineering
|
|
- dmarc
|
|
- awareness
|
|
- training
|
|
- security-culture
|
|
version: '1.0'
|
|
author: mahipal
|
|
license: Apache-2.0
|
|
nist_csf:
|
|
- PR.AT-01
|
|
- DE.CM-09
|
|
- RS.CO-02
|
|
- DE.AE-02
|
|
mitre_attack:
|
|
- T1566
|
|
- T1598
|
|
- T1534
|
|
- T1036
|
|
---
|
|
# Implementing Anti-Phishing Training Program
|
|
|
|
## Overview
|
|
Security awareness training is the human layer of phishing defense. An effective anti-phishing training program combines regular simulations, interactive learning modules, metric tracking, and positive reinforcement to build a security-conscious culture. This skill covers designing, deploying, and measuring a comprehensive phishing awareness program using platforms like KnowBe4, Proofpoint Security Awareness, and open-source alternatives.
|
|
|
|
|
|
## When to Use
|
|
|
|
- When deploying or configuring implementing anti phishing training program capabilities in your environment
|
|
- When establishing security controls aligned to compliance requirements
|
|
- When building or improving security architecture for this domain
|
|
- When conducting security assessments that require this implementation
|
|
|
|
## Prerequisites
|
|
- Management buy-in and budget approval
|
|
- Security awareness training platform (KnowBe4, Proofpoint SAT, Cofense)
|
|
- Employee email list and organizational structure
|
|
- Baseline phishing susceptibility data (from initial simulation)
|
|
- Learning management system (LMS) integration capability
|
|
|
|
## Key Concepts
|
|
|
|
### Training Program Pillars
|
|
1. **Baseline Assessment**: Initial phishing simulation to measure current susceptibility
|
|
2. **Interactive Training**: Role-based modules covering phishing identification
|
|
3. **Regular Simulations**: Monthly/quarterly phishing tests with progressive difficulty
|
|
4. **Just-in-Time Learning**: Immediate training after a user fails a simulation
|
|
5. **Positive Reinforcement**: Recognition for reporting phishing correctly
|
|
6. **Metrics & Reporting**: Track improvement over time by department and role
|
|
|
|
### SANS Security Awareness Maturity Model
|
|
- **Level 1**: Non-existent - No program
|
|
- **Level 2**: Compliance-focused - Annual checkbox training
|
|
- **Level 3**: Promoting Awareness - Engaging, regular content
|
|
- **Level 4**: Long-term Sustainment - Continuous program with culture change
|
|
- **Level 5**: Metrics Framework - Risk-based measurement and optimization
|
|
|
|
## Workflow
|
|
|
|
### Step 1: Establish Baseline
|
|
- Run initial phishing simulation across all departments
|
|
- Measure click rate, submit rate, and report rate
|
|
- Identify high-risk departments and roles
|
|
|
|
### Step 2: Design Curriculum
|
|
- **General awareness**: Phishing identification basics for all employees
|
|
- **Role-specific**: Finance (BEC/wire fraud), IT (credential phishing), Executives (whaling)
|
|
- **Progressive difficulty**: Beginner, intermediate, advanced modules
|
|
- **Micro-learning**: Short (3-5 minute) frequent sessions vs. annual marathon
|
|
|
|
### Step 3: Deploy Training Platform
|
|
- Configure KnowBe4/Proofpoint SAT with organizational groups
|
|
- Set up automated enrollment workflows
|
|
- Integrate with LMS for completion tracking
|
|
- Configure reporting dashboards
|
|
|
|
### Step 4: Run Continuous Simulations
|
|
- Monthly simulations with varied scenarios
|
|
- Increase difficulty based on organizational performance
|
|
- Include diverse attack types: links, attachments, QR codes, BEC
|
|
|
|
### Step 5: Measure and Optimize
|
|
Use `scripts/process.py` to analyze training completion, simulation results, and program effectiveness over time.
|
|
|
|
## Tools & Resources
|
|
- **KnowBe4**: https://www.knowbe4.com/
|
|
- **Proofpoint Security Awareness**: https://www.proofpoint.com/us/products/security-awareness-training
|
|
- **Cofense PhishMe**: https://cofense.com/
|
|
- **SANS Security Awareness**: https://www.sans.org/security-awareness-training/
|
|
- **Terranova Security**: https://terranovasecurity.com/
|
|
|
|
## Validation
|
|
- 90%+ training completion rate across organization
|
|
- Measurable reduction in phishing click rate over 6 months
|
|
- Increase in user phishing report rate
|
|
- Department-level improvement tracking
|