Skip to main content
TrustRadius
KnowBe4 PhishER/PhishER Plus

KnowBe4 PhishER/PhishER Plus

Overview

What is KnowBe4 PhishER/PhishER Plus?

PhishER is presented as a lightweight Security Orchestration, Automation and Response (SOAR) platform to orchestrate threat response and manage the high volume of potentially malicious email messages reported by users. And, with automatic prioritization of emails, PhishER helps InfoSec and…

Read more
Recent Reviews

PHISHER

9 out of 10
June 22, 2024
Incentivized
We currently utilize PhishER to review emails flagged as phishing through our Phish Alert Button through KnowBe4 to determine if they are …
Continue reading

Phishing Hero!

8 out of 10
June 09, 2024
Incentivized
We use KnowBe4 PhishER with our KMSAT. KnowBe4 PhishER is basically helping us to resolve our biggest security problem and that is …
Continue reading
Read all reviews

Awards

Products that are considered exceptional by their customers based on a variety of criteria win TrustRadius awards. Learn more about the types of TrustRadius awards to make the best purchase decision. More about TrustRadius Awards

Popular Features

View all 5 features
  • Machine Learning to Prevent Incidents (64)
    9.1
    91%
  • Live Response for Rapid Remediation (65)
    8.8
    88%
  • Centralized Dashboard (75)
    8.7
    87%
  • Company-wide Incident Reporting (60)
    8.5
    85%

Reviewer Pros & Cons

View all pros & cons
Return to navigation

Pricing

View all pricing

3001-5000 Monthly Pricing Per Seat

$0.75

Cloud
per month (billed annually) per seat

2001-3000 Monthly Pricing Per Seat

$0.85

Cloud
per month (billed annually) per seat

1001-2000 Monthly Pricing Per Seat

$1.00

Cloud
per month (billed annually) per seat

Entry-level set up fee?

  • Setup fee optional
For the latest information on pricing, visithttps://www.knowbe4.com/pricing-phisher…

Offerings

  • Free Trial
  • Free/Freemium Version
  • Premium Consulting/Integration Services
Return to navigation

Features

Incident Response Platforms

Incident response (IR) platforms guide countermeasures against a security breach and deploy preplanned, automated threat responses

8.5
Avg 8.7
Return to navigation

Product Details

What is KnowBe4 PhishER/PhishER Plus?

PhishER is a light-weight SOAR platform that automatically analyzes and prioritizes reported email messages to identify and quarantine malicious emails across an organization. PhishER helps InfoSec and Security Operations teams cut through the inbox noise and respond to the most dangerous threats more quickly.


PhishER is available as a stand-alone product or as an optional add-on for KnowBe4 customers that want to automatically prioritize and manage potentially malicious messages that were reported through the KnowBe4 Phish Alert Button. PhishER Plus is an upgraded subscription level that includes all of the features from PhishER with additional enhancements and AI-validated crowdsourced data. PhishER Plus was developed to help supercharge an organization’s email security defenses. It does this by automatically blocking phishing attacks that mail filters miss.

KnowBe4 PhishER/PhishER Plus Features

Incident Response Platforms Features

  • Supported: Company-wide Incident Reporting
  • Supported: Integration with Other Security Systems
  • Supported: Centralized Dashboard
  • Supported: Machine Learning to Prevent Incidents
  • Supported: Live Response for Rapid Remediation

Additional Features

  • Supported: Automatic Message Prioritization

KnowBe4 PhishER/PhishER Plus Screenshots

Screenshot of a diagram of the PhishER Plus workflow. Reviewing the PhishER Plus workflow before getting started will provide an understanding of how it works.Screenshot of When entering the PhishER Plus platform, the first screen that appears is the Dashboard. Here, a quick overview of the PhishER Plus platform will appear.

KnowBe4 PhishER/PhishER Plus Videos

Introduction to PhishER
PhishER Plus Global Blocklist

KnowBe4 PhishER/PhishER Plus Competitors

KnowBe4 PhishER/PhishER Plus Technical Details

Deployment TypesSoftware as a Service (SaaS), Cloud, or Web-Based
Operating SystemsUnspecified
Mobile ApplicationNo
Supported CountriesGlobal

KnowBe4 PhishER/PhishER Plus Downloadables

Frequently Asked Questions

PhishER is presented as a lightweight Security Orchestration, Automation and Response (SOAR) platform to orchestrate threat response and manage the high volume of potentially malicious email messages reported by users. And, with automatic prioritization of emails, PhishER helps InfoSec and Security Operations team cut through the inbox noise and respond to the most dangerous threats more quickly.

Cofense Triage, Infosec IQ, and Proofpoint Threat Response Auto-Pull are common alternatives for KnowBe4 PhishER/PhishER Plus.

Reviewers rate Machine Learning to Prevent Incidents highest, with a score of 9.1.

The most common users of KnowBe4 PhishER/PhishER Plus are from Mid-sized Companies (51-1,000 employees).
Return to navigation

Comparisons

View all alternatives
Return to navigation

Reviews and Ratings

(176)

Attribute Ratings

Reviews

(1-25 of 72)
Companies can't remove reviews or game the system. Here's why
Score 8 out of 10
Vetted Review
Verified User
Incentivized
We use all of the above tools except for PhishFlip at this time.
PhishML is great for classifying and removing threats once reported. PhishRIP in turn gets used to pull those classified as threats from our users mailboxes and prevent incidents from occurring. Block lists are great crowdsourced preventative measures to keep known bad senders out.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
We have implemented all these features.
The PhishML has machine learning capabilities to detect and categories emails on the basis of email structure and content.
The PhishRIP are used to create a query to search the suspicious emails delivered to the end users.
The PhishFlip is used to convert a real phishing attack email to simulated phishing test to test the end users knowledge.
The KnowBe4 PhishER Blocklist helps us to send the suspicious email and domain information to our email server.
These capabilities of KnowBe4 PhishER has helped our organization a lot. KnowBe4 PhishER's PhishML feature helps us to automatically categorize the reported the emails into clean, spam or threat category.
The PhishRIP feature helps us to create a query and search any suspicious email reported by the end users and then we can quarantine all the found emails from the user inbox.
The PhishFlip feature helps us to convert a phishing email to a simulated phishing campaign to test our users knowledge that will help us to design the awareness training in a better way.
The Blocklist helps us to send the suspicious email and domain information to our email server, so that we can block those domains and emails.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
We use PhishFlip and PhishRIP when necessary.
The PhishFlip has been useful in training staff on mails that are associated with targeted attacks that made it past our other filters. This really helps to reduce the potential of a malicious mail or spear phishing attack making it to the next level.

PhishRip is very handy for the removal of similar mails across all staff mailboxes - reducing the risk of a malicious link or attachment being clicked
Score 10 out of 10
Vetted Review
Verified User
Incentivized
We have been successfully utilizing PhishER, PhishML, PhishRIP, and the blocklist. There is a noticeable time savings involved. We have yet to use Phishflip, but we will probably look into that in the future. We haven't gotten any juicy threat emails yet that would make a good template.
See above.
June 09, 2024

Phishing Hero!

Score 8 out of 10
Vetted Review
Verified User
Incentivized
We have implemented PhishML for automatic categorization of reported emails. We have PhishRIP to see how many number of other users have received the same phishing email that one user reported, so that we can quarantine all emails. PhishFlip is helping us to test our users based on a real phishing attack campaign. KnowBe4 PhishER Blocklist helping us to block suspicious email domains and senders to protect from future attacks.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
PhishER Plus is one of the best anti-phishing protection resources available to us for use. It prevents from local as well as global threats that are constantly adapting. PhishER adapts with these threats and continue to protect our company. Another great thing is that it prevents some phishing attacks before they event reach our staffs inboxes.
Saved us so much time and money as well as resources. Other products require us to have an on-site server etc to run their protection service on our network.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
We utilize PhishML, PhishRIP, and PhishER Blocklist. PhishML is a machine-learning module that helps classify each message as clean, spam, or a threat. When a message is found to be malicious, the PhishRIP module automatically quarantines identical messages from all inboxes. We just starting using PhishER Blocklist and are integrating our Microsoft 365 blocklist with our PhishER Blocklist.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
We have implemented PhishER Blocklist although we are not sure how effective it is, because there is no reporting on that. Also the Entra security dashboard regularly warns of an upcoming blocklist expiration even though this is business as usual with the PhishER Blocklist. PhishML is turned on but not really used - yet. We occasionally use PhishRIP and hardly use PhishFlip.
PhishRIP helps us to find out if a message was also sent to other users and we can remove it. For the other features we are not sure what it brings us.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
We leverage PhishML to automate the identification and remediation of known threats from our users' mailboxes. This machine learning-powered feature analyzes email patterns and content to swiftly detect and mitigate phishing attempts, malware, and other security risks, significantly reducing the likelihood of successful attacks and enhancing our overall email security posture.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
We have implemented PhishRIP to automatically isolate and "rip" malicious emails from our staff members inboxes that have bypassed mail filters.
Saved us the headache of potential security breaches through potential malicious emails that could have easily gotten through.
Scott Wagner | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User
Incentivized
We have only begun using PhishRIP, but we have some awareness of the other capabilities.
PhishRIP has allowed us to remove significant threats from all users' inboxes. This was able to be done within minutes, mitigating tons of risk.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
PhishML PhishRIP (in POC).
PhishML—We have tuned the PhishML confidence level to decipher benign emails from threats to a large extent. PhishRIP—We have successfully evaluated PhishRIP in our POC.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
We have attempted to utilize PhishRIP, but I'm not sure it's found a lot of duplicates to pull from our email. We also utilize the KnowBe4 PhishER Blocklist and PhishML. We have not turned on PhishFlip at this point.
March 15, 2024

Happy with PhishER

Score 10 out of 10
Vetted Review
Verified User
Incentivized
We use PhishRIP, PhishFlip, and PhihsER Blocklist. These tools help us keep everything in one place. PhishRIP pulls threats that were reported by users via the Phish Alert Button from other mailboxes to keep these from getting clicked on. PhishFlip helps us use real phishing emails as phishing tests. PhishER Blocklist allows us to create block entries in the same platform.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
I am currently using PhishRIP to collect and search for malicious emails. I am looking into other capabilities but am still working through onboarding myself and my team fully.
PhishRIP has helped me cut down on noise for email reporting and helps me be proactive in trying to quarnatine emails from other users inboxes
Score 10 out of 10
Vetted Review
Verified User
Incentivized
We are using PhishRip, and the blocklist capability currently. Being able to utilize the efforts of all employees to create a comprehensive blocklist has been great. The ability to search for threats and RIP them from inboxes has also been a huge help. Finding those identified threats and removing them before some users have had the chance to open them just helps with our overall protection and prevention.
Return to navigation