Phishing simulator
General description
In 2020, a phishing simulator was implemented within the Kaspersky ASAP platform—a system that allows organisations to assess employees’ level of information security awareness at any time. The simulator consists of a set of phishing emails of various types designed to test specific practical skills.
These emails assess a wide range of skills:
identifying phishing emails based on grammatical, semantic, and stylistic features;
recognising phishing emails through context and manipulative wording;
not sending passwords via email;
never filling in forms embedded in emails;
verifying links before clicking them;
identifying fake URLs through typos in domain names, incorrect top-level domains, and similar indicators;
never following links consisting solely of numbers;
recognising malicious attachments,
and so on.

My Role in Simulator Development
I conceived, wrote, and designed more than 200 emails for the simulator, and also edited all emails created by other authors during the project.
I also developed a number of phishing emails tailored to specific client requirements.
Examples of Emails
Fake email from Microsoft (the expiration of the OneDrive disk).

Fake email about Flash Player update.

Fake corporate email with a new evacuation plan.

Example of an email developed for a specific client — the Ministry of Defence and Aviation of Saudi Arabia (regarding a potential conflict with a neighbouring country and the need to report to mobilisation centres):
