Azure Advanced Threat Protection

365 Attack Simulator in ATP vs Knowbe4 for Phish training

We have talked before about companies running internal Spear Phishing Tests internally to check if any users need training of how to spot potential attack vectors

There are a wide range of platforms to choose from

Office 365 has added Phish Simulation to their Offerings in ATP Plan 2 so we thought we would compare it to the current industry leading ( according to Gartner ) solution Knowbe4 per below

Office 365
Attack Simulator in ATP
Knowbe4
Diamond Package
Cost3.80GBP/User/Month2GBP/User/Month
LicensingPer UserWhole Organisation
Password attack campaignsYesNo
On Prem and 365 MailboxesYesYes
USB Drive TestNoYes
Video Training AccessNoYes
Phishing Reply Tracking NoYes
Templates available2100+
Vishing Security TestNoYes
Whitelisting RequiredNoYes
Users Sync NeededNoYes

Knowbe4 has a must more customisable solution for enterprises with API intergration and larger offering , however for Small Business’ wanting to add to ATP Plan 1 , the Attack Simulator ticks that box for compliance in regards to running Phish Simulations.

What is Azure Advanced Threat Protection?

We have spoken about Azure SQL Advanced Threat Protection but what about Azure's product for your onpremise enviroment

Azure Advanced Threat Protection ( AATP ) Uses AI to forward traffic from your environment and detect problems or threats on your onpremise enviroment

 

What is currently protected

  • Pass the ticket (PtT)
  • Pass the hash
  • Overpass the hash
  • Forged Privileged Attribute Certificate (PAC; MS14-068)
  • Golden ticket
  • Malicious replication
  • Directory service enumeration
  • Server Message Block (SMB) session enumeration
  • Domain Name Service (DNS) reconnaissance
  • Horizontal brute force
  • Vertical brute force
  • Skeleton key
  • Unusual protocol
  • Encryption downgrade
  • Remote execution
  • Malicious service creation

How it works

Once a license is acquired an Azure ATP Admin center will appear in your 365 Admin Portal

You create a workspace for each of your Domain Forests , enter the credentials for the domain and download the Sensor onto a domain controller. This uses the Wireshark driver to forward traffic Live to Azure for real time log Analysis 

You can then see issues live as well as schedule reports

License

Enterprise Mobility + Security (EMS) E5 at 13 Pounds / Month per User