{"id":249,"date":"2013-07-05T19:59:53","date_gmt":"2013-07-05T19:59:53","guid":{"rendered":"http:\/\/seattle.toorcon.net\/?p=249"},"modified":"2013-07-05T19:59:53","modified_gmt":"2013-07-05T19:59:53","slug":"building-antibodies-the-phishing-program-at-twitter","status":"publish","type":"post","link":"https:\/\/seattle.toorcon.net\/2013\/07\/05\/building-antibodies-the-phishing-program-at-twitter\/","title":{"rendered":"Building Antibodies – The Phishing program at Twitter"},"content":{"rendered":"

I run the phishing program at Twitter. It’s not just an awareness program, the intention is to actually “build an immunity” to phishing. This is somewhat of a daunting task.<\/p>\n

The numbers we’ve collected show improvements over time – we’re actually getting our employees to stop clicking things. Anyone who has ever done incident response will know – the fewer users you have running malware, the more hair you keep on your head.<\/p>\n

This is a description of how the program is built, how you can implement one of your own, how to identify datapoints to measure and how to build the antibodies that will keep more of your employees safe, and keep more malware out of your environment.<\/p>\n

Imagine a world where phishing didn’t work because everybody could recognize a phish. Sounds awesome, huh?<\/p>\n

The intention here is to build antibodies – make phishing such a big deal that employees will help each other out – save each other from phishing. We’ve reached the point where our employees are actually coding chrome extensions to spot phishing scams in their browsers because of this program, and those extensions are stopping outside malware as well.<\/p>\n

Viss<\/b>
\nDan Tentler freelances taking on Red Team and PenTest engagements. A For-Pay bad-guy, who works for the good guys.<\/p>\n","protected":false},"excerpt":{"rendered":"

I run the phishing program at Twitter. It’s not just an awareness program, the intention is to actually “build an immunity” to phishing. This is somewhat of a daunting task. The numbers we’ve collected show improvements over time – we’re actually getting our employees to stop clicking things. Anyone who has ever done incident response […]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3,4],"tags":[22,41,48],"_links":{"self":[{"href":"https:\/\/seattle.toorcon.net\/wp-json\/wp\/v2\/posts\/249"}],"collection":[{"href":"https:\/\/seattle.toorcon.net\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/seattle.toorcon.net\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/seattle.toorcon.net\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/seattle.toorcon.net\/wp-json\/wp\/v2\/comments?post=249"}],"version-history":[{"count":0,"href":"https:\/\/seattle.toorcon.net\/wp-json\/wp\/v2\/posts\/249\/revisions"}],"wp:attachment":[{"href":"https:\/\/seattle.toorcon.net\/wp-json\/wp\/v2\/media?parent=249"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/seattle.toorcon.net\/wp-json\/wp\/v2\/categories?post=249"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/seattle.toorcon.net\/wp-json\/wp\/v2\/tags?post=249"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}