cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
8165
Views
4
Helpful
8
Comments
mkorovesisduo
Level 4
Level 4

Hello everyone.

We want to let you know that Duo is discontinuing our phishing tools to focus on multi-factor authentication and device trust features and functionality. On January 20, 2020, the Phishing Campaigns tool in the Duo Admin Panel will be discontinued. On this date, Duo Access and Duo Beyond customers who purchased their subscriptions prior to November 25, 2019 will no longer be able to start new phishing campaigns from the Duo Admin Panel. The free Duo Insight phishing tool will also be disabled on January 20, 2020.

Beginning November 25, 2019, new Duo Access and Duo Beyond customers will not have access to the Duo Phishing Campaigns tool in the Duo Admin Panel. However, they may still use the free Duo Insight phishing tool if they wish.

On January 20, 2020, all data associated with Duo Phishing Campaigns and Duo Insight will become inaccessible. We encourage administrators to export or otherwise save information from their campaigns prior to this date. Additionally, beginning on this date, Duo Administrators with the Phishing Manager role will be unable to access the Duo Admin Panel. When Phishing Managers attempt to log in, they will see an error message informing them to contact their administrator. To enable Phishing Managers to administer Duo in other ways, consider having an Owner-level administrator change them to a different Administrative Role.

If you are interested in using a phishing simulator in the future, we recommend that you evaluate other services like the free, open-source Gophish to determine whether they meet your organization’s requirements.

Focusing on multi-factor authentication and device trust enables us to release and refine new features like the Device Health Application, which helps administrators control access to applications through the policy system by restricting access when devices do not meet particular security requirements.

Please let us know if you have any questions about this change.

Comments
Paul_Roberts
Level 1
Level 1

There is also a new Cisco Security Awareness Solution available -

BabbittJE
Level 1
Level 1

My firm subscribes to KnowBe4.com CyberSecurity suite. Excellent tools there to test every users in your organization. AND, they have training courses for regular users. Not too technical at all!

I don’t work for them; just a regular user myself that has been through their training courses and weekly phishing tests.

user2001
Level 1
Level 1

How can I test my users for how they respond to fraudulent DUO requests?
I know I can send a user a DUO Push but I can’t seem to modify the text that comes with the request.
I’d really like to be able to set-up a DUO test campaign that sends every user one unexpected DUO push a month and tracks who reported it as Fraud or who accepted or denied.
Is this possible? Thanks.

MtnDew213
Level 1
Level 1

@user2001 Which text are you referring to? The text that I see in the prompt is just the application name which can be configured in application settings which I assume you can just change each time.

logle
Level 1
Level 1

It’s possible to write a script to use to send pushes, phone calls, text messages, etc.
Ours allowed us to change the text and/or voice message after we set it up as an Auth API application in Duo.

jfranchetti
Level 1
Level 1

This is a good idea. A duo phishing exercise. Send it to all employees around 9AM in a Monday. See how many accept an unsolicited push.

dzagadsky
Level 1
Level 1

I’m going to second the notion that performing tests of fake Duo pushes is a good idea. Now onto brainstorming how to do it and what to call the “fake” application…

MtnDew213
Level 1
Level 1

In theory it wont be too difficult to script some authentication attempts to a system using valid fake credentials (so that the auth is successful) which are linked to real users, this then would trigger a duo prompt. Then the application name can be anything similar to applications already in place (perhaps a spacing difference to catch users off guard so it looks similar)

e.g. a very basic script that just runs though a list of user accounts and attempts to logon to a dummy ssh server which is setup to pass a duo prompt.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Quick Links