Systems and methods are described for generating a risk score of a user based at least on groups of events related to security. In an example, a method is described that includes receiving data associated with a plurality of events, identifying a plurality of buckets, assigning each event to a bucket based at least on a type associated with the event, and computing a risk score for a user based at least on a function of the weight assigned to each bucket and a quantity of events in each bucket. In some examples, systems and methods also include providing a graphical user interface to display the risk score.
G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
2.
Contextual security behavior management and change execution
A method and a system for contextually managing and executing a change in security behavior of a target user are provided. The system extracts multiple context attributes including activity telemetry, skill, etc., from multiple external applications. The system dynamically generates one or more security behavioral models for each user based on behavior modeling criteria. The system dynamically generates a security behavior score for each user by scoring a selection of the context attributes from their security behavioral models. The system dynamically generates targeted, contextual control elements specific to a target user identified from among the users using the security behavioral models, the security behavior score, and one or more context libraries. The system dynamically renders one or more of the targeted, contextual control elements on a user device of the target user through one or more delivery channels for executing a change in the security behavior of the target user.
09 - Scientific and electric apparatus and instruments
38 - Telecommunications services
41 - Education, entertainment, sporting and cultural services
42 - Scientific, technological and industrial services, research and design
Goods & Services
Downloadable computer software for application and database integration; Downloadable educational media, namely, audio files, video recordings, multimedia files, white papers, still images, mobile apps, and graphics featuring the fields of social engineering, information security, privacy and data protection, compliance, ethics, and security awareness; Downloadable multimedia files containing artwork, text, audio, video, games, and Internet Web links relating to the fields of social engineering, information security, privacy and data protection, compliance, ethics, and security awareness; Downloadable computer software for use in data security, namely, email and data classification, email and data encryption, secure file transfer, secure automated file transfer, secure online collaboration, secure access to encrypted email and data, secure email and data management, and secure email and data backup, archive and recovery Electronic transmission of data and documents via computer terminals and electronic devices; Electronic data transmission; Telecommunication access services; Providing electronic telecommunication connections; Providing electronic transmission of secure e-mail; Providing private and secure real time electronic communication over a computer network Training services in the field of social engineering, information security, privacy and data protection, compliance, ethics, and security awareness; Training services in the field of employer implementation of training to employees Consulting services in the fields of selection, implementation and use of computer hardware and software systems for others; Software as a service (SAAS) services featuring software for use in data security, namely, email and data classification, email and data encryption, secure file transfer, secure automated file transfer, secure online collaboration, secure access to encrypted email and data, secure email and data management, and secure email and data backup, archive and recovery; Software as a service (SAAS) services featuring software for providing internet security in the form integrated security awareness training as well as simulated attacks to assess vulnerabilities; Software as a service (SAAS) services featuring software using artificial intelligence (AI) for providing adaptive and individualized learning experiences; Providing on-line non-downloadable software for training in the field of social engineering, information security, privacy and data protection, compliance, ethics, and security awareness and for simulation of security attacks and vulnerability assessments
09 - Scientific and electric apparatus and instruments
38 - Telecommunications services
41 - Education, entertainment, sporting and cultural services
42 - Scientific, technological and industrial services, research and design
Goods & Services
Downloadable computer software for application and database integration; Downloadable computer software for use in data security, namely, email and data classification, email and data encryption, secure file transfer, secure automated file transfer, secure online collaboration, secure access to encrypted email and data, secure email and data management, and secure email and data backup, archive and recovery; Downloadable educational media, namely, audio files, video recordings, multimedia files, white papers, still images, mobile apps, and graphics featuring the fields of social engineering, information security, privacy and data protection, compliance, ethics, and security awareness; Downloadable multimedia files containing artwork, text, audio, video, games, and Internet Web links relating to the fields of social engineering, information security, privacy and data protection, compliance, ethics, and security awareness Electronic data transmission; Electronic transmission of data and documents via computer terminals and electronic devices; Providing electronic telecommunication connections; Providing electronic transmission of secure e-mail; Providing private and secure real time electronic communication over a computer network; Telecommunication access services Training services in the field of social engineering, information security, privacy and data protection, compliance, ethics, and security awareness; Training services in the field of employer implementation of training to employees Consulting services in the fields of selection, implementation and use of computer hardware and software systems for others; Providing on-line non-downloadable software for training in the field of social engineering, information security, privacy and data protection, compliance, ethics, and security awareness and for simulation of security attacks and vulnerability assessments; Software as a service (SAAS) services featuring software for use in data security, namely, email and data classification, email and data encryption, secure file transfer, secure automated file transfer, secure online collaboration, secure access to encrypted email and data, secure email and data management, and secure email and data backup, archive and recovery; Software as a service (SAAS) services featuring software for providing internet security in the form integrated security awareness training as well as simulated attacks to assess vulnerabilities; Software as a service (SAAS) services featuring software using artificial intelligence (AI) for providing adaptive and individualized learning experiences
5.
Crowdsourced security awareness workflow recommendation model for improved cybersecurity of an organization
Systems and methods are described for recommendation of one or more security awareness workflows are described. One or more security awareness workflows may be deployed to deliver one or more remedial responses to one or more users in response to detection of one or more actions of the one or more users. An effectiveness of the one or more security awareness workflows are assessed and based at least on the assessment, one or more effectiveness metrics for the one or more security awareness workflows are determined. The one or more effectiveness metrics may represent the effectiveness of the one or more security awareness workflows. Based at least on the one or more effectiveness metrics, a recommendation of one or more security awareness workflow configurations may be identified.
Systems and methods are described herein for global blocklist curation based on crowdsourced indicators of compromise (IoC). One or more servers store the messages reported as suspicious into a message collection system. The server(s) classify he messages as one of clean, spam or threat. The server(s)) tag the messages responsive to the classification and determine a plurality of IoC from the messages classified and tagged as a threat. The server(s) determine one or more metrics for each of the plurality of IoC and selected, based at least on the one or more metrics, one or more of the plurality of IoC as blocklist entry (BLE) candidates.
Described herein are systems and methods for correcting one or more user aliases. One or more alias identifiers are identified by type based at least on one or more user aliases stored in an alias store, the one or more user aliases mapping the one or more alias identifiers to one or more users. Each of the one or more alias identifiers are assigned to one or more rules of a same type as the one or more alias identifiers. The one or more rules are executed against one or more user records in a user metadata store to establish a results table identifying one or more aliases by type found in the user metadata store. An alias correction table is established that identifies one or more aliases of the results table that do not match one or more user aliases and to one of flag, remove, or correct.
Systems and methods are described for security event association rule refresh. One or more rules are executed against one or more user records in a user metadata store. The one or more rules may be configured to match a security event of one or more security events with a user of one or more users using user metadata. A count is determined of a number of times a rule of the one or more rules identifies a plurality of different users. It is further determined that one of the count exceeds a first threshold or a number of the plurality of different users exceeds a second threshold. Responsive to the determination, the rule via a user interface may display a prompt to take an action to one or more of review, remove or modify the rule by a system administrator.
Described herein are systems and methods to provide for blocklist recommendations based on reported threats. In an example embodiment, a method is described for receiving a selection of one or more messages from a plurality of messages identified as threats and identifying, based at least on the one or more messages, one or more candidate blocklist entries (BLEs). The method further includes determining, based at least on the one or more candidate BLEs, a recommendation of one or more BLEs to add to a blocklist. The method includes adding, by the one or more servers, the one or more BLEs to the blocklist, where the blocklist is used by an email system to block messages that match at least the one or more BLEs on the blocklist.
Systems and methods for performing a simulated phishing attack are provided. A simulated attack server can send a simulated attack email including a unique identifier to a target. The simulated attack server can receive a reply email including the unique identifier from the target. The simulated attack server can extract the unique identifier from the reply email. The simulated attack server can determine a match between the unique identifier and an identity of the target. The simulated attack server can record a target failure, responsive to determining the match between the unique identifier and the identity of the target.
The present disclosure describes systems and methods for efficient reporting of data which includes personally identifiable information (PII) and which is collected and processed by a security awareness system. The data may be stored in a data storage system. The data may include a time stamp and queries of an historical nature may be supported. In the event that PII is removed from the data storage system, then the removal may propagate through all aspects of the data storage system, including the historical data.
Systems and methods are provided for user feedback on receiving simulated phishing communications. A method is described that includes receiving feedback from one or more users that interacted with one or more simulated phishing communications. The feedback identifies one or more reasons that the one or more users interacted with the one or more simulated phishing communications. The method further includes categorizing the feedback into one or more categories of a plurality of categories and collating the categorized feedback into one or more classifications of a plurality of classifications. The method also includes communicating a second one or more simulated phishing communications to one or more users based at least on one of the categorized feedback or the one or more classifications.
Systems and methods are described for creating event-driven orchestrated workflows with automated actions in response to security incidents. In an example, a method is described that includes receiving an indication to create a workflow for automating a response to one or more users engaging in an action associated with a security incident and receiving a selection of the action associated with the security incident from a plurality of selectable actions. The selected action is configured into the workflow and configured to trigger execution of the workflow by a user of the one or more users taking the selected action.
Systems and methods of embodiments are described of a campaign controller that establishes a model for using a plurality of types of exploits based on at least results of simulated phishing communications using those exploits, and uses the model to communicate a first simulated phishing communication to one or more devices of a user where the type of exploit used for the first simulated phishing communication is selected using the model. The campaign controller applies either artificial intelligence or machine learning to the results of simulated phishing communications to establish the model. The campaign controller selects the exploit by applying either artificial intelligence or machine learning to one or more attributes of the user and/or one or more responses from the user.
Systems and methods are provided for determining template difficulty based on user security maturity. In an example, a method includes communicating one or more simulated phishing communications to a plurality of users. Each of the users are assigned a user security maturity level of a plurality of user security maturity levels. The one or more simulated phishing communications are generated using a simulated phishing template. The method includes recording the user security maturity level of a user and a type of user interaction for each of the responses to the one or more simulated phishing communications from the users and determining, a failure rate of the simulated phishing template at each user security maturity level of the plurality of user security maturity levels based on the type of user interaction for each of the responses from one or more users assigned to each user security maturity level.
Systems and methods are described for security maturity determination. Initially, first value for security knowledge level and second value for security awareness level of a user are determined. Further, third value for security culture level of a group of the user is determined. Thereafter, fourth value of security maturity of user is determined based at least on function of first value, second value, and third value. The user is then grouped into class of users comprising one or more additional users, wherein the fourth value of security maturity of the user falls within a predetermined range of security maturity values associated with class of users, class of users comprising one or more additional users. A phish prone percentage of user is benchmarked with phish phone percentage of one of one or more additional users of class of users. The benchmarking of phish prone percentage of user is displayed.
Systems and methods are described for leveraging the knowledge and security awareness of well-informed users in an organization to protect other users and train them to identify new phishing attacks. Initially, a report of a message being suspicious may be identified and it may be determined whether message is a malicious phishing message. In an example, a well-informed user of an organization may report the message as suspicious. Further, on determining the message to be a malicious phishing message, a simulated phishing message or a template may be created. The simulated phishing message may then be communicated to one or more devices of one or more users.
System and methods are disclosed for organizations to run a test against an active directory list to see if any user-provided passwords have been part of an existing data breach. Utilizing information from such a test identifies users that have weak passwords, reused passwords or shared passwords that have been associated with an earlier breach. With this information, the organization can seek to reduce risk by training staff for this specific issue in a timely and appropriate manner to significantly reduce the risk of a future breach by those identified users. Training can be customized and targeted at those users who attempt to use passwords that have been associated with a breach (either of their own account or of another account on the same or related domain.
G06F 21/46 - Structures or tools for the administration of authentication by designing passwords or checking the strength of passwords
G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
G09B 9/00 - Simulators for teaching or training purposes
H04L 29/06 - Communication control; Communication processing characterised by a protocol
20.
SYSTEMS AND METHODS FOR CREATING AND COMMISSIONING A SECURITY AWARENESS PROGRAM
Methods, systems and apparatus for implementing a security awareness program are provided which allow a device of a security awareness system to receive attributes of an implementation of a security awareness program from an entity, such as a company. Responsive to the attributes, the device determines a configuration for each of a baseline simulated phishing campaign, electronic based training of users of the entity for security awareness and one or more subsequent simulated phishing campaigns. The device initiates execution of the baseline simulated phishing campaign to identify a percentage of users of the entity that are phish-prone.
Systems and methods are provided for performing simulated phishing attacks using social engineering indicators. One or more failure indicators can be configured in a phishing email template, and each failure indicator can be assigned a description about that failure indicator through use of a markup tag. The phishing email template containing the markup tags corresponding to the failure indicators can be stored and can be used to generate a simulated phishing email in which the one or more markup tags are removed.
H04L 51/52 - User-to-user messaging in packet-switching networks, transmitted according to store-and-forward or real-time protocols, e.g. e-mail for supporting social networking services
22.
SYSTEMS AND METHODS FOR AN ARTIFICIAL INTELLIGENCE DRIVEN SMART TEMPLATE
The present disclosure describes systems and methods for using a template for a simulated phishing campaign, A database includes a plurality of templates for simulated phishing campaigns, each template of the plurality of templates identifying a list of a plurality of types of simulated phishing communications and at least a portion of content for the simulated phishing communications. A campaign controller selects a template from the plurality of templates for a simulated phishing campaign directed to a user of a plurality of users; and communicates, to one or more devices of the user a first type of simulated phishing communication of the plurality of types of simulated phishing communications with at least the portion of content identified by the template.
Systems and methods are described for tailoring shareable content object reference model (SCORM)-compliant content to one or more users. A learning management system (LMS), configured to be SCORM-compliant, initiates shareable content object (SCO) to provide content to users. The LMS implements an instance of application programming interface (API) comprising a plurality of functions to be called by SCO during runtime to access data model elements accessible via LMS. The LMS is configured to support one or more data model elements undefined by SCORM. Further, LMS receives a call to a function of the plurality of functions of the API from SCO to access information about users. The call references a name of a data model element undefined by SCORM. The data model element identifies information about users. The LMS provides information about the users to SCO and the SCO tailors the content to the users based on the information.
The present disclosure describes systems and methods for determining a subsequent action of a simulated phishing campaign. A campaign controller identifies a starting action for a simulated phishing campaign directed to a user of a plurality of users. The simulated phishing campaign includes a plurality of actions, one or more of the plurality of actions to be determined during execution of the simulated phishing campaign The campaign controller responsive to the starting action, communicates a simulated phishing communication to one or more devices of a user. The campaign controller determines a subsequent action of the plurality of actions of the simulated phishing campaign based at least on one of a response to the simulated phishing communication received by the campaign controller or a lack of response within a predetermined time period and initiating, responsive to the determination, the subsequent action of the simulated phishing campaign.
Systems and methods are described for facilitating assessment of security awareness of a candidate prior to a decision on whether or not to hire the candidate. Security awareness of the candidate in association with an application for a job may be assessed using responses to one or more simulated phishing communications provided by the candidate. Responses to the one or more simulated phishing communications may be used to determine a risk score for the candidate. Further, the risk score for the candidate may be used to make a decision on whether or not to hire the candidate.
Methods and systems are provided for automated management of compliance training. One or more events triggered from one or more platforms that a user uses to carry out a job function is received via one or more adapters. In response to and based at least on the one or more events, a change of status of the user in the one or more platforms may be identified. Whether or not the change of status is to be allowed may be determined in each of the one or more platforms before the user completes a training. Responsive to the determination, the change of status of the user in the one or more platforms may be controlled.
The systems and methods disclose an automated effective template generation and recommendation for selection. A semantic similarity of a plurality of messages may be identified that at least meets a similarity threshold, each of the plurality of messages reported by a plurality of users as a potentially malicious message. The plurality of messages may be indexed under a common template identifier. One or more messages of the plurality of messages indexed under the common template identifier may be determined to have a report-to-reach ratio less than a report-to-reach threshold. Responsive to the determination, the one or more messages may be identified to be used for generating one or more simulated phishing templates. A recommendation of the one or more templates may be provided to a system administrator and/or a security awareness and simulation training platform to create and deliver simulated phishing messages using the templates.
Systems and methods are described for verifying whether simulated phishing communications are allowed to pass by a security system of an email system to email account of users. One or more email accounts of the email system with the security system may be identified to use for a delivery verification campaign. Further, one or more types of simulated phishing communications may be selected from a plurality of types of simulated phishing communications. The delivery verification campaign may be configured to include the selection of the one or more types of simulated phishing communications from the plurality of types of simulated phishing communications. The selected one or more types of simulated phishing communications of the delivery verification campaign may be communicated to the one or more email accounts. Further, whether or not each of the one or more types of simulated phishing communications was allowed by the security system to be received unchanged at the one or more email accounts.
Embodiments disclosed describe a security awareness system may adaptively learn the best design of a simulated phishing campaign to get a user to perform the requested actions, such as clicking a hyperlink or opening a file. In some implementations, the system may adapt an ongoing campaign based on user's responses to messages in the campaign, along with the system's learned awareness. The learning process implemented by the security awareness system can be trained by observing the behavior of other users in the same company, other users in the same industry, other users that share similar attributes, all other users of the system, or users that have user attributes that match criteria set by the system, or that match attributes of a subset of other users in the system.
H04L 29/06 - Communication control; Communication processing characterised by a protocol
G06F 21/55 - Detecting local intrusion or implementing counter-measures
G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
The present disclosure describes systems and method for performing a vulnerabilities assessment of an organization. A campaign controller executes one or more simulated phishing campaigns directed to a plurality of users of an organization, using a plurality of models determined by the campaign controller based at least on identification of the organization. The campaign controller stores to a database the results of execution of the one or more simulated phishing campaigns and based on the results, the campaign controller determines one or more vulnerabilities to phishing for the organization. In one embodiment, the campaign controller determines a percentage of the plurality of users of the organization that are phish-prone. In some embodiments, the users of the organization that are phish-prone interacted with a link of a simulated phishing communication.
Systems and methods are described for using secured groups for simulated phishing campaigns to obfuscate data for levels of privacy based on protected criteria classes. Initially, a group to resolve members of the group based on multiple users matching one or more group criteria is established. It is then determined that at least one criteria of the one or more criteria has been configured as one of multiple protected criteria classes. Responsive to the determination, the group is identified as a secured group. A query of the group is then executed to identify one or more users of the multiple users as members of the group based on the users matching the criteria of the secured group at the time of execution of the group and information of the one or more users resulting from the execution of the secured group is obfuscated in accordance with the protected criteria class.
Systems and methods are described for enrichment of breach data for security awareness training. Initially, breached credentials of a user are obtained from breach data of one or more breaches. Analysis of the breached credentials are performed and a level of risk that the breached credentials pose to the organization is determined. Thereafter, a breach score of the user is determined based at least on the level of risk. A remedial action with respect to the user is taken based at least on the breach score.
G06F 21/46 - Structures or tools for the administration of authentication by designing passwords or checking the strength of passwords
G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
33.
Systems and methods for security awareness using ad-based simulated phishing attacks
Systems and methods are described for modifying one or more advertisements of a webpage or a social media feed to create a simulated cybersecurity attack. Initially, content responsive to a request by a user via a user device to access a webpage or social media feed with one or more advertisements is received. One or more advertisements are detected within the content. An advertisement of the one or more advertisements is modified or replaced with simulated cybersecurity attack advertisements. The webpage or social media feed with the modified advertisement is displayed to the user device. User interactions with the simulated cybersecurity attack content are tracked and training is provided based on user interactions.
Systems and methods are described for providing customized message content to be displayed to a user of an email client, responsive to the user selecting, via a plug-in or agent of the email client, to report an email as a potential phishing email. In examples, the user may be an employee of an organization and the systems and methods may facilitate a determination by the plug-in or agent of the email client that the reported email is one that does not pose a security risk, such as a simulated phishing email sent by the organization itself, or an email sent from a trusted partner of the organization. The systems and methods may facilitate a customization of the message content that is displayed to the user. In examples, the customized message content may be included or specified within one or more SMTP extension headers of an SMTP email.
The systems and methods disclose creating variations of criteria for a query-based group of users. One or more criteria from a plurality of criteria available is selected to form a query to identify members of query-based group of users. Using the selected one or more criteria, query-based groups of users are generated. Each of the plurality of query-based groups of users may have a query with a variation of the selected one or more criteria. A user count data of user membership in each query-based group of the query-based groups of users is determined based at least on applying the query of each of the plurality of query-based groups of users to one or more databases. One or more of the plurality of query-based groups of users is identified as being validated for a statistical significance based at least on the user count data and the one or more criteria.
G06F 21/55 - Detecting local intrusion or implementing counter-measures
G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
The systems and methods disclose creating variations of criteria for a query-based group of users. One or more criteria from a plurality of criteria available is selected to form a query to identify members of query-based group of users. Using the selected one or more criteria, query-based groups of users are generated. Each of the plurality of query-based groups of users may have a query with a variation of the selected one or more criteria. A user count data of user membership in each query-based group of the query-based groups of users is determined based at least on applying the query of each of the plurality of query-based groups of users to one or more databases. One or more of the plurality of query-based groups of users is identified as being validated for a statistical significance based at least on the user count data and the one or more criteria.
G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
G06Q 10/06 - Resources, workflows, human or project managementEnterprise or organisation planningEnterprise or organisation modelling
Embodiments of the disclosure describe systems and methods for selecting a first group of users, which is selected to receive simulated phishing emails as part of a simulated phishing campaign, and adding users to a second group of users based upon those selected users interacting with a simulated phishing email that is part of a simulated phishing campaign; tracking the completion of remediation training related to phishing emails by users in the second group of users and receiving one or more indications that the users in the second group of users have completed remedial training; and automatically adding users, who are members of the second user group, to the first user group, to a third user group, or to a predetermined user group responsive to the one or more indications that the users in the second group of users have completed remedial training.
G06F 21/55 - Detecting local intrusion or implementing counter-measures
G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements
G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
38.
SYSTEMS AND METHODS FOR ANALYSIS OF USER BEHAVIOR TO IMPROVE SECURITY AWARENESS
Systems and methods are disclosed for analysis of user behavior data to improve security awareness. User behavior data of an organization is received from one or more agents on endpoint devices accessed by the users and using the user behavior data, one or more risk scores representative of the severity of risk associated with the user behavior of the users are determined. Based on the one or more risk scores representative of the severity of risk associated with the user behavior of the users, the behavior of the is determined to pose a security risk to the organization, In response to the determination that the user behavior of the users of the organization poses a security risk to the organization, electronic security awareness training is delivered to the users.
G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
The systems and methods disclose an automated effective template generation and recommendation for selection. A semantic similarity of a plurality of messages may be identified that at least meets a similarity threshold, each of the plurality of messages reported by a plurality of users as a potentially malicious message. The plurality of messages may be indexed under a common template identifier. One or more messages of the plurality of messages indexed under the common template identifier may be determined to have a report-to-reach ratio less than a report-to-reach threshold. Responsive to the determination, the one or more messages may be identified to be used for generating one or more simulated phishing templates. A recommendation of the one or more templates may be provided to a system administrator and/or a security awareness and simulation training platform to create and deliver simulated phishing messages using the templates.
Systems and methods are described for using a template for simulated phishing campaigns based on predetermined date from a date associated with a user. The predetermined date may by an event, an anniversary or a milestone associated with employment of the user with a company. The campaign controller may identify a date associated with the user and based on the identification of the date associated with the user, the campaign controller may select one or more templates for one or more simulated phishing campaigns to be triggered by a predetermined date related to the date associated with the user.
Systems and methods are disclosed for simulating a phishing attack involving an email thread. An email thread of a plurality of email threads of an entity for use in a simulated phishing attack is identified. A simulation system generates a converted reply simulated phishing email to an email of the email thread. The converted reply simulated phishing email is generated to be from a user that is one of a recipient or a sender of one or more emails of the email thread and is communicated to a target user's email account, the converted reply simulated phishing email.
A system and method is described that sends multiple simulated phishing emails, text messages, and/or phone calls (e.g., via VoIP) varying the quantity, frequency, type, sophistication, and combination using machine learning algorithms or other forms of artificial intelligence. In some implementations, some or all messages (email, text messages, VoIP calls) in a campaign after the first simulated phishing email, text message, or call may be used to direct the user to open the first simulated phishing email or text message, or to open the latest simulated phishing email or text message. In some implementations, simulated phishing emails, text messages, or phone calls of a campaign may be intended to lure the user to perform a different requested action, such as selecting a hyperlink in an email or text message, or returning a voice call.
09 - Scientific and electric apparatus and instruments
41 - Education, entertainment, sporting and cultural services
42 - Scientific, technological and industrial services, research and design
Goods & Services
Computer software for providing security awareness training
and tools to assist in IT risk management and regulatory
compliance, simulation of security attacks, and
vulnerability assessments to collect data on user responses
in order to assess user training necessities and test user
training progress; downloadable multimedia files containing
videos, text, images, and audio relating to security
awareness training for the prevention of security breaches
targeting protected information and access to
infrastructure. Training services in the field of security awareness for the
prevention of security breaches targeting protected
information and access to infrastructure; training services
for employer implementation of security awareness to
employees. Computer consultation in the field of computer security,
network security, network security protocols, and
cybersecurity; computer services, namely,
software-as-a-service featuring software in the field of
providing internet security in the form integrated security
awareness training as well as simulated attacks to assess
vulnerabilities; providing temporary use of on-line
non-downloadable software for security awareness training,
simulation of security attacks, and vulnerability
assessments.
44.
SYSTEM AND METHODS TO INCENTIVIZE ENGAGEMENT IN SECURITY AWARENESS TRAINING
Systems and methods to incentivize engagement in security awareness training are disclosed. The systems and methods include a user enrolling in a simulated self-phishing system that enables the user to receive simulated self-phishing communications and be scored on the user's interactions with the simulated self-phishing communications. The method includes identifying organizational information of the user, and communicating simulated self-phishing communications based at least on the organizational information of the user. The method includes receiving interaction data of the user with the simulated self-phishing communications. The method may generate a score of the user based at least on the interaction data.
Systems and methods are described for determination of indicators of malicious elements within messages. A report of a malicious message is received from a user of an organization, the malicious message having traversed an endpoint security system of the organization. After receiving the report of the malicious message, one or more indicators of one or more malicious elements of the malicious message are identified. Further, an identification of the endpoint security system and a dangerousness score of the malicious message are determined. The one or more indicators, the identification of the endpoint security system, and the dangerousness score are stored into a threat database that is able to be queried to generate an endpoint-specific threat data set.
Systems and methods for prioritization of reported messages and rewarding reporting users are disclosed. The systems and methods leverage knowledge and security awareness of the most informed users in an organization to protect an organization from serious harm from new malicious messages, give credit to the most informed users, and optimize threat triage and analysis. The system converts a reported malicious message to a defanged message. The system communicates the defanged message to a plurality of users. The system determines an impact score for the user based on interactions with the defanged message by the plurality of users, and with the impact score gives credit to the reporter and optimizes threat triage and analysis.
Systems and methods are described for detecting a simulated phishing message by an email client plug-in. A unique key is received at the email client plug-in. An indication that an email was reported by a user as a suspicious message is received at the email client plug-in. The email is a simulated phishing message having the unique key mapped by cryptographic hashing function into a hash value in a predetermined field in the header of the simulated phishing message. The presence of the predetermined field is detected and the hash value in the predetermined field is compared to a result of applying cryptographic hashing function to the unique key received by the email client plug-in. Responsive to being matched to the result, it is determined that the suspicious message is a simulated phishing message generated by a server.
H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system
48.
Systems and methods to identify a simulated phishing message
Systems and methods are described for detecting a simulated phishing message by an email client plug-in. A unique key is received at the email client plug-in. An indication that an email was reported by a user as a suspicious message is received at the email client plug-in. The email is a simulated phishing message having the unique key mapped by cryptographic hashing function into a hash value in a predetermined field in the header of the simulated phishing message. The presence of the predetermined field is detected and the hash value in the predetermined field is compared to a result of applying cryptographic hashing function to the unique key received by the email client plug-in. Responsive to being matched to the result, it is determined that the suspicious message is a simulated phishing message generated by a server.
H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system
Systems and methods are described for communication of a third-party application server with a third-party email client plug-in. The systems and the methods enable the third-party application server to provide a plug-in header contained in a message. The plug-in header may include an X-header. The X-header may be injected into the message. The plug-in installed within an email client receives the message. The plug-in is configured to process the plug-in header to identify one or more instructions to perform an action of one or more actions. The one or more instructions may relate to a property of a user and/or a property of the email client of the user. Responsive to the one or more instructions, the plug-in performs the action.
42 - Scientific, technological and industrial services, research and design
Goods & Services
Providing temporary use of non-downloadable cloud-based software for measuring the sentiments of an organization's employees towards security and benchmarking the results against industry peers
42 - Scientific, technological and industrial services, research and design
Goods & Services
Providing temporary use of non-downloadable cloud-based software for benchmarking an organization's susceptibility to cyber-attacks against industry peers
52.
Using smart groups for computer-based security awareness training systems
This disclosure describes embodiments of an improvement to the static group solution because all the administrator needs to do is specify the criteria they care about. Unlike static groups, where the administrator needs to keep track of the status of individual users and move them between static groups as their status changes, smart groups allows for automatic identification of the relevant users at the moment that action needs to be taken. This feature automates user management for the purposes of enrollment in either phishing and training campaigns. Because the smart group membership is determined as the group is about to be used for something, the smart group membership is always accurate and never outdated. The query that determines the smart group membership gets run at the time when you are about to do a campaign or perform some other action that needs to know the membership of the smart group.
H04L 29/06 - Communication control; Communication processing characterised by a protocol
G06F 9/30 - Arrangements for executing machine instructions, e.g. instruction decode
G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements
G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
G09B 19/00 - Teaching not covered by other main groups of this subclass
41 - Education, entertainment, sporting and cultural services
Goods & Services
Arranging and conducting of conferences, congresses and symposiums in the field of cybersecurity, security awareness, information security, and regulatory compliance; Organizing, arranging, and conducting virtual conferences, congresses and symposium events in the field of cybersecurity, security awareness, information security, and regulatory compliance; Providing education in the nature of video conferences in the field of cybersecurity, security awareness, information security, and regulatory compliance; Simulation-based training services in the field of cybersecurity, security awareness, information security, and regulatory compliance; Training services in the field of cybersecurity, security awareness, information security, and regulatory compliance; Training services in the field of employer implementation of cybersecurity, security awareness, information security, and regulatory compliance to employees
09 - Scientific and electric apparatus and instruments
Goods & Services
Downloadable software for simulating a ransomware attack to determine how an organization's endpoint protection software may respond in the event of an actual ransomware attack
09 - Scientific and electric apparatus and instruments
Goods & Services
Downloadable software for simulating a ransomware attack to determine how an organization's endpoint protection software may respond in the event of an actual ransomware attack
09 - Scientific and electric apparatus and instruments
41 - Education, entertainment, sporting and cultural services
Goods & Services
Downloadable mobile applications for aggregating online articles in the field of cyber security news Providing a website featuring blogs and non-downloadable publications in the nature of aggregated online articles in the field(s) of cybersecurity news
09 - Scientific and electric apparatus and instruments
41 - Education, entertainment, sporting and cultural services
Goods & Services
Downloadable mobile applications for aggregating online articles in the field of cyber security news Providing a website featuring blogs and non-downloadable publications in the nature of aggregated online articles in the field(s) of cybersecurity news
58.
Systems and methods for aida campaign controller intelligent records
Systems and methods, disclosed herein, of a campaign controller that stores information to a database about execution of multiple simulated phishing campaigns for multiple users, where each of the simulated phishing campaigns use one or more models for communicating simulated phishing communications. Based on this information, the campaign controller may determine a rate of success of the model, in causing a user to interact with a link in one of the simulated phishing campaigns, and may display the model's rate of success via a user interface.
G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
G06F 30/20 - Design optimisation, verification or simulation
Systems and methods are described for providing calendar-based simulated phishing attacks to users of an organization. Initially, a context is identified for a calendar-based simulated phishing attack directed towards a user. An electronic calendar invitation for the calendar-based simulated phishing attack is then generated using the context. Thereafter, the electronic calendar invitation may be communicated to an electronic calendar of the user.
Systems and methods are described for contextualizing a simulated phishing communication based at least on one of language and locale. Initially, a template for a simulated phishing communication is created with content in a source language. Then one or more contextual parameters for a user are identified. The one or more contextual parameters identify at least one of a target language and a target locale. The content of the simulated phishing communication is modified according to at least one of the target language and the target locale and the simulated phishing communication is communicated to one or more devices of the user with the content modified for at least one of the target language and the target locale.
The present disclosure describes a system for saving metadata on files and using attribute data files inside a computing system to enhance the ability to provide user interfaces based on actions associated with non-executable attachments like text and document files from untrusted emails, to block execution of potentially harmful executable object downloads and files based on geographic location, and to a create a prompt for users to decide whether to continue execution of potentially harmful executable object downloads and files. The system also records user behavior on reactions to suspicious applications and documents by transmitting a set of attribute data in an attribute data file corresponding to suspicious applications or documents to a server. The system interrupts execution of actions related to untrusted phishing emails in order to give users a choice on whether to proceed with actions.
G06F 21/54 - Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity, buffer overflow or preventing unwanted data erasure by adding security routines or objects to programs
G06F 11/34 - Recording or statistical evaluation of computer activity, e.g. of down time, of input/output operation
G06F 16/17 - Details of further file system functions
G06F 21/55 - Detecting local intrusion or implementing counter-measures
G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements
G06F 21/51 - Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems at application loading time, e.g. accepting, rejecting, starting or inhibiting executable software based on integrity or source reliability
42 - Scientific, technological and industrial services, research and design
Goods & Services
Software as a service (SAAS) services featuring software for automating the addition and removal of users from training in various knowledge areas, based on specified criteria
67.
System and methods for spoofed domain identification and user training
Systems and methods are disclosed that minimize ongoing risk to an organization from user behaviors which magnify the severity of a spoofed domain. Systems and method are provided which enable an entity and users of an entity to identify potential harmful domains, combining search, discovery, reporting, the generation of risk indicators, end-user risk assessments, and training into a security awareness system.
Embodiments disclosed herein describe a server, for example a security awareness server or an artificial intelligence machine learning system that establishes a job score for a user based on the user's job title. In embodiments, the vulnerability of a user to malicious cybersecurity attacks, the propensity for the user to engage with a malicious attack, and the severity of a malicious attack likely to be sent to the user and the severity of the harm to the user's organization is the user engages with the malicious attack is represented in a user risk score. The risk score for a user of a security awareness system, or for a group of users of a security awareness system, may be calculated based on one or more of a frequency score for the user, a propensity score for the user, a severity score for the user, and a job score for the user.
Embodiments disclosed herein describe a server, for example a security awareness server or an artificial intelligence machine learning system that establishes a risk score or vulnerable for a user of a security awareness system, or for a group of users of a security awareness system. The server may create a frequency score for a user, which predicts the frequency at which the user is to be hit with a malicious attack. The frequency score may be based on at least a job score, which may be represented by a value that is based on the type of job the user has, and a breach score that may be represented by a value that is based on the user's level of exposure to email.
09 - Scientific and electric apparatus and instruments
42 - Scientific, technological and industrial services, research and design
Goods & Services
Downloadable software for prompting users, after clicking a link in their email, whether they wish to proceed or abort visiting a potentially unsafe or unknown website Software as a service (SAAS) services featuring software for prompting users, after clicking a link in their email, whether they wish to proceed or abort visiting a potentially unsafe or unknown website that may be deployed throughout an organization by an administrator, allowing the administrator to view users and devices where prompts have occurred
09 - Scientific and electric apparatus and instruments
42 - Scientific, technological and industrial services, research and design
Goods & Services
Downloadable software for prompting users, after clicking a link in their email, whether they wish to proceed or abort visiting a potentially unsafe or unknown website Software as a service (SAAS) services featuring software for prompting users, after clicking a link in their email, whether they wish to proceed or abort visiting a potentially unsafe or unknown website that may be deployed throughout an organization by an administrator, allowing the administrator to view users and devices where prompts have occurred
72.
Systems and methods for situational localization of AIDA
The present disclosure describes systems and methods for using for a simulated phishing campaign, information about one or more situations of a user determined from an electronic calendar of the user, A campaign controller may identify/an electronic calendar of a user for which to direct a simulated phishing campaign, determine one or more situations of the user from information stored in the electronic calendar and select either a template from a plurality of templates or a starting action from a plurality of starting actions for the simulated phishing campaign based at least on the one or more situations of the user. The campaign controller may communicate to one or more devices of the user a simulated phishing communication based at least on the respective template or starting action.
Systems and methods are described for using secured groups for simulated phishing campaigns to obfuscate data for levels of privacy based on protected criteria classes. Initially, a group to resolve members of the group based on multiple users matching one or more group criteria is established. It is then determined that at least one criteria of the one or more criteria has been configured as one of multiple protected criteria classes. Responsive to the determination, the group is identified as a secured group. A query of the group is then executed to identify one or more users of the multiple users as members of the group based on the users matching the criteria of the secured group at the time of execution of the group and information of the one or more users resulting from the execution of the secured group is obfuscated in accordance with the protected criteria class.
09 - Scientific and electric apparatus and instruments
41 - Education, entertainment, sporting and cultural services
Goods & Services
Downloadable educational media, namely, audio files, video recordings, multimedia files, electronic publications in the nature of white papers, still images, and graphics, all in the fields of diversity, equity, and inclusion, discrimination, business ethics, workplace safety, data privacy, data protection, and employment law; Downloadable multimedia file containing artwork, text, audio, video, games, and Internet web links in the fields of diversity, equity, and inclusion, discrimination, business ethics, workplace safety, data privacy, data protection, and employment law Providing on-line training services in the fields of diversity, equity, and inclusion, discrimination, business ethics, workplace safety, data privacy, data protection, and employment law; Training services in the fields of diversity, equity, and inclusion, discrimination, business ethics, workplace safety, data privacy, data protection, and employment law
42 - Scientific, technological and industrial services, research and design
Goods & Services
Cloud computing featuring software for use in processing user-reported phishing and other suspicious emails by grouping and categorizing emails based on rules, tags, and actions
42 - Scientific, technological and industrial services, research and design
Goods & Services
Providing temporary use of a web-based software application for assessing and assisting organizations identify the controls needed to be in place for the organization to be ready for a cybersecurity compliance audit
42 - Scientific, technological and industrial services, research and design
Goods & Services
Providing on-line non-downloadable software using artificial intelligence for use by organizations to automate individualized learning experiences for its users, relating to the fields of security awareness, social engineering, information security, privacy and data protection, compliance, and ethics, that adapts to its users' specific roles, current levels of knowledge, phishing and training performance history, and various other risk factors
09 - Scientific and electric apparatus and instruments
42 - Scientific, technological and industrial services, research and design
Goods & Services
Downloadable software for building a customized security awareness program for an organization Providing temporary use of on-line non-downloadable cloud computing software for building a customized security awareness program for an organization
42 - Scientific, technological and industrial services, research and design
Goods & Services
Providing on-line non-downloadable software using artificial intelligence for use by organizations to automate individualized learning experiences for its users, relating to the fields of security awareness, social engineering, information security, privacy and data protection, compliance, and ethics, that adapts to its users' specific roles, current levels of knowledge, phishing and training performance history, and various other risk factors
09 - Scientific and electric apparatus and instruments
42 - Scientific, technological and industrial services, research and design
Goods & Services
Downloadable software for building a customized security awareness program for an organization Providing temporary use of on-line non-downloadable cloud computing software for building a customized security awareness program for an organization
09 - Scientific and electric apparatus and instruments
41 - Education, entertainment, sporting and cultural services
Goods & Services
Downloadable educational media, namely, audio files, video recordings, multimedia files, electronic publications in the nature of white papers, still images, and graphics, all in the fields of diversity, equity, and inclusion, discrimination, business ethics, workplace safety, data privacy, data protection, and employment law; Downloadable multimedia file containing artwork, text, audio, video, games, and Internet web links in the fields of diversity, equity, and inclusion, discrimination, business ethics, workplace safety, data privacy, data protection, and employment law Providing on-line training services in the fields of diversity, equity, and inclusion, discrimination, business ethics, workplace safety, data privacy, data protection, and employment law; Training services in the fields of diversity, equity, and inclusion, discrimination, business ethics, workplace safety, data privacy, data protection, and employment law
85.
Systems and methods for determining individual and group risk scores
Embodiments disclosed herein describe a server, for example a security awareness server or an artificial intelligence machine learning system that establishes a risk score or vulnerable for a user of a security awareness system, or for a group of users of a security awareness system. The server may create a frequency score for a user, which predicts the frequency at which the user is to be hit with a malicious attack. The frequency score may be based on at least a job score, which may be represented by a value that is based on the type of job the user has, and a breach score that may be represented by a value that is based on the user's level of exposure to email.
42 - Scientific, technological and industrial services, research and design
Goods & Services
Cloud computing featuring software for use in processing user-reported phishing and other suspicious emails by grouping and categorizing emails based on rules, tags, and actions
87.
Systems and methods for improving assessment of security risk based on personal internet account data
Systems and methods are described for improving assessment of security risk based on a user's personal information. Registration of personal information of a user of an organization is received at a security awareness system. Post receiving the registration of the personal information, at least one of an exposure check or a security audit of the personal information of the user is performed by the security awareness system. A personal risk score of the user is then generated or adjusted based at least on a result of one of the exposure check or the security audit.
Systems and methods are described for providing customized message content to be displayed to a user of an email client, responsive to the user selecting, via a plug-in or agent of the email client, to report an email as a potential phishing email. In examples, the user may be an employee of an organization and the systems and methods may facilitate a determination by the plug-in or agent of the email client that the reported email is one that does not pose a security risk, such as a simulated phishing email sent by the organization itself, or an email sent from a trusted partner of the organization. The systems and methods may facilitate a customization of the message content that is displayed to the user. In examples, the customized message content may be included or specified within one or more SMTP extension headers of an SMTP email.
Systems and methods are described for mitigating false positives in a simulated phishing campaign. A simulated phishing message reported to second security awareness system by a user as suspicious is received by first security awareness system. The reported message includes a link that has been followed. Link data of followed link of the reported message is held in click cache having predetermined delay. Post the predetermined delay, whether the link was followed by second security awareness system instead of being clicked by user responsive to identifying that link data in click cache corresponds to link data in link cache or internet protocol (IP) address of an entity that follows a link corresponds to IP address stored in IP cache known to be associated with second security awareness system. Responsive to determination, second security awareness system's following of link of the reported message is excluded as interaction of the user.
G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
90.
Systems and methods identifying malicious communications in multiple message stores
Systems and methods are described for identifying other instances of messages corresponding to a reported malicious message. A report of a malicious message from a user of a plurality users using a messaging system is received. Responsive to the report of the malicious message, plain text of content selected from the malicious message is provided. Thereafter, one or more segments of the plain text are selected as key content for construction of a search. A search is then executed in the messaging system for one or more other malicious messages corresponding to the reported malicious message using the selected one or more segments of the plain text with one or more match criteria or no criteria. The one or more other malicious messages corresponding to the reported malicious message are identified in the messaging system.
Systems and methods are described for using secured groups for simulated phishing campaigns to obfuscate data for levels of privacy based on protected criteria classes. Initially, a group to resolve members of the group based on multiple users matching one or more group criteria is established. It is then determined that at least one criteria of the one or more criteria has been configured as one of multiple protected criteria classes. Responsive to the determination, the group is identified as a secured group. A query of the group is then executed to identify one or more users of the multiple users as members of the group based on the users matching the criteria of the secured group at the time of execution of the group and information of the one or more users resulting from the execution of the secured group is obfuscated in accordance with the protected criteria class.
The present disclosure describes a system that notifies users regarding specific user decisions with respect to solution phishing emails. The system notifies users when users perform specific actions with respect to the untrusted phishing emails. The system pauses execution of these actions and prompts the user to confirm whether to take the actions or to revert back to review the actions. In contrast from anti-ransomware technologies which are entirely in control, the system gives the user autonomy in deciding actions relating to untrusted phishing emails. The system interrupts execution of actions related to untrusted phishing emails in order to give users a choice on whether to proceed with actions.
The present disclosure describes systems and methods for dynamically creating groups of users based on attributes for simulated phishing campaign. A campaign controller determines one or more attributes of a plurality of users during execution of a simulated phishing campaign and creates one or more groups of users during based on the identified attributes. The campaign controller selects a template to be used to execute a portion of the simulated phishing campaign for a first group of users and then communicates one or more simulated phishing communications to the first group of users according to the template. The template may identify a list of a plurality of types of simulated phishing communications (email, text or SMS message, phone call or Internet based communication) and at least a portion of the content for the simulated phishing communication.
G06F 21/55 - Detecting local intrusion or implementing counter-measures
G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
Systems and methods are described for using secured groups for simulated phishing campaigns to obfuscate data for levels of privacy based on protected criteria classes. Initially, a group to resolve members of the group based on multiple users matching one or more group criteria is established. It is then determined that at least one criteria of the one or more criteria has been configured as one of multiple protected criteria classes. Responsive to the determination, the group is identified as a secured group. A query of the group is then executed to identify one or more users of the multiple users as members of the group based on the users matching the criteria of the secured group at the time of execution of the group and information of the one or more users resulting from the execution of the secured group is obfuscated in accordance with the protected criteria class.
42 - Scientific, technological and industrial services, research and design
Goods & Services
Software as a service (SAAS) services featuring software for managing and automating an organization's compliance and audit cycles for governance, risk management, and compliance (GRC)
09 - Scientific and electric apparatus and instruments
41 - Education, entertainment, sporting and cultural services
42 - Scientific, technological and industrial services, research and design
Goods & Services
Downloadable computer software for providing security awareness training, providing tools to assist in IT risk management and regulatory compliance, providing simulation of security attacks, and providing vulnerability assessments in order to collect data on user responses, to assess user training necessities, and to test user training progress; Downloadable multimedia file containing artwork, text, audio, video, games, and Internet Web links relating to security awareness and regulatory compliance Simulation-based training services in the field of security awareness; Training services in the field of security awareness and regulatory compliance; Training services in the field of employer implementation of security awareness and regulatory compliance to employees Providing temporary use of on-line non-downloadable software for security awareness training and regulatory compliance training; Software as a service (SAAS) services featuring software for providing internet security in the form of integrated security awareness training, simulated attacks to assess vulnerabilities, and regulatory compliance training; Technological consultation in the technology field of computer security, network security, network security protocols, and cybersecurity
42 - Scientific, technological and industrial services, research and design
Goods & Services
Software as a service (SAAS) services featuring software for managing and automating an organization's compliance and audit cycles for governance, risk management, and compliance (GRC)
99.
Systems and methods of simulated phishing campaign contextualization
Systems and methods are described for contextualizing a simulated phishing communication based at least on one of language and locale. Initially, a template for a simulated phishing communication is created with content in a source language. Then one or more contextual parameters for a user are identified. The one or more contextual parameters identify at least one of a target language and a target locale. The content of the simulated phishing communication is modified according to at least one of the target language and the target locale and the simulated phishing communication is communicated to one or more devices of the user with the content modified for at least one of the target language and the target locale.
Systems and methods are described for tailoring shareable content object reference model (SCORM)-compliant content to one or more users. A learning management system (LMS), configured to be SCORM-compliant, initiates shareable content object (SCO) to provide content to users. The LMS implements an instance of application programming interface (API) comprising a plurality of functions to be called by SCO during runtime to access data model elements accessible via LMS. The LMS is configured to support one or more data model elements undefined by SCORM. Further, LMS receives a call to a function of the plurality of functions of the API from SCO to access information about users. The call references a name of a data model element undefined by SCORM. The data model element identifies information about users. The LMS provides information about the users to SCO and the SCO tailors the content to the users based on the information.