
Key takeaways
- AutoPhish is a new Adaptive platform feature that automatically assigns role- and vendor-based phishing scenarios to employees based on their role, department, and the tools they use.
- Instead of manually mapping scenarios team by team, admins choose the vendor or scenario types they want to simulate, and AutoPhish builds personalized campaigns from those selections.
- The article gives concrete examples of tailored lures: an engineer might receive a spoofed GitHub login, while someone in finance might get a fake invoice.
- Before launch, AutoPhish provides a preview with sample employees and their assigned scenarios, and admins can search for any individual employee to see exactly what will arrive in that person's inbox.
- AutoPhish is built into the existing phishing campaign creation flow, and post-launch reporting, failure handling, and remediation remain the same as for manually created campaigns.
- The feature is available now in the Adaptive platform, and current users can select AutoPhish the next time they create a phishing campaign.
For too many security teams, their phishing simulation program becomes a tedious manual chore. Someone has to decide which scenario each employee should receive, and then keep those assignments accurate as people join, switch teams, and pick up new tools. An engineer should be tested against a spoofed GitHub login while someone in finance should see a fake invoice, but matching hundreds of employees to the right scenario by hand is slow, and it goes stale the moment the org chart changes.
Today, we're launching AutoPhish: role- and vendor-based phishing scenarios that assign themselves to the right employees.
What's in AutoPhish
AutoPhish builds personalized campaigns from the vendors you want to simulate. Instead of picking scenarios one team at a time, you select the type of scenarios that matter to your organization, and AutoPhish assigns each employee scenarios that fit their role, department, and the tools they actually use.
Before anything launches, a preview shows you a sample of employees and the scenarios they're set to receive. You can search for any individual employee to see exactly what will land in their inbox, so nothing about the campaign is a surprise once it goes live.
Why It Matters
The payoff is a phishing program that's both more realistic and far less work to run. A relevant lure is a better test than a generic blast because it mirrors the kind of attack an employee is actually likely to face, which means your simulation data reflects real-world risk instead of how people react to an obviously irrelevant email.
It also removes one of the biggest recurring admin burdens in phishing simulation. Deciding who gets what, and maintaining those decisions as the org changes, used to be a manual mapping exercise across every team. Now, you set it once, and the right scenarios reach the right people on their own.
How It Fits Into Your Existing Workflow
AutoPhish lives inside the campaign creation flow you already use. When you create a new phishing campaign, you'll see an option to choose AutoPhish instead of building one manually.
Once a campaign is live, you can open it to see which employee received which scenario, just like any other campaign. Reporting and remediation are unchanged, so if an employee falls for an AutoPhish scenario, they move into the same failure and follow-up flow you already rely on.
Available Now
AutoPhish is live in the Adaptive platform today. If you're already using Adaptive, open the admin platform and choose AutoPhish the next time you create a phishing campaign. If you'd like a walkthrough, book a demo or take a tour directly in the platform.
Brian Long is the CEO & Co-Founder of Adaptive Security.
Get started with Adaptive Security
Get started