-
Notifications
You must be signed in to change notification settings - Fork 7
User Manual
To request access for your organisation to use phishtray. Please email research@cybsafe.com.
The Admin application is where the magic happens - here you can create, view, update, and delete records (experiments, their dependencies (such as email texts, email replies, tasks), participants and admin users).
You can log in via www.emtray.com/admin with your given credentials.
The intended audience for the following are super users (users who have full permissions on the platform).
Below, details how to add users to your organisation.
The first step into creating a user is going to emtray.com/admin, and clicking on users (or simply going to https://www.emtray.com/admin/auth/user/ ). Everything should be straightforward from that point onwards:
1. Choose a username
2. Choose a password
3. Confirm the password
4. Save
The platform will redirect you to a new user page where you can add more information about the user, such as:
1. First Name
2. Last Name
3. Email address
4. Organisation (if there isn't one, click on the Plus and create it).
Users will only be able to see platform wide experiments or experiments created within their organisation. If they don't belong to an organisation, they will only the platform wide experiments. No one will see the experiments they create either. By default, the user created is not an admin. They won't be able to log in to the admin panel. To do that, you must change their user permissions.
Perhaps you've created a user that doesn't have all the permissions you do and they should. Or perhaps the user has access to modify too many things, and that might be dangerous to your experiment. Don't worry, there's a simple way to fix those issues - Once a user is set up, return to Home › Authentication and Authorization › Users and click on the specific user. You will see there's a number of actions you can perform from this panel, namely:
- View Action History You can view the main actions a user has performed by clicking History on the top right
- Change User Details You can change user details such as their username and personal details.
- Change User Permissions
- Active Status - keep active unless you know a user won't be on the platform.
- Staff Status - if you tick this, the user will be able to log in through the admin panel.
- Super User Status - the user will be able to do anything on the platform - they will have access to all experiments created and will have permission to modify any content. You can also set specific permissions - say you want to give someone the ability to be an admin without them being a super user. You can do that by choosing specific permissions
To set up an experiment, the experiment administrator needs to go through a number of steps:
- Login and open admin panel.
- Go to Exercises.
If you want to use an experiment that has already been added to the platform and you have access to, you need to go to Home>Exercise>Exercises and select your experiment.
Click on the experiment ID and click on "Copy Exercise". A copy of the exercise will be made so you can deploy it within your organisation. Any administrator user within your organisation will be able to see and edit this experiment.
Go to Home>Exercise>Exercises and click "add exercise"
Here, you will add all the information about demographics, emails to appear during exercise, the length of the exercise and information to appear to participants at baseline and at debrief.
To make edits to existing demographic info, exercise emails, files, replies and webpages can be done so on the admin homepage.
There's two actions you can perform in the Demographics panel - add and remove questions.
- To add demographics questions, go to Exercise > Demographics Infos>Add demographics info There you will be asked to define the question type:
- Number denotes a question that will require a numeric answer, such as "How old are you?".
- String denotes a question that will require a text-based answer, such as "Where are you from?".
To add experiment emails, go to Home>Exercise>Exercise emails and click on Add Exercise Email tab. Here, you will need to populate each individual email shown in the experiment with the following data:
- Subject - the subject of the email.
- From address - the email address of the sender.
- From name - name of the sender.
- From profile img url - link to the email profile picture of the sender.
- To address - email address of the recipient.
- To name - name of the recipient.
- To role - role of the recipient.
- Phish type - there's a dropdown menu with 3 types of phishing - regular, phishing and e-tray.
Regular - normal email, not phishing email.
Phishing - phishing email.
- Phishing explained - If using phishtray for training purposes, you can explain to the user about the phishing email here. This will be displayed to the user at debrief stage
- Content - this is the body of the email.
- Attachments - if you wish to upload any attachments, click on the + button, enter the details and the attachment URL.
- Replies - Select the replies you want to appear in this email, or create a new one by clicking the + button.
- Belongs to - If the email is part of an email thread, then select the main email in that thread, otherwise select the email itself. Emails need to belong to another email or themselves to count as threads. Please note, emails that are not part of a thread will not be shown during the exercise.
- Sort order - Select the order number in the thread. Now all that's left is configuring the time at which the email will be revealed throughout the experiment. To do so, go to Home>Exercise>Exercise Email Properties and proceed with the following steps:
1. Filter by exercise on the right hand side
2. Click on the Add Exercise Email Proprieties button on the top right of the panel.
3. Select the relevant exercise (experiment)
4. Select the email subject
5. Add the time at which the email should appear in the experiment.
> This will be in seconds
> For 400, the email will appear in the inbox at second 400.
In this section, you can also edit the date and time the email was "received" to appear to the participants. You can also "intercept" exercises, this feature will lock phishtray until a "release code" is entered.
Add experiment trials
This feature was created to allow the testing of multiple similar experiments (i.e. experiments with a few extra emails but the same storyline, experiments with or without debrief etc).
If you want to create a trial for your experiment, click on Add Trial within the excerises tab and follow the previous set up flow.
To provide detailed training to participants about their anti-phishing ability.
You can add specific feedback per phishing email (see above).
You can also provide a "debrief" by ticking the debrief box on exercise tab.
There is some training provided by default, however to link to your own training, you can paste a link within "Training link".
Phishtray works best in Chrome Browser on PC or Mac. It is currently not optimised for use on tablets or iPad.
It is also recommend to run Phishtray within incognito mode.
1. How do I send an experiment link to participants? You need to copy the exercise id (found in Home> Exercise> Exercises) and add it on the emtray link. All experiment links will follow this particular structure: www.emtray.com/welcome/experiment_id . This way, if the management task ID is c266f00c-e42a-blabla-460310c5aa34, the link to the management demo task is www.emtray.com/welcome/c266f00c-e42a-blabla-460310c5aa34.
2. How do I download experiment data? To download the data, you need to do to Home>Participant>Participants. There are two data files for each participant. If you want to download granular data for specific participants, select the participant, click on Action and select "Email Interactions CSV". To view data (such as answers to demographic questions), click on the participant ID.
3. Can the "files"/"accounts" section be removed or can I request modifications? We don't currently offer modifications on the supported version of Phishtray. However, as Phishtray is open-source you are able to make any modifications.
4. Can I record a participant's prolific ID To store a participant's prolific ID in their data set, please use the following question with "demographic info": Please enter your Prolific ID