Hoxhunt
Adaptive phishing training that adjusts to each employee
Hoxhunt sends each employee simulated phishing at a difficulty matched to how they have responded before, so a person who reports every attempt sees harder ones and a person who clicks gets shorter, more frequent practice. Reporting is a button in the mail client, and the training arrives as a short response to what the person just did rather than as an annual course. The same reports feed incident response: when a real attack is reported, the platform clusters it with everything else that looks like it and automates the triage that would otherwise be manual. A behaviour risk console widens the picture beyond email, surfacing risky real-world behaviour and letting an intervention be automated against it. Compliance and awareness content sits alongside the phishing programme for the training an audit expects. Pricing is not published; it is quoted per organisation.
- Simulation difficulty adapts to each person's history
- Reporting is a button inside the mail client
- Training arrives as a response to what someone just did
- Reported mail clusters into incidents for triage
- Email incident response automation
- Behaviour risk console reaches beyond email
- Security awareness and compliance training content
- Risk measured per person rather than per campaign
Based on what people have said
Every answer links back to the mentions it came fromHow does Hoxhunt's approach to training differ from traditional methods?
Rather than relying on annual training modules, Hoxhunt uses continuous, adaptive simulations that provide immediate feedback and micro-training moments. It incorporates gamification elements like leaderboards, level-ups, and departmental competitions to encourage engagement and positive reinforcement.
7 mentions · r/AskNetsec · r/AskNetsec · r/ITManagers · r/sysadmin · r/cybersecurity · r/sysadmin · Aug 2025 – Sep 2026
What do users say about the effectiveness of the gamification and adaptive features?
Several users report that the gamified approach leads to high engagement and improved reporting quality over time. Some note that the adaptive difficulty model is effective for moving beyond baseline metrics and building habits, though one user cautioned that constant simulations can lead to employee burnout.
8 mentions · r/AskNetsec · r/sysadmin · r/sysadmin · r/cybersecurity · r/cybersecurity · r/sysadmin · Aug 2025 – Sep 2026
How does Hoxhunt compare to other platforms like KnowBe4?
Users often compare the two, noting that KnowBe4 is a standard enterprise choice with a massive content library and strong compliance reporting. In contrast, Hoxhunt is frequently described as more gamified and engaging, with some users switching to it specifically to improve participation rates or move away from what they perceive as sterile, corporate-style training.
7 mentions · r/cybersecurity · r/sysadmin · r/cybersecurity · r/cybersecurity · r/sysadmin · Aug 2025 – Apr 2026
What is the experience like regarding customer support?
Support is described as responsive, though some users note that because the team is based in Finland, availability can be limited by local business hours or company retreats.
1 mention · r/AskNetsec · Jun 2026
Are there any concerns regarding employee sentiment?
Opinions are divided; while many users report that employees find the gamification engaging and less punitive than traditional methods, at least one person suggested that such tools can negatively impact employee morale.
4 mentions · r/AskNetsec · r/sysadmin · r/AskNetsec · r/msp · Mar 2025 – Apr 2026
These summarise counts and dates only. Read the quotes themselves under what people are saying.
What people are saying about Hoxhunt
69% positive“I see what HoxHunt is doing here and it's not a bad idea. With my company, we don't go specifically themed, like World Cup angle, but we definitely have that friendly gamified friendly competition, which everyone globally can relate to.”
“If you’re talking about phishing I highly recommend Hoxhunt for the gamification, easiest tool I’ve ever used.”
“In Hoxhunt the reporting speed and repeat misses give the team angle some behavior to track so its not much like an October theme but more like a way to see if people are improving”
“Well the Hoxhunt model fits that pretty well imo. Repeated adaptive simulations give security teams behavioral data they can use to tune training around specific user risk patterns and measure if reporting quality improves month to month”
“The Hoxhunt angle of treating awareness more like ongoing practice and coaching instead of a once a year training module makes sense. People need repetition and some sense that security is part of everyones job, not only the security team’s problem”
“Hoxhunt wouldn't even talk to us because of the minimum.”
“* Our pricing bands start at 1-50 users, so you won't hit the Hoxhunt problem - and we come in well under the $6K Adaptive quoted you.”
“I've seen hoxhunt mentioned but their request a quote form requires user count to be at least 100. Adaptive Security is a bit pricey at $6K for 50 and under users though demoed features are quite interesting.”
“So far for the last few months we've been running them it's been going really well, and they are updating the platform at a considerable speed too. Their MS Teams integration for "hey you missed this phishing" and "hey you have training" has been a greay way to make sure our users see the training.”
“The thing that sold me over the older players is that the simulations include newer types of lures, such as deepfakes, based on the latest threat trends. They also adapt to each person, so people who keep clicking get more coaching while the ones who are already sharp aren't stuck doing baby steps.”
“I found their support to be very responsive. The downside is they are based out of Finland so when the clock strikes 5 pm local or they are at their company retreat once a year, work stops for them. They do seem to have a small support team in the US.”
“We renewed Hoxhunt after evaluating alternatives, which honestly surprised me because I'm usually the first person pushing for a competitive review. The biggest reason was that we saw steady engagement even after the first year.”
“Definitely check out Hoxhunt. It is by far the most effective platform. I can’t recommend it enough.”
“Vendors I keep hearing about are Hoxhunt, Wombat, Proofpoint, Cofense, etc., but I'd rather hear from people who have actually lived with them.”
“The key difference for us was that training happens in-context, phishing simulations land in the actual inbox and the learning moment is right there when someone interacts with one. No separate portal, no scheduled hour of suffering. Took a quarter or two to see meaningful change but click rates dropped and reporting rates went up, which is the actual goal.”
“The key difference for us was that training happens in-context, phishing simulations land in the actual inbox and the learning moment is right there when someone interacts with one. No separate portal, no scheduled hour of suffering. Took a quarter or two to see meaningful change but click rates dropped and reporting rates went up, which is the actual goal.”
“hoxhunt is decent if u want high engagement, but honestly the constant pestering can burn people out after a few months. at my last firm we switched to cybeready because it focuses more on actual behavioral change rather than just trying to trick people into clicking links.”
“Hoxhunt seems to get a lot of credit here because of gamification/adaptive difficulty.”
“Another vote for Hoxhunt.”
“These two HoxHunt and CyberHoot have the psychology and educational nuances of behavior change nailed!”
“Hoxhunt is built more around positive reinforcement and micro training moments rather than catching people and making them feel dumb. Users actually engage with it because it feels more like a game than a punishment. Leaderboards, level ups, departments competing against each other, the whole thing.”
“Hoxhunt leans hard into gamification and adaptive simulation difficulty, which works well if your goal is behavior change over time. KnowBe4 is the safe enterprise pick if you need compliance reporting and a massive content library.”
“we used Hoxhunt for a while (decent adaptive simulations) then switched to Riot mostly because of the breach monitoring being built in. having that all in one place instead of separate dashboards made reporting to leadership a lot less painful.”
“I actually am in talks with HoxHunt. May replace KnowBe4”
“For phising simulation training tool, take a look at Hoxhunt. Simple interface, simple setup, gamification of the training itself.”