What people previously said about KnowBe4

Older than the 25 on KnowBe4’s page
“Hi there, I have question related to single sign on for Knowbe4. Currently we are creating user manually. My plan is to enable single sign on using Entra id which is outlook email and password of user.”
Slight_Gur1122 · reddit ·
“Cyber security company Knowbe4 apparently has corporate scripted shows for their customers”
jcdulos · reddit ·
“We moved to BullPhish ID because it has better support, Knowbe4 support is bad.”
BobElssa · reddit ·
“Fuck KnowBe4, imo. Too many stories of them delivering shit service support.”
itishowitisanditbad · reddit ·
“That sounds like a excellent question to ask knowbe4 support.”
Extra_Pen7210 · reddit ·
“The problem we've been having recently is that Microsoft Defender is flagging the attachments on KnowBe4 phishing emails as malicious. This would be great if they were actual phishing attempts, but because the file is being flagged and quarantined, the user is NOT getting flagged in KnowBe4 as having failed the test when they try to open the attachment.”
havens1515 · reddit ·
“Our company has been using their products for 3 years. We have had great success, our users are more security conscious and aware on how to spot and report phishing emails.”
Bjnesbitt · reddit ·
“The thought was if someone was inside knowbe4 and managed to burrow into systems, they could work from inside the mailsystem. Given that this guy got caught shortly after receiving his laptop, I don't think he was going to embedding himself in much.”
Redemptions · reddit ·
“KnowBe4's mailserver is pretty much set up where you can't weaponize it. Plus, they'd have a hard time bypassing email protection software, as they wouldn't be sending from the same hostname or same IPs as KB4 does.”
Lobsterv2 · reddit ·
“If a Russian agent can stay inside solarwinds for 6 months undetected, you think KnowBe4 is going to invest anything more in their SOC?”
Whyme-__- · reddit ·
“Since no one responded correctly here, in the blog post from KnowBe4 they said it was AI enhanced, not generated. They took a stock image of a guy in glasses and used AI to modify it with an actual photo of the interviewee.”
Mrtw33tums · reddit ·
“Slightly ironically, the podcast is sponsored by Knowbe4.”
CJVCarr · reddit ·
“In the actual KnowBe4 blog post they mention they had 4 separate video conferences”
h_habilis · reddit ·
“The article is incorrect. The blog post from KnowBe4 is here: [https://blog.knowbe4.com/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us](https://blog.knowbe4.com/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us)”
BernieDharma · reddit ·
“I'm betting KnowBe4 will in fact, be fooled again.”
changee_of_ways · reddit ·
“Why link an aggregator instead of their actual blog post about the event?”
Cinci555 · reddit ·
“KnowBe4 out of all the companies? Really? we hit the new low folks... SMH”
detsd · reddit ·
“Cyber firm KnowBe4 hired a fake IT worker from North Korea”
Memphisto480 · reddit ·
“This is like giving the keys to a burgler and then claiming your house is insecure. Trash.”
ultramegamediocre · reddit ·
“Reach out to KnowBe4 support. They have 24 root domains that need to be added to your tenant so MS trusts the emails and doesn't inadvertently 'click' the email on scans, generating a false positive.”
Any-Fly5966 · reddit ·
“It seems like Advanced Delivery Policies work pretty well at stopping these false positives, but if not then the Smart Hosting setup should definitely take care of it. On-premises the smart host config will probably be your only effective option, though I haven't messed with On-premises exchange for 3 or 4 years now.”
1337j4k3 · reddit ·
“We've recently implemented KnowBe4 and started our first internal Phishing tests. Now is the problem, that as soon as the E-Mail arrives it is being marked as read and clicked. I've tried disabling my local anti virus, disabling every Outlook add-in but still haven't found a fix.”
TheCha5er · reddit ·
“also, sometimes false positives in knowbe4 happen if a user forwards a phish somewhere.”
covex_d · reddit ·
“Yeah just set this up and it doesn't work in Outlook classic. Waiting on a response from knowbe4 support.”
Oricol · reddit ·
“We had a user plausibly refute a reported click on a phishing simulation, and found out the IP of origin for the click belongs to Microsoft. We have all KB4 domains/IPs whitelisted in 365.”
Tier1idiot · reddit ·
“Couldn't recommend it more, even preferring it over KnowBe4.”
myrianthi · reddit ·
“I am a little late to this post however they do NOT spoof the domain; you can clearly see it comes from knowbe4.com in the email header and all they do is modify the From Address to say something else. All you need to do is set up a rule in Outlook that looks for this and route it to a folder that you never open emails from.”
woodworkerweaver · reddit ·
“Not PAB, but my concern with Phisher is that an email containing PHI could be sent to knowbe4 unencrypted. I'm not sure if it encrypts the copy it sends them or not.”
chiefsfan69 · reddit ·
“I'm of the opinion that the best value you can get from a service like knowbe4 would be from refusing to whitelist them and telling them to get through your filters...”
lvlint67 · reddit ·
“I like KnowBe4 as a set it and forget it option.”
SoonerMedic72 · reddit ·
“So far, what I've seen Bullphish ID has better reporting tools and a friendlier interface than Knowbe4.”
PMPeek · reddit ·
“KnowBe4 might be useless unless it’s being used as a Cya.”
sprucecone · reddit ·
“Knowbe4 is absolute trash. Some of their *correct* answers are the opposite of what you should do. I ended up thinking what the best answer was, to looking for the one that the test wanted.”
ns_theeggmaster · reddit ·
“We have had Knowbe4 for 2 years. I like it but management has only allowed us to run 1 training campaign. They don't want to inconvenience users too much with training.”
icedutah · reddit ·
“Ever spoken to knowbe4 sales? they will hound you, call your personal number(and get it from fuck knows where), tell your boss you suck if you don't agree to whatever upgrade theyre shilling etc, utterly horrid company to do any business with”
xDARKFiRE · reddit ·
“Does your users also use the phish alert button on the knowbe4 training course emails?”
jocke92 · reddit ·
“with Knowbe4 you can mute the video, click on the end and take the test, boom your ciso will stfu for another year with just 5 minutes of work.”
Dabnician · reddit ·
“I personally wouldn’t trust them within 100 feet of anything I manage.”
ITGardner · reddit ·
“I used knowbe4 at my last job mostly for phishing tests and it's great. But at my new job we don't have a budget for that.”
wooties05 · reddit ·
“Seems like the post over the last little while have been people either switching because of the price or have already switched awhile ago. Have notice that the training hasn't been updating in some time or atleast very little update.”
kermitdafrog83 · reddit ·
“I believe knowbe4 and proof point are on AWS. Not sure what deal they have with them or if someone from either org can confirm”
One_Cod413 · reddit ·
“How does Knowbe4 do it? How would I start?”
Hot_Worldliness_6835 · reddit ·
“Yeah , in our environment , Knowbe4 has a AAD user , so it can send emails using company domain .”
sanchankun · reddit ·
“We've been with KnowBe4 for years and whilst it has every feature under the sun, we're finding it a bit stale now so we're looking at others but can't find a decent replacement. We've had demos from;”
Allinyourcabeza · reddit ·
“All I know is knowbe4 is my arch nemesis. My current company keeps saying I’ve failed after I reported or ignored the emails. 5 times now.”
JTen87 · reddit ·
“It is intended to get the email in front of the user. It is designed to evaluate the end user's ability to recognize a suspicious communication and respond accordingly.”
LPinTX · reddit ·
“If a valid SPF entry authorising KnowBe4 is configured, then mail sent from the authorised sender will pass DMARC, if in use.”
P0iS0N0USFR0G · reddit ·
“I've just set up KnowBe4 and at no point did they ask to spoof our domain, but they did ask to whitelist the phishing domains in M365 to ensure they got through. And we all know M365 regularly lets spam through so I personally have no issues with this.”
osricson · reddit ·
“It’s a lot of work to *allow* knowbe4 to spoof your domain for phishing tests. Otherwise they couldn’t spoof…”
carpetnoodlecat · reddit ·
“So you pay for a service that you and Knowbe4 setup together, and then you want to undo those changes? I'd get it if it was for part of a pen test but that isn't what this is.”
JonU240Z · reddit ·