PandaONEPhish

Authorized simulations only

Simulate phishing.Measure exposure.

Run controlled campaigns with real funnel analytics — templates, landings, SMTP delivery, and per-recipient proof for security teams.

Q4 Security Awareness — Live

Email preview

Action required: verify your account

Your session expires in 24 hours. Click below to confirm your credentials.

Try clicking — watch the graph update

Click activity

42

Opened

75%

Clicked

16.9%

Reported

12.5%

SMTP profilesREST APIWebhooksCSV importOIDC SSOOpenAPIMCP agentsLive funnelSMTP profilesREST APIWebhooksCSV importOIDC SSOOpenAPIMCP agentsLive funnel

Campaigns

Launch simulations in minutes

Wizard-guided campaigns with template pick, group targeting, SMTP profile selection, and schedule controls.

New campaign
✓
Template
✓
Group
✓
Sending
4
Review

Review & launch

CampaignFinance password reset drill
TemplateIT Helpdesk — Password reset
GroupFinance team (42 recipients)
SMTPCorporate relay · smtp.company.com
ScheduleSend now · spread over 2 hours
BackLaunch campaign

Analytics

See who fell for the phish

Live funnel from sent to reported. Spot weak links in your organization before attackers do.

Campaign analytics — Finance Q4

Click activity

Cumulative clicks during campaign

42

9a10a11a12p1p2p3p4p

Click rate

16.9%

Submit rate

3.6%

Report rate

12.5%

Recipient funnel

Sent248 (100%)
Opened186 (75%)
Clicked42 (16.9%)
Submitted9 (3.6%)
Reported31 (12.5%)

Recent activity

  • Alex M.Submitted
  • Priya K.Reported
  • Jordan L.Clicked

Landings

Clone any site as a landing page

Import URLs with headless capture for JS-rendered pages. Edit HTML and preview before launch.

Landing importer

Source URL

https://login.microsoftonline.com/…
Capture

Original

Captured · editable

Sign in

Next

Headless capture for JS-rendered pages · edit HTML before launch

Developers

Automate with API and MCP

Full REST API with OpenAPI spec, signed webhooks, and local MCP for AI-driven campaign management.

REST API · OpenAPI

POST /api/v1/campaigns/quick

{
  "name": "Q4 finance drill",
  "template_id": "tpl_…",
  "group_id": "grp_…",
  "smtp_profile_id": "smtp_…"
}

GET /api/v1/campaigns/{id}/stats

{ "sent": 248, "clicked": 42,
  "submitted": 9, "reported": 31 }
WebhooksAPI keysMCP toolsCSV export

Live in three steps

From template to measurable results — built for security teams running authorized drills.

  1. 01

    Build templates & targets

    Create email templates with paired landing pages. Import sites or upload HTML. Add groups via CSV.

  2. 02

    Launch the simulation

    Send to your authorized recipient list. Launch immediately or schedule with spread delivery.

  3. 03

    Measure exposure

    Track opens, clicks, submissions, and reports in near real time — per campaign and per recipient.

Questions, answered

Everything security teams ask before their first simulation.

An authorized phishing simulation platform for security teams. Run controlled campaigns, measure click-through and submission rates, and track who reports suspicious emails.

Your next campaign could prevent a real breach.

Build a template, pick your authorized list, and measure who clicks — before attackers do.