Exercises from real attacks
How a message from quarantine becomes a harmless exercise, what is removed in the process and why the result is always a draft.
A template library talks about parcel services. The real attack on your organisation talks about the supplier you spoke to on the phone yesterday. That is why messages from quarantine can be defused and reused as an exercise.
What defusing removes
- Every link points to the exercise placeholder. On sending, it becomes your account's landing page. No target of the attacker remains, not even in image maps or mailto references.
- Every remotely loaded image is removed. A tracking pixel would otherwise tell the attacker that the exercise was opened. Embedded images stay, they load nothing.
- Scripts, forms and frames are dropped.
- Addresses and names of the original recipients are replaced by a placeholder. On sending, it holds the address of the person receiving the exercise.
- Contact details are dropped: phone numbers, postal addresses, bank details, register and tax numbers, lists of names after "Managing director". If a line consists mainly of these, the whole line goes; if a pattern sits in the middle of a sentence, only the pattern goes.
What deliberately stays
Everything that makes up the technique: subject, salutation, urgency, structure, closing and the name directly below it. In CEO fraud, that name is the lesson.
The displayed link text also stays. If it reads https://portal.microsoft.com and the link leads elsewhere, that is exactly the learning content.
Why the result is always a draft
No automatic process recognises a full name in the middle of running text. "Please talk to Martina Kellermann" would remain.
A real attack therefore always becomes a draft, never an approved template. A person in your organisation reads the text before it goes to the workforce. The interface says so explicitly and shows which patterns were found and removed.
Not every message is suitable as an exercise
Classes such as "attachment with active content" match every PDF with a form field and therefore legitimate business mail too. An exercise made from it would be a forgery of your own supplier.
Suitable carriers are the classes that prove intent: display name spoofing or a phishing URL.