In the Security Awareness Service (SAS), a file is considered opened as soon as a user downloads it or interacts with it in any other way.
Background
Depending on the scenario of the simulated attacks, files are attached to the generated emails to test users' reactions. This is used to verify the effectiveness of training and awareness measures regarding phishing and other fraudulent activities. If a user interacts with such a file, the simulated attack is considered successful and is logged accordingly.
What Counts as an Opened File?
- Any interaction with a file counts as a successful attack.
- The file can be included directly as an attachment in the email.
- The file can also be made available via a download link.
- Downloading alone is sufficient to be included in the statistics; the file does not necessarily have to be opened.
How Is It Counted?
If a file is accessed via a link, one hit is recorded for the respective scenario in both the Links column and the Documents column.
What Does This Mean for the ESI?
Although two hits appear in this case, the ESI is not charged twice. The duplicate display is only for clearer traceability of how the hit occurred.
Further Information
How to interpret the values in the table is explained in the following manual article: Simulated Attacks
What counts as a clicked link is explained in the article: What Counts as a Clicked Link?