Depending on the scenario of a simulated attack, emails may contain files with macros.
Macros are small programs or sequences of commands in files, for example in Microsoft Office documents. They can automatically perform certain actions. Therefore, macros can be misused in real attacks to carry out harmful actions on a device.
These scenarios check whether users perform potentially dangerous actions.
A macro is only considered executed when the user actively starts the execution of the macro and then confirms it.
Simply opening the email or the attached file is not sufficient.
When Is a Macro Counted as Executed?
A macro is only included as a executed macro in the statistics after the following steps have been completed:
- The user opens the attached file.
- The user starts the execution of the macro.
- The user confirms the execution of the macro.
Only after this confirmation is the action logged and included in the statistics.
What Does Not Count as an Executed Macro?
The following actions are not yet considered executed macros:
- The user opens the email.
- The user opens the attachment.
- The user sees a prompt regarding macro execution but does not confirm it.
Why Is This Recorded?
Recording this helps evaluate user behavior in simulated attack scenarios.
This way, it can be checked whether training and awareness measures in the areas of phishing and social engineering are effective.