C24 Sentry

Please sign in to continue

C24 Sentry — Security Awareness & Phishing Simulation

Client Security Awareness Overview

Training

👥

0

Enrolled Employees

🎯

0%

Training Completion Rate

📊

0%

Average Quiz Score

📁

0

Active Training Campaigns

Phishing Simulation

🎣

0

Simulation Campaigns Run

✉️

0

Simulated Emails Sent

👆

0%

Click Rate

0%

Training Acknowledged Rate

Phishing Simulation Funnel

Sent → Opened → Clicked → Acknowledged, across all simulation campaigns to date.

Recent Activity

    My Training

    Here's your personal training status.

    📧 Phishing Results

    Phish-Prone Percentage
    Emails Delivered0
    Clicked0
    Refresher Completed0

    🎓 Training Assignments

    Assignments Completed
    Completed0
    In Progress0
    Not Started0
    📚

    0

    Assigned Trainings

    0

    Completed

    0

    Pending

    📊

    Average Score

    Completed Trainings

    Training Type Completed Score

    Employee Training Status

    Uses the group/enabled/licensed filters set on the M365 Integration tab.

    Name Email Department Status Score Source Action

    Training Campaigns

    This sends a real training email (with lesson content and a short quiz) to each enrolled employee's inbox, and tracks who started, completed, and how they scored.
    Campaign Type Target Progress Avg Score Actions

    Phishing Simulation — M365

    Important: This sends real email, from your own M365 tenant, to real mailboxes. Only run this against people whose organization has agreed to run phishing awareness simulations — log the engagement in the Consent & Engagement tab first. Clicking the simulated link takes recipients to a plain educational notice page; it never presents a fake login form and never collects passwords or personal data.

    New Simulation Campaign

    A realistic-looking lure document (e.g. "Invoice.pdf") sent alongside the email. Allowed types: PDF, Word, Excel, PowerPoint, images, text/CSV — max 5MB. Executable/script files are not allowed.

    Recipients are pulled from the Employees tab (anyone with an email on file). Add employees manually or sync them from M365 there first. Use the department filter for role-based targeting (e.g. send the "Invoice Approval" template only to Finance), or check individuals directly below.

    Filter by department:
    Name Email Department

    Campaign Results

    Campaign Category Sent Click Rate Ack. Rate Launched Actions

    Reports

    Filterable, exportable reporting across training and phishing simulation — pulled live from the database.

    Overview

    👥

    0

    Enrolled Employees

    🎯

    0%

    Training Completion Rate

    📊

    0%

    Average Quiz Score

    🎣

    0

    Simulation Campaigns

    👆

    0%

    Phish-Prone Percentage

    0%

    Training Acknowledged Rate

    Phish-Prone Percentage Trend

    Click rate per simulation campaign, in chronological order — the key metric for tracking whether awareness is improving over time.

    By Department

    Department Employees Training Completion Avg Score Phishing Sent Phish-Prone %

    Repeat Clickers — clicked a simulated phishing link in 2+ campaigns

    Name Email Department Times Clicked Most Recent

    Campaign Detail

    Training Campaigns

    Campaign Type Target Enrolled Completed Avg Score

    Phishing Campaigns

    Campaign Category Sent Opened Clicked Acknowledged

    Exports

    
            

    Microsoft 365 Integration

    Connect to Microsoft 365 / Entra ID via Microsoft Graph to import users and (optionally) sync the Employees tab. This connection is also used if you choose "Microsoft 365" as the send method on the Email Sending tab.

    Connection Settings

    Status: Not configured

    These filters apply both to "Import Users" below and to "Sync from M365" on the Employees tab. Picking a group requires the app registration to have Group.Read.All permission.

    Name Email

    Imported users become available as recipients on the Phishing Simulation tab, where campaigns are built and launched.

    Email Sending

    Choose how simulation emails go out. You can configure both and pick which one to use each time you launch a campaign.

    Option A — Microsoft 365 (Graph API)

    Uses the connection configured on the M365 Integration tab. The sender mailbox's domain must already be added and verified in your M365 tenant (Admin Center → Domains) — Graph will reject sending from domains the tenant doesn't own.

    Option B — SMTP (e.g. Hostinger email)

    Sends directly through a mailbox's SMTP server instead of M365. For Hostinger email, this is usually smtp.hostinger.com, port 465 (SSL) with an existing mailbox on your domain (e.g. security-training@ciqur.com) created in hPanel → Emails.

    Option C — Resend (HTTP email API)

    Sends over plain HTTPS instead of SMTP — useful if your host (e.g. Render's free tier) blocks outbound SMTP ports. Sign up at resend.com, verify a sending domain there, and paste the API key below.

    Option D — Amazon SES

    Also sends over plain HTTPS via AWS's API (not SES's SMTP interface, which would hit the same port block). You'll need an IAM user with ses:SendEmail permission, a verified sending identity in SES, and — for a brand new AWS account — production access approved (new accounts start in "sandbox mode" and can only send to addresses you've individually verified).

    External Training

    Connect third-party training content two ways: live-launched via LTI 1.3 (grades sync back automatically, content stays hosted by the provider), or by uploading a SCORM 1.2 package they've exported for you. Both show up together on each employee's My Training dashboard, alongside your regular campaigns.

    Option A — LTI 1.3 (live-launched)

    1. Register a Tool

    You'll need three URLs from the provider's own LTI 1.3 platform registration instructions (for RansomLeak, this is in their admin console under "LTI Integration" or similar).

    Tool Client ID (give to provider) Deployment ID

    3. Add specific exercises

    Each "resource link" is one launchable exercise or course from the provider — get the exact launch URL from their content catalog or deep-linking flow.

    Exercise Tool Target

    Option B — SCORM 1.2 package upload

    Upload a course package

    Export the course as a SCORM 1.2 zip from the provider's own platform, then upload it here. Some packages (like RansomLeak's) stream the actual content live from the provider's servers even after upload — you're just hosting the launch shell and receiving completion/score reports here.

    Course Target Uploaded

    Admin Control Panel

    Manage who can log into this dashboard, what they can do, and how they sign in. This is separate from Employees (the people being trained/tested).

    Portal Users

    Username Display Name Role Groups Sign-in Effective Role Actions

    Permission Groups

    Groups grant their assigned role to every member — useful for bulk permission changes (e.g. give an entire team Manager access at once).

    Group Grants Role Members Actions

    Single Sign-On

    Microsoft (Entra ID)

    Reuses the Tenant ID / Client ID / Client Secret already configured on the M365 Integration tab. In your Entra ID app registration, add this as a Web redirect URI: (loads once page is open)

    Generic SSO (SAML/OIDC provider — e.g. Okta, Google Workspace, Auth0)

    Enter the OIDC endpoints from your identity provider's app configuration. Redirect URI to register with your provider: (loads once page is open)