PhishER Plus is your lightweight Security Orchestration, Automation and Response (SOAR) platform to orchestrate your threat response and manage the high volume of potentially malicious email messages reported by your users.
Introducing PhishER Plus - the most powerful anti-phishing defense available in the world. PhishER Plus is a light-weight SOAR platform that automatically analyzes and prioritizes reported email messages to identify and quarantine malicious email across your organization. Additionally, transforms in-the-wild phishing emails into training opportunities by flipping them into simulated phishing campaigns.
PhishER Plus adds AI-and-human-validated, crowdsourced blocklist and PhishRIP capabilities to proactively block and remove active phishing attacks that have bypassed email filters BEFORE your user gets exposed to them. PhishER Plus is powered by an active global threat feed (Global Blocklist) that is crowdsourced from more than 10 million highly trained KnowBe4 end users from across the globe to spot and report on active phishing and social engineering attacks in the wild. The reported email-based threats are subject to three levels of human and AI-based validation and analysis: the collective initial reporting from all KnowBe4 trained users; each PhishER customer organization's own SOC/IT security team; and the KnowBe4 Threat Research Lab team, which examines and vets each submitted threat for validity.
Machine learning and AI-powered analysis eliminates the guesswork of identifying high-risk phishing threats from all the user-reported messages and to automate the security workstream for managing the "other 90%" of user-reported emails. This allows your organization to build a fully orchestrated and highly effective SOC team that can identify and mitigate social engineering threats in near real-time.
WHY IS THIS DIFFERENT?
-Cut through the mail clutter and allow your IR and SOC teams to focus on the high-level threats
-Group or cluster messages based on patterns to allow incident response teams to quickly identify a widespread phishing attack
-Automatically remove phishing emails from users' inboxes at the email server level
-Harness the power of blocklisting and crowdsourcing to prevent malicious emails
-Take real-world phishing attacks and change them into simulated phishing templates to train your employees, strengthen your organization's human firewall against future assaults
-Global Blocklist: Fingerprints of validated threats are used to automatically block matching new incoming messages from reaching your users' inboxes. This constantly updated Global Blocklist threat feed syncs with your Microsoft 365 mail server
-Global PhishRIP: Messages that match an identified phishing threat other PhishER customers have removed and have been validated by the KnowBe4 Threat Research Lab can be automatically quarantined by removing (ripping) them from all of your users' inboxes
Contact us with any questions or for custom pricing at AWS@knowbe4.com
"Buy Now" Disclaimer: When you click "Create Contract" your purchase request will be forwarded to KnowBe4 for additional evaluation. You will receive a notification confirming the acceptance of your order as soon as it has been reviewed and approved. Your subscription will not begin until your order has been fully accepted in accordance with the EULA.
Highlights
Block email threats that have bypassed other email security filters or systems before they reach your users' mailboxes
Isolate malicious emails that already bypassed your mail filters through automated quarantine with Global PhishRIP
Crowdsource threat intelligence from 10+ million KnowBe4 trained users
Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
PhishER Plus uses a single pricing dimension: Users, billed per user per month. You pay based on the number of users you cover. As your user count changes, your cost scales up or down with that count. This dimension is sold under a contract term, so you commit to coverage for the agreed period. All included capabilities apply to every user you enroll, with no separate feature-based charges in this listing.
Top-of-mind questions for buyers
What counts as one user for billing purposes?
One user is one mailbox or person enrolled for phishing response coverage. You are billed for each user you cover, per month. Every enrolled user gets the same protection features, including message prioritization, quarantine, and blocklist capabilities, with no separate per-feature charge.
What happens to my cost if my user count grows or shrinks during the term?
Your charge is based on the number of users you cover per month. As your user count changes, your cost scales up or down with that count. This listing is sold under a contract term, so you commit to coverage for the agreed period.
Is this listing sized for any organization, or a certain user range?
The seller notes that buying through AWS Marketplace keeps procurement and billing in one place and is suited for up to 500 users. Above that count, contact the vendor to confirm the right arrangement for your organization.
www.knowbe4.com+2
Helpful?
Vendor refund policy
All Orders are non-cancellable and all fees and other amounts you pay under this Agreement are non-refundable, except in the event KnowBe4 is unable to cure a valid warranty claim within thirty (30) days of notice, as provided in further detail in Section 9 of the KnowBe4 Terms of Service.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
When you have questions, we have answers. We make it easy to connect with us when you need technical support, the way you want to connect: Online Community, Support Knowledgebase, and full time dedicated Technical Support teams worldwide. With an average Median Response Time of an hour in responding to new support tickets and a 98% customer support satisfaction rate, KnowBe4's tech experts respond quickly and get your issues resolved super-fast! Visit:
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Lightweight SOAR platform that automatically analyzes, prioritizes, and orchestrates response to reported email messages to identify and quarantine malicious emails across the organization
AI and Machine Learning-Powered Threat Analysis
Machine learning and AI-powered analysis to identify high-risk phishing threats from user-reported messages and automate security workflows for threat prioritization
Crowdsourced Global Threat Intelligence
Active global threat feed powered by crowdsourced intelligence from over 10 million trained end users with three levels of human and AI-based validation from collective reporting, customer SOC teams, and dedicated threat research lab
Automated Threat Remediation
Automatic removal of phishing emails from users' inboxes at the email server level and quarantine of matching threats through Global PhishRIP capability that syncs with Microsoft 365 mail servers
Threat Pattern Clustering and Campaign Conversion
Message clustering and pattern-based grouping to identify widespread phishing attacks, with capability to convert real-world phishing attacks into simulated phishing training templates
AI-Powered Threat Detection and Response
Leverages AI engine to detect and block phishing, malware, ransomware, spear phishing, spam, and account takeover threats through cloud email gateway and API-based inbox defense mechanisms.
DMARC Authentication and Domain Spoofing Prevention
Provides DMARC reporting with granular visibility and analysis of SPF/DKIM/DMARC configurations to prevent email domain spoofing and minimize false positives.
Cloud-to-Cloud Backup and Data Protection
Offers unlimited Microsoft 365 backup for OneDrive and SharePoint environments with automated data recovery capabilities against malicious or accidental data deletion.
Sensitive Data Discovery and Remediation
Includes Data Inspector tool that scans OneDrive and SharePoint for sensitive information and malware-containing files, with visibility into file sharing and automated remediation for improper shares.
Security Awareness Training and Attack Simulation
Provides simulation-based training with localized content library and continuous attack simulation testing with reporting capabilities for security awareness and user education.
AI-Driven Threat Detection
Utilizes artificial intelligence to detect and prevent advanced email attacks, phishing, credential theft, ransomware, business email compromise, and cloud account takeover threats.
Unified Cross-Channel Visibility
Provides centralized dashboard with holistic view of user interaction and threat telemetry across cloud, email, endpoint, and web channels in a cloud-native interface.
Automated Incident Response
Enables automated remediation and consistent, scalable incident response to sophisticated email attacks with reduced manual triage requirements.
Behavioral and Content Analysis
Correlates user activity, behavior patterns, and content analysis with threat intelligence and data movement to identify and prevent data loss and insider threats in real time.
Data Protection and Privacy Controls
Implements anonymization of user data, content snippet masking, and regional data residency management to protect user privacy while defending against data loss scenarios.
I really like how KnowBe4 PhishER/PhishER Plus allows our users to report phishing emails easily and helps automate the review process for these reports. The setup was super easy, and we quickly got it up and running with the support of their team. Its ease of use and customization have been great, especially since most reported emails are automatically evaluated and the right actions are taken, which saves us a lot of time. It also boosts our confidence in determining whether a reported email is truly malicious or not. We also love the integration with Crowdstrike; it makes scanning attachments for malicious content super easy, eliminating the need for manual downloads. The platform is straightforward compared to Microsoft’s Defender, with less complexity in seeing what happens behind the scenes and understanding decision-making processes.
What do you dislike about the product?
Sometimes the report button in Outlook is a bit slow to load, but other than that, we haven't really run into any issues.
What problems is the product solving and how is that benefiting you?
We use KnowBe4 PhishER/PhishER Plus to automate phishing email reviews, save time from manual checks, create action rules, and boost our confidence in identifying malicious emails.
Manufacturing
I have been using PhishER for several years and I have found it to be extremely useful
Reviewed on Jul 09, 2026
Review provided by G2
What do you like best about the product?
Easy to use platform. I find that the percentages for clean-spam-threat are spot on and provide an outstanding gauge for deciding if a message is a threat or not.
What do you dislike about the product?
My issue is not necessarily a PhishER issue but an internal process issue at our company. We have several administrators and we all tend to process the PhishER messages a little differently. Some of the administrators tend to skip steps - the ability to incorporate some type of recommended process flow into the system would be helpful - nothing complex - perhaps something AI-driven that would simply have reminder steps such as: run PhishRIP, mark the message as resolved, etc.
What problems is the product solving and how is that benefiting you?
It solves the problem of worrying if a message is a threat or not.
Automotive
High Performance and Responsive Support When Issues Arise
Reviewed on Jul 08, 2026
Review provided by G2
What do you like best about the product?
Performance of platform. Responsiveness to potential issues within our association
What do you dislike about the product?
Implementation- Not all staff use it because they either don't know how to start the implementation process or too confusing for finish the set up
What problems is the product solving and how is that benefiting you?
catching issues before they become large scale problems
Manufacturing
Proactively Removes Malicious Emails Across Mailboxes
Reviewed on Jul 08, 2026
Review provided by G2
What do you like best about the product?
One of the most helpful things with this product is the fact that it will run through everyone's mailbox and remove any malicious email after someone submits one. This helps prevent anyone else from clicking on something they shouldn't.
What do you dislike about the product?
There wasn't much to dislike about it. Maybe the AI recognizing malicious emails could be better, but it's already very good.
What problems is the product solving and how is that benefiting you?
This solution helps keep users from clicking on something malicious. This is only if someone submits the email before others see it. This helps me from having to remediate a breach or virus.
Weston G.
PhishER Simplifies Phishing Review and Stops Threats Organization-Wide
Reviewed on Jul 08, 2026
Review provided by G2
What do you like best about the product?
PhishER makes reviewing potential phishing emails so much easier. It integrates with most common email platforms, and gives the end user a button to click to report a suspicious email. It splits out the headers so they are easy to find and review, automatically scans attachments, and in most cases will automatically categorize submitted emails for you. Once it makes the determination that the email is malicious, it will automatically pull matching emails from other inboxes in your organization. It has saved us multiple times.
What do you dislike about the product?
The only real pain point we have had with the product, is getting users to click the Phish Alert Button, rather than forwarding the email to our helpdesk account. That isn't a fault of the platform, but a user training issue. It does have a limitation where if the user has replied to the email or forwarded it before clicking the button, it doesn't give you the information you need from the original email, but submits the most recent email in the thread. I'm not sure if that is able to be fixed. But, once again, it boils down to a user training issue.
What problems is the product solving and how is that benefiting you?
It has taken the guesswork out of reviewing phishing emails. If it can't make a solid determination with regard to the validity of an email, it will send an alert so it can be manually reviewed. The majority are categorized automatically, but it makes the manual review process very easy.