
The most likely scenario for SaaS phishing platforms is a scheduled demonstration, which may or may not result in you obtaining access to a version of product that you can actually use. That is, until you actually try.In most cases, the best can you get after jumping through various hoops (filling out a request form, subscribing to a mailing list, confirming your email address, etc.) is a free campaign managed by the vendor, or a demo account with so many limitations that it doesn’t even give you a good understanding of the full version’s capabilities, let alone providing you with an actual tool that you can effectively use to create and manage multiple phishing campaigns. With phishing being among the top cybersecurity risks and commercial phishing simulators popping up like mushrooms after a rain, finding a free demo seems like an easy task. With those, you usually get the best of all worlds: ease of use, rich features (including reporting), technical support, etc. The majority of commercial phishing simulators are offered as software-as-a-service (SaaS).

So, if words like “missing dependencies” don’t sound like an alien tongue, then this category may be of interest to you. Additionally, most of them are Linux-based. But all the usual shortcomings are there as well: tools like this usually require some significant technical skills to install, configure, and run. With open-source, you get all the usual benefits, such as feature-rich free versions and community support. This is a growing and interesting category, which makes up the majority of our list. Features like reporting or campaign management are often not an option, making them more like penetration testing tools than phishing simulators.


The title of this article was supposed to be “Top 9 Free Phishing Simulators.” However, after much searching, trying, visiting of broken links, filling out forms and signing up for mailing lists, it became clear that the combination of “free” and “top” really narrows down the selection to very few actual choices for phishing training.
