Breacher.ai Add-On for Microsoft Attack Simulation Training
Beta Limited seats open now

Breacher.ai Add-On for Microsoft Attack Simulation Training

Your attackers do not stop at email. Your simulation program should not either.

Attack simulation training in Microsoft Defender for Office 365, still widely called Microsoft Attack Simulator, covers the email surface well. Breacher.ai adds the surfaces it was never built for: deepfake video calls, AI voice phishing, SMS and QR, sequenced into a single orchestrated campaign. Campaign and result data moves both ways through the Microsoft Graph attack simulation API, so email and every other channel land on one score instead of two disconnected dashboards.

Deepfake Video AI Voice SMS & QR Graph Sync Unified Reporting

Free 90-day pilot. Beta cohort holds a discounted rate for the twelve months after.

Configuring a live Microsoft Attack Simulator campaign from inside the platform. Four minutes, unedited.

An add-on, not a migration

5
Channels sequenced into one campaign: email, SMS, QR, voice, video call
2-way
Campaign and result sync across the Microsoft Graph attack simulation API
0
Payloads to migrate. Your Microsoft campaigns keep running exactly as they are

The deepfake gap in Microsoft Attack Simulation Training

This is not a knock on Microsoft. Attack simulation training does what it was scoped to do. The scope is the problem.

The delivery surface is email

Microsoft's own simulation schema exposes three delivery platforms: email, SMS and Teams. There is no voice call, no video call, and no synthetic media of any kind. The attacks your board is asking about live entirely outside that list.

Stages cannot be chained

Real social engineering arrives in sequence. A text that primes, a call that pressures, a video call that confirms the face. A tool that fires one email in isolation cannot reproduce the thing it is meant to be testing.

Training is catalogue-driven, not finding-driven

Assignment is from a fixed library, matched to a lure type. It cannot build a module around the specific pretext that worked on your finance team last Tuesday, because that module does not exist yet.

Six capabilities on top of what you already run

Nothing here replaces a Microsoft feature. Each one covers ground the native tool does not.

Simulate
Deepfake Video Call

A conversational avatar on a live video call, holding a pretext and responding to challenge. The scenario your finance controls were never tested against, run under authorization against your own people.

Not available in Attack simulation training
Simulate
AI Voice and Vishing

Cloned or synthetic voice against the help desk, the finance team, and the people who approve exceptions by phone. Covers both the automated path and the human judgment behind it.

Not available in Attack simulation training
Simulate
Orchestrated Sequencing

Stages that build on each other across channels and days, with branching on what the target did at the previous step. Your Microsoft email stage can sit inside the sequence rather than beside it.

Extends your existing campaigns
Prove it changed
Generate Your Own Training

Build micro modules yourself from live threat intel or from what a simulation just exposed, in minutes, not off a catalogue shelf. Your team writes the prompt, the platform builds the module, you assign it.

Sits alongside Microsoft training, not inside it
Connect
Two-Way Graph Sync

Simulations created and scheduled in your tenant outbound. Simulation records, per-user outcomes, user coverage and training coverage read back inbound. Standard Microsoft Graph endpoints, scoped app registration.

Read-only mode available
Measure
Unified OSES™ Risk Score

Every channel resolves to one two-axis score: DEPTH, how far the worst single case progressed, and SPREAD, weighted population incidence. One number for the board, with the evidence underneath it.

Reported organizationally, never per person
Cloning is gated, not trusted to a checkbox. Before the platform will generate a voice or likeness, the individual being cloned completes a biometric and voice verification of their own consent, and that obligation is carried in the service agreement as well. No admin can authorize the cloning of someone else. Recorded-call scenarios are configured to the recording consent law of every jurisdiction your targets sit in.

Connect once, then run everything from one plan

The add-on is the Microsoft-connected mode of OSES™, our orchestrated social engineering simulation framework. Same three stages, Simulate, Measure, and Prove it changed, with your Microsoft tenant carrying the email leg.

01
Connect
A scoped Entra ID app registration against the attack simulation endpoints, consented by your administrator. Under an hour
02
Import
Existing Microsoft simulations, outcomes and coverage read in, so the baseline is your real history and not a cold start
03
Orchestrate
Design a sequence across email, SMS, QR, voice and video. Microsoft delivers the email leg, Breacher.ai delivers the rest
04
Score
Every outcome, native and added, resolves to one OSES™ Risk Score on DEPTH and SPREAD across four bands
05
Generate
Build a training module from the finding or from live threat intel, assign it yourself, and track completion next to Microsoft training coverage

Before and after the add-on

Everything on the left keeps working. The right is what gets added on top of it.

Microsoft Attack simulation training
What you have today
Email payloads: link, attachment and QR code
SMS and Teams delivery platforms
Credential harvest, drive-by URL, OAuth consent grant and other built-in techniques
Payload harvesting from real mail detected in your tenant
Training assigned from a fixed catalogue on click or compromise
Repeat offender targeting and predicted compromise rate
Reporting inside the Defender portal
Requires Microsoft 365 E5 or Defender for Office 365 Plan 2. Stays exactly as it is.
With the Breacher.ai add-on
What gets added
Deepfake video call impersonation against live targets
AI voice and vishing against the help desk and finance
Multi-stage sequences that branch on the previous step
Microsoft email stages scheduled from inside the wider campaign
AI micro modules built from the specific finding, not a catalogue
One OSES™ Risk Score across every channel, native and added
Board-ready output: DEPTH, SPREAD, score and band
You operate it. No migration, no payload rebuild, no rip and replace, and a read-only connection is available if you only want the unified reporting.

Free to start, discounted to stay

The connector is in beta. We are being deliberate about how many tenants we onboard while it is, because each one gets direct engineering time.

Open pilot
90 days
Free, while seats last
Full add-on across every channel
Two-way Microsoft Graph sync
Unified OSES™ Risk Score reporting
One orchestrated multi-channel campaign
Standard onboarding support
Open to any organization running Attack simulation training on a qualifying Microsoft licence.

Generate training modules from live threat intel

The part of your awareness program that ages fastest is the content. This is the part you stop waiting on a vendor for.

Microsoft assigns training from a fixed catalogue, matched to the lure type someone fell for. Every other vendor in the category does a version of the same thing. The module was written before the campaign existed, which means it can describe a category of attack but never the one that actually worked on your people.

Breacher.ai gives your team a generator instead of a library. Point it at a live threat intel report, at the real phishing Microsoft harvested from your own tenant, or at the finding from the simulation that ran last week, and it builds a micro module on that specific pretext. Your team writes the prompt, the platform builds the module, you assign it. No content request, no vendor queue, no waiting for the next catalogue refresh.

Modules carry through to the same place everything else does: completion reported next to your Microsoft training coverage, and the behaviour change measured on the same OSES™ Risk Score as the simulation that triggered it.

Live threat intelligence
A sector advisory, a published breach writeup, a new fraud pattern your ISAC flagged this morning. Turn it into training the same day it lands.
Real mail from your own tenant
Microsoft payload harvesting already captures genuine phishing detected in your environment. Build the module from the thing that actually got through your filters.
Your own simulation findings
The pretext that worked, the channel it arrived on, the step where the process broke. Trained on the specific failure rather than the general topic.
Your policies and process
Feed in the payment approval path or the help desk verification standard you want reinforced, and the module teaches your procedure rather than a generic one.
Catalogue model

Content written months ahead of the threat, refreshed on the vendor's schedule, selected by lure category. A request to cover something new goes into a roadmap you do not control.

Generated model

Content built from this week's intelligence by the team that read it, on the pretext your own people fell for, in the language of your own process. Refreshed whenever you decide it needs to be.

What you need before the scoping call

Short list. We confirm all of it with you rather than assuming any of it.

Qualifying licence
Microsoft 365 E5 or Defender for Office 365 Plan 2 for the Microsoft side. E3 tenants can still run the Breacher.ai channels
Administrator consent
A Global Administrator or Security Administrator to consent the scoped app registration
Service agreement
You operate the platform against your own tenant under the service agreement, which sets permitted scope and acceptable use
Verified consent
Anyone whose voice or likeness is cloned completes a biometric and voice verification first. The platform will not generate without it
Simulation allowlisting
Sending domains and numbers allowlisted through your mail flow and filtering so the test measures people, not filters
A named owner
One person on your side who owns the program and receives the findings

Common questions

What is Microsoft Attack Simulation Training?

It is the phishing simulation capability built into Microsoft Defender for Office 365, reached from the Defender portal under Email and collaboration. It sends benign phishing payloads to your own users, tracks who clicked, opened the payload or entered credentials, and assigns training from a built-in catalogue to the people who engaged. It requires Microsoft 365 E5 or Defender for Office 365 Plan 2.

What is the difference between Attack Simulator and Attack simulation training?

They are the same capability under two names. Attack Simulator was the original Office 365 name and was retired around 2020 when the feature moved into Microsoft Defender for Office 365 and was rebuilt as Attack simulation training. Microsoft documentation now uses Attack simulation training exclusively, but the old name is still in wide use, and the portal URL still contains the word attacksimulator.

Does Microsoft Attack Simulation Training support deepfake or voice phishing simulations?

No. Microsoft's own simulation model exposes three delivery platforms: email, SMS and Teams. There is no voice call, no video call and no synthetic media of any kind anywhere in it. Payloads are links, attachments and QR codes inside email. Deepfake video impersonation and AI voice phishing sit entirely outside what the native tool can deliver, which is the specific gap this add-on fills.

Is there an API for Microsoft Attack Simulation Training?

Yes. The Microsoft Graph attack simulation API covers it. On the read side you can list simulations, get a single simulation, pull the report overview and per-user detail, and retrieve tenant-level user coverage and training coverage. On the write side you can create, update and delete simulations. That is what makes a genuine two-way integration possible rather than a report export.

Can Attack simulation training send SMS or Microsoft Teams messages?

SMS and Teams both appear as delivery platforms in Microsoft's simulation model, so the capability exists alongside email. Availability varies by tenant and environment, and some advanced features including payload automation and recommended payloads are not offered in GCC High and DoD. What none of those channels give you is a live voice or video interaction, which is a different kind of test rather than a different message format.

Do we have to replace Microsoft Attack simulation training?

No. That is the point of the add-on. Your Microsoft tenant stays the system of record for email simulations, your existing payloads and campaigns keep running untouched, and nothing is migrated. Breacher.ai adds the channels Attack simulation training does not deliver and brings both sets of results into one view.

What does bi-directional sync actually do?

It uses the Microsoft Graph attack simulation API. Outbound, Breacher.ai can create and schedule simulations in your Microsoft tenant so an email stage sits inside a wider campaign. Inbound, it reads simulation records, per-user outcome detail, user coverage and training coverage back out of Microsoft. Those results are then scored alongside the voice, video, SMS and QR stages that ran outside Microsoft.

Can you write AI training modules into Microsoft's training library?

No, and any vendor telling you otherwise is overselling. Microsoft's training catalogue is delivered through its own content partnership and is not open to third-party content. Breacher.ai builds and hosts AI-generated micro training modules on the OSES™ Behave side, triggered by what a specific simulation exposed, and reports completion next to your Microsoft training coverage rather than inside it.

What licensing do we need?

Attack simulation training itself requires Microsoft 365 E5 or Microsoft Defender for Office 365 Plan 2, and the Graph attack simulation endpoints follow the same entitlement. If you are on E3 you can still run the Breacher.ai channels, you simply will not have a Microsoft side to sync with. We confirm licensing on the scoping call before anything is connected.

What permissions does the connection need?

An Entra ID application registration scoped to the attack simulation endpoints, consented by a Global Administrator or Security Administrator. Read-only is enough if you only want unified reporting. Read and write is needed if you want Breacher.ai to schedule the Microsoft email stage as part of an orchestrated campaign. We will run the narrower of the two unless you ask otherwise.

How is consent handled for voice and video impersonation?

Consent is enforced by the product, not by a form. Before the platform will generate a voice or likeness, the individual being cloned completes a biometric and voice verification of their own consent, and that obligation is carried in the service agreement as well. An administrator cannot authorize the cloning of somebody else, which means no executive voice or likeness is ever produced on the strength of a security team's approval alone. Recorded-call scenarios are separately configured to the recording consent law of every jurisdiction your targets sit in.

Can we build our own training modules from threat intelligence?

Yes, and this is the part most teams tell us they want first. Your team points the generator at a source, a live threat advisory, the real phishing Microsoft harvested from your tenant, a finding from last week's simulation, or your own payment approval policy, and the platform builds a micro module on that specific pretext. You write the prompt, you review the output, you assign it. There is no content request queue and no waiting for a vendor catalogue refresh.

Who runs the simulations, your team or ours?

Yours. This is a platform you operate under a service agreement, not a managed engagement we deliver. Your team designs the campaign, selects the channels, generates the training and reads the results. That is a deliberate difference from our red team services, which are separately scoped and separately priced if you want us running it instead.

What does the beta cost, and what is the catch?

The 90-day pilot is free and open while seats last. When it ends, accepted beta cohort members hold a discounted rate for the following twelve months rather than moving to list price, and that rate is locked for the full term. In exchange we ask for structured feedback on the connector and the reporting model, and the option to reference the engagement pattern in anonymized form. We never name a client in public material. Seats are limited because each beta tenant gets direct engineering support during the connector build.

How long does it take to stand up?

The connection itself is an application registration and a consent grant, usually under an hour once approvals are in hand. The first orchestrated campaign typically runs one to two weeks after the scoping call, with scenario design and consent collection accounting for most of that window.

Apply for the beta

Thirty minutes. We will look at what your Microsoft program covers today and design the first orchestrated campaign around what it does not.

Free 90-day pilot No migration required Read-only option available
Apply for Beta

Or read how we score it on the OSES™ Risk Score page.