HERALD addresses the weakest link in enterprise security: human behaviour. Automated phishing simulations run continuously against all employees — with difficulty and targeting adapted based on each individual's risk profile. Click rates, reporting rates, and repeat behaviour are tracked and scored. Employees who fall for simulations are automatically routed to targeted training modules. HERALD integrates with AUGUR to target simulations using the same techniques actively used by tracked threat actors against your industry.
HERALD operates as a fully integrated node within the PHALANX unified intelligence fabric. All telemetry flows bidirectionally through the PHALANX CORE event bus, enabling real-time correlation across all seven applications without data silos or integration overhead.
HERALD supports all four PHALANX deployment models. Select the configuration that matches your infrastructure requirements and regulatory constraints.
HERALD is configured via YAML policy files deployed through the PHALANX CLI or management API. Configuration changes apply within 30 seconds without restart.
All configuration changes are logged immutably. Use phalanx config diff to preview changes before applying to production environments.
The HERALD REST API provides programmatic access to all module capabilities. All endpoints require Bearer token authentication using a PHALANX API key.
HERALD integrates with 16+ external platforms across 5 categories. All integrations are configured through the PHALANX management console or API.