Cybears X PhishAI Phishing Simulation

AI-Powered PhishingTurn your weakest link into your strongest sensor

Beyond awareness. Beyond simulation. The AI-native platform that runs realistic phishing across email, SMS, voice, QR & MFA adapts to every employee, scores human risk in dollars, and closes the loop with your SOC, IAM & EDR.

Book a Demo Download data sheet
MSSP-native Arabic · French · Tamazight Sovereign hosting, your jurisdiction
Email QR Voice SMS MFA AitM
Cybears X Phish mascot
Phish-Prone Rate
4.2%
Median Time to Report
4m 12s
Report Rate
73%
Resilience Ratio
17 : 1
Email PhishingSmishingVishingQuishingMFA FatigueAitMDeepfake VishingTeams & WhatsApp Email PhishingSmishingVishingQuishingMFA FatigueAitMDeepfake VishingTeams & WhatsApp
Why XPhish

Click rates lie.
Human risk is the truth.

Where legacy tools report a click percentage and stop, XPhish acts it tightens access, triggers coaching, and feeds intelligence straight back to the SOC. A closed loop, not a quarterly report.

The Problem
Click rates plateau but breaches still happen.
Human risk can't be quantified in dollars the board asks "are we safer?" and gets no answer.
Awareness tools sit in a silo disconnected from the SOC, IAM & EDR.
Compliance ≠ security and email-only sims miss SMS, voice, QR & MFA attacks.
The Solution · A Human Risk OS
A closed loop of AI multi-channel simulation, adaptive learning, behavioral telemetry & automated controls.
It acts tightens access, triggers coaching, and feeds enriched signal back to the SOC.
One unified Human Risk Score (0–1000), quantified as defensible $ exposure.
Sovereign & MEA-native Arabic, French & Tamazight from day one.
200
YoY growth in multi-channel attacks vishing, QRishing, AitM yet most platforms are still email-only.
74
of breaches involve a human element but the board still asks "are we safer?" and gets no number back.
11.8
projected HRM & phishing-simulation market by 2030 and no sovereign, MEA-first leader yet exists.
See It In Action

Watch an attack land
then get caught

A ninety-second explainer of how XPhish works then a full walkthrough of a live multi-channel simulation, from lure to Human Risk Score.

Explainer

Product Explainer

How XPhish works

The threat, the adaptive AI, and the dollar-quantified outcome in the time it takes to fall for one lure.

Live Demo

Live Platform Demo

Guided product tour

Watch a multi-channel campaign launch, adaptive difficulty in action, and the Human Risk Score dashboard end to end.

Omnichannel Threat Realism

Every channel an attacker uses

Email is table stakes. XPhish simulates the full modern kill-chain coordinated across channels, just like a real APT.

Email Phishing
SPF/DKIM/DMARC-aware, lookalike & IDN-homograph domains.
SMS / Smishing
MEA-specific gateways · fake OTP, parcel & banking scams.
Voice / Vishing
TTS scripts in Gulf & Maghrebi Arabic, branching IVR.
QR / Quishing
QR lures in emails, posters & fake invites scan-tracked.
MFA Fatigue
Push-bombing vs. Entra ID, Okta, Duo approve-rate scored.
Adversary-in-the-Middle
Evilginx-class session-theft demos even with MFA. Gated.
Teams · Slack · WhatsApp
Impersonated colleagues & bots on collaboration apps.
Deepfake Vishing
AI-cloned CEO/CFO voice & video consent-gated, audit-trailed.
Adaptive AI Engine

Per-user difficulty.
No template fatigue.

An AI that learns each person's psychology and serves the next-best lure for maximum learning infinite variations, so nobody can warn the next desk.

Adaptive Difficulty AI

Multi-armed-bandit calibration learns which lure types trigger each user and escalates intelligently.

Polymorphic Lures

Same intent, infinite variants per recipient different subject, sender, body & landing page.

BearX Co-Pilot

"Run a Ramadan invoice-fraud sim against finance in Arabic, 4 weeks, escalating." BearX builds & deploys it.

OSINT Spear-Phishing

Auto-enriches targets from LinkedIn, GitHub & news lures that reference real projects & colleagues.

Susceptibility Model

A per-user profile across Cialdini's six levers authority, urgency, curiosity, fear drives lure choice.

Live Attack Mirroring

A real attack at one client becomes a sanitized simulation for every tenant within 24h phishing herd immunity.

Human Risk Management

Risk in dollars,
not click rates

A unified Human Risk Score (0–1000) per user fed by simulations, real reports, browser activity, MFA failures, DLP signals & access privileges translated into board-ready dollar exposure with a FAIR-aligned model.

Closed-loop controls auto-tighten IAM, EDR & conditional access for high-risk users.
Heatmaps & benchmarks by department, geo & role, against MEA-specific peers.
Predictive forecast ML flags next-quarter risk before the clicks happen.
Human Risk Score
LIVE
418
of 1000
Phish resilience81%
Report rate73%
Coaching completion94%
62
$ exposure
240
at-risk
12
repeat clickers
MEA-First & Sovereign

It thinks in your language.
It stays in your country.

Native Arabic (MSA, Gulf & Maghrebi), French & Tamazight authored, not translated plus region-specific lures and sovereign hosting global vendors can't match for years.

Arabic-Native

MSA + Gulf + Maghrebi + Levantine dialects, RTL layout, cultural tropes built in.

French & Tamazight

Maghrebi business French & Tamazight (Latin + Tifinagh) plus a 42-language layer.

Cultural Calendar Lures

Ramadan, Hajj, Eid, local tax deadlines & regional brands Algérie Poste, STC, Etisalat.

Sovereign Hosting

Deploy the platform wherever your sovereignty requires sovereign cloud, in-country or on-prem selectable per tenant, DPIA-ready.

Mapped to ISO 27001 A.6.3 NCA ECC PDPL Loi 18-07 NIST PR.AT PCI 12.6
Integration & Control Plane

Wired into your whole stack

Bidirectional connectors turn the risk score into action and feed enriched signal back to the SOC.

Identity & SSO
Microsoft Entra ID, Okta, Auth0, Ping, Google Workspace.
EDR
CrowdStrike, SentinelOne, Microsoft Defender bidirectional.
SIEM / SOAR
Splunk, Sentinel, QRadar, XSOAR, Tines streaming & playbooks.
Email Gateways
Proofpoint, Mimecast, Barracuda pull real reported phish.
HR / LMS
Workday, SuccessFactors, BambooHR, Cornerstone, Moodle.
Ticketing
ServiceNow & Jira auto-tickets for repeat offenders.
Automated Control
Risk-based: tighten CA, force MFA reset, restrict app access.
API & Webhooks
Full REST API, Terraform provider, campaign-as-code.
MSSP-Native

Built for service
providers from day one

True multi-tenancy, not bolted-on. Onboard a tenant in under four hours, white-label everything, and pool licenses to protect your margin.

White-Label
Per-tenant logo, colors, domain & emails your brand.
Pooled Licensing
Shift seats between tenants, revenue-share automation.
Partner Portal
Onboarding, billing, margin controls, cross-tenant benchmarks.
Red Team Mode
Gated license, consent & chain-of-custody for offensive use.
4
to onboard a brand-new tenant directory sync, brand kit & templates pre-loaded.
100
platform modules across 9 layers from lure DNA to closed-loop control.
The Cybears X Suite

A full-stack human-risk loop

XPhish doesn't work alone. XTI feeds it live threats, XASA delivers the training, and the loop closes back into your SOC and GRC.

X Awareness
Security Awareness

Cinematic training & microlearning that turns the click into a coachable moment.

Explore X Awareness →
X Threat Intel
XTI

Live regional threat intelligence the source of XPhish's real-attack mirroring & actor replays.

GRC & AiDR
Govern & Respond

Risk & compliance plus AI-driven detection & response the loop closes here.

Built For Every Stakeholder

Value for everyone who
carries the risk

CISO

Defend the budget with a dollar metric, pass the audit, and let risk-based controls protect high-risk users automatically.

Awareness Manager

Author full multi-channel campaigns in natural language, localized natively spend time on strategy, not admin.

SOC Manager

Get enriched, prioritized user reports streamed to your SIEM and train analysts on the threats they actually triage.

MSSP & Employee

Onboard tenants in hours under your brand while employees learn in their own language, with empathy, never shame.

Why We Win

What no global vendor can copy

Where KnowBe4 reports and Hoxhunt translates, XPhish acts and thinks regionally from day one.

Live Attack Mirroring
XTI telemetry → 24h sanitized replay across tenants. Nobody else has the feed.
Closed-Loop Control
It doesn't just report risk it tightens access via IAM, EDR & SOAR.
Native Regional Depth
Arabic/French/Tamazight content & sovereign hosting not a translation layer.
$-Quantified Risk
FAIR-aligned exposure your CFO and board actually understand.
BearX Co-Pilot
Natural-language campaign authoring & moment-of-failure coaching.
X Suite Integration
XPhish + XASA + XTI + GRC + AiDR a full-stack human-risk OS.
Plans & Packaging

Three ways to deploy XPhish

From an email baseline to a sovereign, AI-max, MSSP-ready Human Risk OS. Every tier is a superset of the one before it.

9 layers · 84 modules · MVP → V3
Essential
Baseline your human risk fast.
Corecoverage
Email & web phishing · standard hosting
Best for · Mid-market & IT-led teams
Email phishing channel SPF/DKIM/DMARC-aware
Campaign orchestrator + 300+ templates
Generative lure studio + brand library
Arabic · French · English native content
Moment-of-failure coaching + micro-learning
Human Risk Score + CISO dashboard
Microsoft 365 / Entra ID connector
Audit-ready evidence & basic reporting
Start free baseline
Advanced
Most Popular
Full omnichannel realism + adaptive AI.
Completeprogram
All channels + adaptive AI · sovereign hosting available
Best for · Awareness teams & CISOs
Everything in Essential, plus
All channels: SMS · Voice · QR · MFA-fatigue · Teams/WhatsApp
Adaptive Difficulty AI + polymorphic lures
BearX co-pilot + OSINT spear-phishing
Full localization (+Tamazight · 42 languages)
Heatmaps · $-quantified risk · repeat-offender workflow
Gamification + role-based curriculum
IAM · EDR · email-gateway · HR/LMS connectors
Automated control engine + live attack mirroring
DPIA + regulatory mapping · audit vault
Download data sheet
Ultra
Sovereign / Enterprise
AI-max, fully integrated, MSSP-ready.
Customtailored scope
Sovereign · on-prem · MSSP-ready
Best for · Regulated enterprise, Gov & MSSP
Everything in Advanced, plus
Advanced threats: AitM · deepfake voice/video · callback · BitB
Predictive risk forecast + APRP reporting + exec tabletop
Full SIEM/SOAR + universal API / Terraform (CaC)
X Suite bundle (XASA · XTI · GRC · AiDR) + live mirroring
Multi-tenant · white-label · partner portal · pooled licensing
Sovereign / on-prem · customer-managed keys · dedicated tenant
Red Team Mode authorized offensive (add-on)
Dedicated CSM · 24/7 SLA
Talk to sales
+ Red Team Mode adversary simulation (legal & chain-of-custody included) | MSSP pooled licensing volume tiers for large estates | XPhish + XASA bundle available
FAQ

Questions, answered

What security teams ask before running XPhish. Still curious? Talk to our team.

Where global tools report and translate, XPhish acts and thinks regionally: live attack mirroring from XTI telemetry, closed-loop control that tightens IAM/EDR for high-risk users, FAIR-aligned dollar-quantified risk, and Arabic / French / Tamazight content authored natively not machine-translated.

Email, SMS (smishing), voice (vishing), QR (quishing), MFA-fatigue push-bombing, adversary-in-the-middle session theft, and collaboration apps (Teams, Slack, WhatsApp) plus consent-gated deepfake voice & video. One coordinated, cross-channel kill-chain, just like a real APT.

Days, not months. The Microsoft 365 / Entra ID connector, 300+ templates and the BearX co-pilot let you author and launch a multi-channel baseline in natural language and hand back a board-ready Human Risk Score fast.

A unified 0–1000 score per user, fed by simulation results, real reports, browser activity, MFA failures, DLP signals and access privileges then translated into board-ready dollar exposure with a FAIR-aligned model, with predictive next-quarter forecasting.

Yes. Adversary-in-the-middle and deepfake modes are consent-gated, audit-trailed and chain-of-custody controlled, with legal guardrails built in so you can demonstrate real-world threats safely and defensibly.

The platform moves to meet your sovereignty requirements data residency of your choice, whether sovereign cloud, in-country or fully on-prem, selectable per tenant. DPIA-ready and mapped to ISO 27001, NCA ECC, PDPL and NIST.

Yes Microsoft 365 / Entra ID, Okta and Duo, SIEM / SOAR for enriched user reports, and closed-loop IAM & EDR actions that automatically tighten access for high-risk users.

Absolutely. XPhish is MSSP-native: white-label the platform under your brand and onboard new tenants in hours, each with its own sovereign residency, content and reporting.

Resources

Take the details
with you

Everything you need to brief your team and make the case one click away.

PDF

White Paper

The state of human risk in MEA the data, the model, the ROI.

Download PDF
PDF

Battle Card

XPhish vs. KnowBe4 & Hoxhunt where we win, at a glance.

Download PDF
PDF

Data Sheet

Full channel, AI-engine and integration specifications on two pages.

Download PDF
PDF

Flyer

A one-page overview to share across your organization.

Download PDF

See your human risk,
in dollars

Book a pilot and we'll run a multi-channel baseline against your org, then hand you a board-ready Human Risk Score in your language, in your region.