Microlearning drills
One attack, one decision, two to four minutes. Every drill below runs in the browser on the interface the attack actually arrives in. Pick a vector and play it.
Every vector, playable right now
Every live drill runs on a public seed. Click one and it opens in place, with no account and no data collected.
What is a microlearning drill?
A microlearning drill is a two to four minute security simulation that drops one person into one attack, rendered in the interface that attack really arrives in.
One drill for every attack vector
- Email phishing
- Smishing (SMS)
- Vishing (voice call)
- Chat (Teams / Slack)
- MFA fatigue
- Quishing (QR code)
- Fake login page
- AI chat data-leak
- Attack chain
- OAuth consent
- Malicious attachment
- Social media / OSINT
- Deepfake
Drills differ from a full training exercise in scope. An exercise teaches a topic end to end and runs five to ten minutes, while a drill tests one decision: click or do not click, approve or deny, hang up or keep talking. The learner acts first and reads the explanation second.
That makes the drill the right unit for repetition. Teams run them monthly, right after a failed phishing simulation, or as the follow-up a rising human risk score triggers, without pulling anyone off work for an hour.
Drill or exercise?
Both ship in every plan. They answer different questions.
A drill
- Two to four minutes, one attack vector
- Tests a single decision under time pressure
- Built for repetition: monthly, or triggered by a failed simulation
- Renders the real interface: an inbox, a phone, a consent screen
An exercise
- Five to ten minutes, one topic end to end
- Teaches the concept, then checks comprehension
- Built for coverage: onboarding, annual refresh, compliance evidence
- Over 200 of them across eight catalogue categories
Frequently asked questions
How long does a microlearning drill take?
Two to four minutes. Most land at two.
That is deliberate: a drill tests one decision, so it ends the moment the learner makes it and reads why it was right or wrong.
Do employees need an account to play a drill?
Not for the public drills on this page. They run anonymously in the browser with no signup and no data collected.
Inside a customer tenant, drills are assigned to named users so completion and outcomes feed reporting and the human risk score.
How are drills different from phishing simulations?
A phishing simulation sends a real lure to a real mailbox or phone and measures what people do with it, unannounced.
A drill is training the learner knows they are in. It is where someone practices the decision, usually right after a simulation caught them out.
Can we build drills for our own attack surface?
Yes. Drills are authored in the RansomLeak LMS, and every customer builds an unlimited number of them.
Teams commonly rebuild a phish their staff genuinely reported, so the practice matches the lures actually hitting the organization. Run the result on our LMS, or export it as a SCORM package for the LMS you already run.
Which vectors do the drills cover?
Every social-engineering vector we train: email phishing, smishing, vishing, chat impersonation, MFA fatigue, quishing, fake login pages, AI chat data leaks, multi-step attack chains, OAuth consent, malicious attachments, OSINT oversharing, and deepfakes.
Most have a public demo today. The deepfake drill ships to customers and its public seed is still in production.
See RansomLeak in Action
Try the free exercises or book a demo to see analytics, SCORM export, SSO, and custom content in your environment.