EVS and Hack Records

EVS and Hack Records

Security Insights (EVS & Hack Records)


This article explains how to monitor, analyze, and manage your organization's security posture using the Employee Vulnerability Score (EVS) and Hack Records within the TSAT dashboard.

Monitoring Employee Vulnerability Score (EVS)

The Employee Vulnerability Score (EVS) provides real-time visibility into the overall and individual risk levels of employees based on their interactions with simulation campaigns.

Key Metrics & Overview Widgets:

  • Total Users: Displays the aggregate number of tracked users across the platform.

  • AVG EVS: The collective average risk percentage of your entire organization.

  • Risk Distribution Bar: A color-coded summary categorizing your workforce across four risk tiers:

    • Low (Green)

    • Medium (Yellow)

    • High (Orange/Red)

    • Critical (Dark Red)




Dashboard Controls & Tools:

  • Export CSV: Click the Export CSV button in the top right to download a spreadsheet of all employee EVS metrics.

  • Search: Quickly locate any employee by typing their name or email into the search field.

  • Filter Options: Filter user lists by specific risk levels or departments.

  • Pagination & Rows: Adjust the dropdown to choose how many records display per page (e.g., 10, 25, 50).

  • View Details: Click the Eye Icon (👁️) on the far right of any user row to open their detailed drawer/profile.

Analyzing Individual Employee Data

Clicking the Eye Icon (👁️) opens an interactive side-drawer displaying detailed behavioral analytics for that specific user.

Profile Breakdown:

1. Header & Risk Indicator

  • Attack Vector Filter: Select specific vectors (e.g., Phishing, Smishing, Vishing) or leave set to Overall.

  • EVS Score Gauge: A visual dial displaying the user's current EVS percentage and risk severity level (Critical, High, Medium, Low).

2. Detailed Tabs:

  • Score Analysis Tab:

    • EVS Score Breakdown: Displays risk scores categorized by attack vector.

    • EVS Trend Graph: A chronological chart illustrating how the user's vulnerability score has changed over time.

    • Breach Count: Displays total breaches out of total campaigns assigned (e.g., 2 times out of 3).

    • Minimum Breach Time: The fastest time recorded for the user falling for a simulation link/prompt.

    • Repeat Offender & Campaign Summary: Visual charts showing repeat compromise counts and total assigned campaigns.

  • Campaigns Tab: Switch to this tab to review a full history of specific simulation campaigns sent to the user and their actions (e.g., opened, clicked, submitted data, passed).

Understanding Hack Records

Hack Records serve as a central search repository to check if an employee's credentials or email address have appeared in known breach databases or simulation compromises.

Checking for Breaches:

  1. Navigate to Security Insights > Hack Record on the left menu.

  2. Enter the employee's email address in the Enter email search bar.

  3. Click Search.

  4. If a breach is found, a table will display specific records.


Frequently Asked Questions (FAQ)

Why does a user display as "User not found" in the list?

If a row shows "User not found" under the name field, it indicates that the employee has been deleted or removed from the active user directory in TSAT, but their historical simulation data is retained for risk reporting continuity.

Why is an employee's EVS 0%?

An EVS of 0% means the employee has either not yet been included in any active simulation campaigns or has successfully passed every assigned simulation without failing any security checks.

What is the difference between EVS and a Hack Record?

  • EVS is an ongoing, dynamic risk score calculated from user responses in phishing simulations.

  • Hack Record is a historical breach detection tool that searches known dark-web or past leak databases for compromised employee credentials.


    • Related Articles

    • What is a hack record?

      Hack record is a feature of the tool that allows you to find out if your employee's official email ID has been compromised. It also lists down all the third-party platforms where the ID has been compromised.
    • How Employee Vulnerability Score (EVS) Is Calculated?

      Employee Vulnerability Score (EVS) is a feature of ThreatCop which is used to measure how vulnerable are employees within an organization. The score is calculated on the basis of different parameters of the complete simulated attack campaign ...
    • How do you extract the data provided by Hack record?

      We have partnered with various external APIs that fetch this information for us.
    • TSAT Campaign Workflow: Scheduling, Running, and Analysis

      Campaign Workflow: Scheduling, Running, and Analysis This article provides a step-by-step guide for Admins and Org Admins on managing the lifecycle of a simulation—from technical testing and template selection to launching campaigns and analyzing ...
    • How is Top Repeat Offenders different from Most Vulnerable Employees?

      Top Repeat Offenders : These are users or employees who have been targeted by phishing attempts, meaning they have submitted their data in multiple campaigns. The compilation of these individuals forms the Repeat Offenders List. You'll locate the ...