Sign in as a Global Admin to grant application permissions. This allows the simulator to generate traffic across your tenant's Exchange, OneDrive, SharePoint, and Teams.
Connect M365 TenantValidate your M365 security posture using the industry-standard EICAR antivirus test string and simulated ransomware-activity patterns. No real malware, no encryption, no data loss.
M365SecurityTest/
for easy cleanup.
Sends emails with EICAR attachment. Triggers Safe Attachments / ATP.
Uses users selected on Simulation tab.
Uploads EICAR files to each selected user's OneDrive.
Uploads EICAR to SharePoint sites selected on the Simulation tab.
Uploads EICAR to Teams channels selected on the Simulation tab.
Uploads a batch of pseudo-random-content files with ransomware extensions
(.locked,
.encrypted,
.wncry, etc.)
plus a README_RESTORE_FILES.txt
ransom note. Designed to trigger Defender for Cloud Apps mass-file-activity rules.
No files are actually encrypted.
One ransom note + N files per selected user.
Uses sites selected on Simulation tab.
Uses teams selected on Simulation tab.