Runs authorized phishing, vishing, and deepfake attacks on employees to test whether detection tools actually catch them.
GhostEye is a security-testing platform that launches authorized social-engineering attacks — phishing emails, scam calls, texts, and deepfake attempts — against an organization's own employees, then follows what happens after someone clicks or responds. It checks whether the company's existing detection stack and EDR tooling actually flag the resulting activity, rather than just measuring who fell for the message. The company is a New York-based startup founded in 2025 and backed by Y Combinator. Pricing isn't published: GhostEye sells an annual platform fee plus a per-headcount tier, quoted after a call.
Sold as an annual platform fee plus a per-headcount tier; no list price is published, quote given after a call.
Use tool ↗GhostEye goes past the usual click-rate phishing test by tracing what happens after an employee falls for a simulated attack, checking whether the security team's own detection tools would have caught it. That follow-through is the differentiator, but it's an enterprise sale with no public price and no self-serve option.
Watch out: As an authorized-attack tool it needs sign-off and coordination with IT/security leadership before running — it is not something to point at employees without internal buy-in.
No reviews yet — be the first to review Ghosteye.
Reviews are tied to your EffectHub account — one review per tool, so the rating for Ghosteye reflects real users.
No questions yet — ask the first one about Ghosteye.
Questions about Ghosteye are tied to your EffectHub account, so answers can reach you and the section stays free of spam.