phishing-technique

Installation
SKILL.md

Phishing Technique

Goal: design, configure, and operate phishing infrastructure that models real adversary tradecraft while staying inside written rules of engagement.

When this technique applies

  • Engagement authorizes phishing or social engineering.
  • Need to set up GoPhish, Evilginx (v3.x), Muraena, or Modlishka.
  • Need domain reconnaissance for lookalike domains.
  • Need to configure email authentication for deliverability.
  • Need MFA/session interception via AitM proxy, device code flow abuse, or Browser-in-the-Browser when explicitly authorized.

Boundary

  • Pretext design and awareness training: social-engineering-technique.
  • Payload generation: offensive-coding/shellcode-dev/, offensive-tools/exploits/metasploit/.
  • Post-exploitation: post-exploit-technique.

Authorization gate

Installs
4
GitHub Stars
22
First Seen
Sep 5, 2026
phishing-technique — aeondave/malskill