phishing-technique
Installation
SKILL.md
Phishing Technique
Goal: design, configure, and operate phishing infrastructure that models real adversary tradecraft while staying inside written rules of engagement.
When this technique applies
- Engagement authorizes phishing or social engineering.
- Need to set up GoPhish, Evilginx (v3.x), Muraena, or Modlishka.
- Need domain reconnaissance for lookalike domains.
- Need to configure email authentication for deliverability.
- Need MFA/session interception via AitM proxy, device code flow abuse, or Browser-in-the-Browser when explicitly authorized.
Boundary
- Pretext design and awareness training:
social-engineering-technique. - Payload generation:
offensive-coding/shellcode-dev/,offensive-tools/exploits/metasploit/. - Post-exploitation:
post-exploit-technique.