offensive-phishing

Installation
SKILL.md

Offensive Phishing

Phishing remains the most reliable initial access vector in red team engagements. You are simulating a real adversary -- your infrastructure, pretexts, and payloads must withstand the same scrutiny that a targeted organization's email security stack applies to inbound mail. This skill walks you through building campaigns that test an organization's human and technical defenses against email-based social engineering.

Every technique here assumes you hold explicit written authorization. Document your scope, target lists, and escalation procedures before sending the first email.

Quick Workflow

  1. Register a lookalike domain 4-8 weeks before the engagement; configure DNS records for SPF, DKIM, and DMARC alignment.
  2. Stand up GoPhish on dedicated infrastructure; configure SMTP relay through a reputable provider or self-hosted MTA.
  3. Develop pretexts based on OSINT -- org announcements, vendor relationships, internal processes.
  4. Build or clone landing pages; deploy EvilGinx2 phishlets if MFA bypass is in scope.
  5. Craft payloads matched to the target's email security posture (macro-enabled docs, HTML smuggling, ISO containers).
  6. Send test emails to your own accounts first; verify rendering, link tracking, and payload delivery.
  7. Launch the campaign in waves; monitor GoPhish dashboard for opens, clicks, and credential submissions.
  8. Document findings with timestamps, screenshots, and affected user counts for the final report.

Installs
32
GitHub Stars
6.1K
First Seen
Aug 27, 2026
offensive-phishing — snailsploit/claude-red