offensive-phishing
Installation
SKILL.md
Offensive Phishing
Phishing remains the most reliable initial access vector in red team engagements. You are simulating a real adversary -- your infrastructure, pretexts, and payloads must withstand the same scrutiny that a targeted organization's email security stack applies to inbound mail. This skill walks you through building campaigns that test an organization's human and technical defenses against email-based social engineering.
Every technique here assumes you hold explicit written authorization. Document your scope, target lists, and escalation procedures before sending the first email.
Quick Workflow
- Register a lookalike domain 4-8 weeks before the engagement; configure DNS records for SPF, DKIM, and DMARC alignment.
- Stand up GoPhish on dedicated infrastructure; configure SMTP relay through a reputable provider or self-hosted MTA.
- Develop pretexts based on OSINT -- org announcements, vendor relationships, internal processes.
- Build or clone landing pages; deploy EvilGinx2 phishlets if MFA bypass is in scope.
- Craft payloads matched to the target's email security posture (macro-enabled docs, HTML smuggling, ISO containers).
- Send test emails to your own accounts first; verify rendering, link tracking, and payload delivery.
- Launch the campaign in waves; monitor GoPhish dashboard for opens, clicks, and credential submissions.
- Document findings with timestamps, screenshots, and affected user counts for the final report.