offensive-phishing

Featured

Phishing campaign execution methodology for authorized red team engagements. Covers end-to-end campaign lifecycle: infrastructure provisioning (GoPhish, SMTP relay configuration, domain acquisition and aging, SPF/DKIM/DMARC alignment), payload delivery vectors (Office macro weaponization, HTA droppers, ISO/IMG container abuse, LNK shortcut hijacking, OneNote embedded payloads, HTML smuggling), email authentication bypass techniques (SPF softfail exploitation, DKIM replay attacks, display name spoofing, homoglyph and cousin domain registration), credential harvesting with MFA bypass (EvilGinx2 transparent proxy, Modlishka session relay, pixel-perfect HTML cloning), spear phishing pretext development informed by OSINT, email security gateway evasion, QR code phishing (quishing), and callback phishing for initial access. Integrates with GoPhish for campaign management, EvilGinx2 for adversary-in-the-middle credential interception, King Phisher for template design, and the Social Engineering Toolkit for payload g

Web & Frontend 3,234 stars 523 forks Updated 1 weeks ago MIT

Install

View on GitHub

Quality Score: 91/100

Stars 20%
100
Recency 20%
90
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# Offensive Phishing Phishing remains the most reliable initial access vector in red team engagements. You are simulating a real adversary -- your infrastructure, pretexts, and payloads must withstand the same scrutiny that a targeted organization's email security stack applies to inbound mail. This skill walks you through building campaigns that test an organization's human and technical defenses against email-based social engineering. Every technique here assumes you hold explicit written authorization. Document your scope, target lists, and escalation procedures before sending the first email. ## Quick Workflow 1. Register a lookalike domain 4-8 weeks before the engagement; configure DNS records for SPF, DKIM, and DMARC alignment. 2. Stand up GoPhish on dedicated infrastructure; configure SMTP relay through a reputable provider or self-hosted MTA. 3. Develop pretexts based on OSINT -- org announcements, vendor relationships, internal processes. 4. Build or clone landing pages; deploy EvilGinx2 phishlets if MFA bypass is in scope. 5. Craft payloads matched to the target's email security posture (macro-enabled docs, HTML smuggling, ISO containers). 6. Send test emails to your own accounts first; verify rendering, link tracking, and payload delivery. 7. Launch the campaign in waves; monitor GoPhish dashboard for opens, clicks, and credential submissions. 8. Document findings with timestamps, screenshots, and affected user counts for the final report. --- ## Infrastructu...

Details

Author
SnailSploit
Repository
SnailSploit/Claude-Red
Created
6 months ago
Last Updated
1 weeks ago
Language
Python
License
MIT

Similar Skills

Semantically similar based on skill content — not just same category

DevOps & Infrastructure Featured

offensive-social-engineering

Social engineering attack techniques beyond email phishing for authorized red team and physical penetration testing engagements. Covers pretexting methodology (persona creation, authority and urgency psychological triggers, rapport building), vishing (voice phishing via caller ID spoofing, IVR system exploitation, VoIP infrastructure setup with Twilio/Asterisk), smishing (SMS-based phishing, carrier gateway abuse, short code impersonation), physical social engineering (tailgating and piggybacking, RFID badge cloning with Proxmark3, lock picking and bypass, dumpster diving for sensitive documents), USB drop attacks (Rubber Ducky keystroke injection, Bash Bunny multi-vector payloads, O.MG cable covert implants, BadUSB firmware attacks), watering hole attack planning and execution, and OSINT-driven targeting (LinkedIn harvesting, organizational chart reconstruction, employee pattern analysis). Integrates with the Social Engineering Toolkit for attack automation, Proxmark3 for RFID/NFC cloning, USB Rubber Ducky a

3,234 Updated 1 weeks ago
SnailSploit
AI & Automation Listed

initial-access

Initial access methodology for authorized red team engagements. Covers phishing, payload delivery, drive-by compromise, supply chain entry points, and living-off-the-land initial access techniques.

1 Updated 3 weeks ago
sunilgentyala
AI & Automation Solid

phishing-simulation-analysis

Phishing-simulation campaign analysis: click-rate trend direction across campaigns, repeat-clicker identification with remedial-training cross-reference, and optional enrichment that correlates simulated failures with real-world phishing incidents from a connected email-security tool as a compounding risk signal.

45 Updated 1 weeks ago
wyre-technology