What problem does it solve?
Organizations cannot measure their human attack surface or validate security awareness training without controlled simulations of real-world deception techniques, and ad-hoc phishing tests often miss critical signals like report rates, MFA bypass feasibility, and non-email vectors.
Core Features & Use Cases
- Multi-Channel Campaign Design: Structured phases covering OSINT target profiling, GoPhish phishing campaigns, vishing call scripts, and physical pretexting scenarios such as tailgating and USB drops.
- MFA Bypass Validation: Guidance for using Evilginx2 reverse-proxy phishing to test whether session-token theft defeats MFA, with explicit authorization requirements.
- Metrics and Remediation: Templates for campaign result dashboards, risk scoring by attack vector, and prioritized remediation recommendations such as FIDO2 deployment and email gateway hardening.
- Use Case: A red team lead scoping an annual social engineering assessment uses this Skill to build a target selection matrix, configure a GoPhish campaign against finance and help-desk staff, run a vishing pretext, and produce a report measuring click, credential-submission, and report rates.
Quick Start
Ask the AI to design a social engineering penetration test plan for your organization covering phishing, vishing, and physical pretexting with defined success metrics and remediation priorities.