What problem does it solve?
Red teams need a structured, repeatable methodology to run authorized spearphishing simulations that realistically test an organization's email security controls and user awareness, while avoiding common mistakes like broken SPF/DKIM/DMARC setup, unaged domains, and untested payloads that invalidate results.
Core Features & Use Cases
- Five-Phase Campaign Workflow: Covers pretext development, payload development, infrastructure setup, campaign execution, and post-campaign analysis with concrete validation checklists.
- MITRE ATT&CK Mapping: Maps every activity to techniques like T1566.001 (Spearphishing Attachment), T1566.002 (Spearphishing Link), and T1204 (User Execution) for standardized reporting.
- Tool Guidance: Compares GoPhish, Evilginx2, King Phisher, SET, Modlishka, and other open-source phishing frameworks for campaign management and credential harvesting.
- Use Case: A red team operator running an authorized engagement uses this Skill to build a look-alike domain, configure email authentication, send wave-based phishing emails, and measure credential submission rates for the final engagement report.
Quick Start
Ask the AI to walk you through planning an authorized spearphishing simulation campaign, starting with pretext development and email infrastructure setup.