executing-phishing-simulation-campaign

Automate GoPhish phishing campaigns via REST API with metrics reporting.

2|Updated Apr 14, 2026
One-click install
npx skills add https://github.com/Acczdy/MoZiSec --skill executing-phishing-simulation-campaign
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: executing-phishing-simulation-campaign
Source: https://github.com/Acczdy/MoZiSec/tree/main/penetration-testing/.claude/skills/executing-phishing-simulation-campaign
Command: npx skills add https://github.com/Acczdy/MoZiSec --skill executing-phishing-simulation-campaign

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires requests, and includes scripts (resource) and references (resource) components.

What problem does it solve?

Executes authorized phishing simulation campaigns to assess an organization's susceptibility to email-based social engineering attacks. The tester designs realistic phishing scenarios, builds credential harvesting infrastructure, sends targeted phishing emails, and tracks open rates, click-through rates, and credential submission rates to measure human security awareness. Activates for requests involving phishing simulation, social engineering assessment, email security testing, or security awareness measurement.

Core Features & Use Cases

  • GoPhish-based campaign management: templates, landing pages, target groups, and real-time metrics.
  • Scenario planning and risk assessment: authorized red-team-like exercises to establish baselines and training needs.
  • Compliance and reporting: documentation of authorization, scope, and results for stakeholders.

Quick Start

Set up an authorized phishing campaign by configuring GoPhish, importing targets, creating a template and landing page, and launching the campaign to collect results.

Frequently Asked Questions about executing-phishing-simulation-campaign

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run a phishing simulation campaign with GoPhish?

Run a phishing simulation campaign by using a GoPhish-based REST API workflow to create email templates, landing pages, target groups, and campaigns. The Skill automates sending targeted phishing emails and tracks open rates, click-through rates, and credential submissions.

What metrics are tracked during a security awareness phishing simulation?

Phishing simulation metrics tracked include email open rates, click-through rates, and credential submission rates. These metrics measure human security awareness and establish baselines for training needs within security awareness programs.

Can I automate sending phishing emails and aggregating results through a REST API?

Yes, you can automate sending phishing emails and aggregating results through the GoPhish REST API. The workflow creates templates, landing pages, target groups, and campaigns programmatically, then collects and reports the simulation metrics.

Do I need to install external libraries to use this phishing simulation automation?

You need the requests library installed to use this phishing simulation automation. The Skill depends on the requests package to interact with the GoPhish REST API for campaign management and metrics aggregation.

When should I use phishing simulation in a red-team exercise?

Use phishing simulation in authorized red-team exercises to assess an organization's susceptibility to email-based social engineering attacks. It helps evaluate email security, user reporting behaviors, and incident response capabilities in a controlled testing environment.

What is the best way to document authorization for a social engineering assessment?

The best way to document authorization for a social engineering assessment is by recording the authorization scope and campaign results for stakeholders. The Skill supports compliance and reporting by generating documentation of the authorized phishing simulation scope and metrics.