Phishing Attacks

Guide phishing attack simulations using Shellphish and Wifiphisher for penetration testing.

34|10|Updated Feb 27, 2025
One-click install
npx skills add https://github.com/zebbern/SecOps-CLI-Guides --skill phishing-attacks
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: Phishing Attacks
Source: https://github.com/zebbern/SecOps-CLI-Guides/tree/main/skills/phishing-attacks
Command: npx skills add https://github.com/zebbern/SecOps-CLI-Guides --skill phishing-attacks

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill helps security professionals assess and improve an organization's resilience against phishing and social engineering attacks by simulating real-world scenarios.

Core Features & Use Cases

  • Phishing Simulation: Utilize tools like Shellphish and Wifiphisher to create and deploy phishing campaigns.
  • Credential Harvesting: Demonstrate how attackers capture sensitive information.
  • Security Awareness Training: Provide insights and resources to educate users on recognizing and avoiding phishing attempts.
  • Use Case: Conduct an authorized phishing simulation using Shellphish to test employee susceptibility to credential harvesting via a fake login page, then use the results to tailor security awareness training.

Quick Start

Use the phishing attacks skill to simulate a WiFi phishing attack using Wifiphisher.

Frequently Asked Questions about Phishing Attacks

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I simulate a phishing attack for security awareness training?

You simulate a phishing attack for security awareness by utilizing tools like Shellphish to deploy fake login pages for credential harvesting, or Wifiphisher to execute WiFi-based social engineering attacks.

What is credential harvesting and how does Shellphish demonstrate it?

Credential harvesting is the capture of sensitive login information by attackers. Shellphish demonstrates this during a phishing simulation by creating fake login pages that collect user credentials submitted during authorized penetration testing.

Can I use Wifiphisher to conduct WiFi-based phishing attacks?

Yes, you can use Wifiphisher to conduct WiFi-based phishing attacks. It is specifically covered as a core tool for simulating scenarios where attackers manipulate wireless connections to execute social engineering campaigns.

Do I need authorization before running a phishing simulation with these tools?

Yes, you must obtain explicit authorization before running a phishing simulation. The skill requires an understanding of social engineering principles and stresses that testing an organization's resilience must be properly authorized.

What is the best way to test employee susceptibility to social engineering?

The best way to test employee susceptibility to social engineering is by conducting an authorized phishing simulation using Shellphish to deploy fake login pages, then analyzing the credential harvesting results to tailor security awareness training.