Skip to main content
Offensive Security Project — 2025

Phishing Operations
Campaign Design & Kill Chain

Comprehensive phishing operations project covering the full social engineering kill chain — from GoPhish infrastructure setup and email template crafting to multi-wave campaign execution, credential harvesting, and Business Email Compromise (BEC) simulation. Each campaign wave was designed with increasing sophistication to test different layers of human defense.

MITRE ATT&CK NIST SP 800-53 CIS Controls

Project at a Glance

0[1] Campaign Waves
0[2] Phishing Vectors
0[3] MITRE Techniques
0[4] Target Users

Multi-Wave Phishing Simulation

Four escalating campaign waves designed using GoPhish framework, each targeting different organizational behaviors and security awareness levels.

Wave 1 — Generic Phish

Broad generic phishing email with urgent password reset request. Designed to establish a baseline click-through rate and identify the most vulnerable segments of the organization. Low sophistication with obvious red flags for security-aware users.

Wave 2 — Spear Phish

Targeted spear-phishing emails crafted using OSINT-gathered employee information and role-specific context. Emails appeared to come from internal departments (IT, HR) with personalized details to increase credibility and bypass content filters.

Wave 3 — CEO BEC

Business Email Compromise simulation impersonating the CEO requesting urgent wire transfer to a vendor. Tested organizational response to executive impersonation and financial fraud scenarios. Included follow-up email pressure tactics.

Wave 4 — Credential Harvest

Sophisticated credential harvesting campaign using cloned login pages for Office 365 and internal portals. Captured credentials via HTTPS phishing pages hosted on GoPhish. Tested MFA adoption and credential reuse awareness across the organization.

MITRE ATT&CK Mapping

Phishing techniques mapped to the MITRE ATT&CK Enterprise framework.

Initial Access

T1566 — Phishing
T1566.001 — Spear Phishing
T1566.002 — Spear Phishing Link

Credential Access

T1417 — Input Capture
T1556 — Modify Auth Process

Collection

T1114 — Email Collection
T1056 — Input Capture

Defense Evasion

T1557 — Adversary-in-the-Middle
T1036 — Masquerading

Full Project Report

Complete phishing operations documentation covering infrastructure setup, campaign wave designs, click-through metrics, credential harvesting results, and security awareness recommendations.

Download Report (PDF) Back to Red Team

References

  1. Campaign Plan — 4-phase phishing simulation (recon, template design, launch, post-campaign analysis) using GoPhish framework.
  2. Template Library — 3 email templates (credential harvest, BEC, malicious attachment) with landing page replicas.
  3. Infrastructure Map — 7 components including VPS, GoPhish server, tracking domain, landing pages, and SMTP relay.
  4. Campaign Results — 500 targets across 3 departments with click-rate analysis and security awareness recommendations.

Full deliverables available in the project repository.