Comprehensive phishing operations project covering the full social engineering kill chain — from GoPhish infrastructure setup and email template crafting to multi-wave campaign execution, credential harvesting, and Business Email Compromise (BEC) simulation. Each campaign wave was designed with increasing sophistication to test different layers of human defense.
Four escalating campaign waves designed using GoPhish framework, each targeting different organizational behaviors and security awareness levels.
Broad generic phishing email with urgent password reset request. Designed to establish a baseline click-through rate and identify the most vulnerable segments of the organization. Low sophistication with obvious red flags for security-aware users.
Targeted spear-phishing emails crafted using OSINT-gathered employee information and role-specific context. Emails appeared to come from internal departments (IT, HR) with personalized details to increase credibility and bypass content filters.
Business Email Compromise simulation impersonating the CEO requesting urgent wire transfer to a vendor. Tested organizational response to executive impersonation and financial fraud scenarios. Included follow-up email pressure tactics.
Sophisticated credential harvesting campaign using cloned login pages for Office 365 and internal portals. Captured credentials via HTTPS phishing pages hosted on GoPhish. Tested MFA adoption and credential reuse awareness across the organization.
Phishing techniques mapped to the MITRE ATT&CK Enterprise framework.
T1566 — Phishing
T1566.001 — Spear Phishing
T1566.002 — Spear Phishing Link
T1417 — Input Capture
T1556 — Modify Auth Process
T1114 — Email Collection
T1056 — Input Capture
T1557 — Adversary-in-the-Middle
T1036 — Masquerading
Complete phishing operations documentation covering infrastructure setup, campaign wave designs, click-through metrics, credential harvesting results, and security awareness recommendations.
Full deliverables available in the project repository.