Executing Phishing Simulation Campaign
Overview
Cybersecurity skill for executing phishing simulation campaign. Follows industry best practices and security standards.
When to Use
Trigger phrases:
"executing phishing simulation campaign"
"Executes authorized phishing simulation campaigns to assess an organization's su"
Measuring employee susceptibility to phishing attacks as part of a security awareness program
Testing the effectiveness of email security controls (secure email gateway, DMARC, SPF, DKIM)
Conducting the social engineering component of a red team exercise to gain initial access
Establishing a baseline for phishing susceptibility before deploying security awareness training
Validating that incident response procedures work when employees report suspicious emails
Do not use without explicit written authorization from the organization's leadership, for actual credential theft beyond the authorized scope, for targeting individuals personally rather than professionally, or for sending phishing emails that could cause psychological harm or legal liability.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Written authorization from executive leadership specifying the campaign scope, target groups, and escalation procedures
- Coordination with the IT/security team to whitelist the sending infrastructure (or test whether it bypasses controls, depending on scope)
- GoPhish or equivalent phishing platform configured with a sending domain, SMTP relay, and landing page infrastructure
- Phishing domain registered and configured with SPF, DKIM, and DMARC records to maximize deliverability
- Employee email list from HR, organized by department for targeted campaigns
- Incident response team briefed on the campaign timeline and escalation procedures
Workflow
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
- Define Objectives — Clarify the goals and scope for phishing simulation campaign.
- Gather Resources — Collect tools, data, and access needed for phishing simulation campaign.
- Execute Process — Carry out phishing simulation campaign operations methodically.
- Verify Quality — Check results against acceptance criteria.
- Document Outcomes — Record findings, decisions, and next steps.
Tools
- Analysis Platform — Data processing and visualization
- Collaboration Tools — Team coordination and knowledge sharing
Process
- Reconnaissance — Gather target information, identify attack surface, enumerate services
- Analysis/Exploitation — Execute the technique, analyze results, document findings
- Reporting — Document IOCs, write findings, provide remediation recommendations
Verification
Anti-Rationalization Table
| Rationalization |
Reality |
| "We are too small to be targeted" |
Automated attacks target everyone. Size does not matter. |
| "Security slows us down" |
A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" |
Vulnerabilities in production are exploited within hours. Fix before deploy. |
1---2name: executing-phishing-simulation-campaign3description: Use when executes authorized phishing simulation campaigns to assess an organization's susceptibility to email-based social engineering attacks. The tester designs realistic phishing scenarios, builds credential harvesting infrastructure, sends targeted phishing emails, and tracks open rates, click-through rates, and credential submission rates to measure human security awareness. Use when working with executing phishing simulation campaign.4license: Apache-2.05---67# Executing Phishing Simulation Campaign89## Overview1011Cybersecurity skill for executing phishing simulation campaign. Follows industry best practices and security standards.1213## When to Use14**Trigger phrases:**15- "executing phishing simulation campaign"16- "Executes authorized phishing simulation campaigns to assess an organization's su"171819- Measuring employee susceptibility to phishing attacks as part of a security awareness program20- Testing the effectiveness of email security controls (secure email gateway, DMARC, SPF, DKIM)21- Conducting the social engineering component of a red team exercise to gain initial access22- Establishing a baseline for phishing susceptibility before deploying security awareness training23- Validating that incident response procedures work when employees report suspicious emails2425**Do not use** without explicit written authorization from the organization's leadership, for actual credential theft beyond the authorized scope, for targeting individuals personally rather than professionally, or for sending phishing emails that could cause psychological harm or legal liability.262728## When NOT to Use2930- When you lack proper authorization for testing31- For production systems without change management32- When the task requires legal or compliance expertise beyond technical scope333435## Prerequisites3637- Written authorization from executive leadership specifying the campaign scope, target groups, and escalation procedures38- Coordination with the IT/security team to whitelist the sending infrastructure (or test whether it bypasses controls, depending on scope)39- GoPhish or equivalent phishing platform configured with a sending domain, SMTP relay, and landing page infrastructure40- Phishing domain registered and configured with SPF, DKIM, and DMARC records to maximize deliverability41- Employee email list from HR, organized by department for targeted campaigns42- Incident response team briefed on the campaign timeline and escalation procedures4344## Workflow4546```python47# Example: IOC detection48import re4950IOC_PATTERNS = {51 "ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",52 "domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",53 "hash_md5": r"\b[a-f0-9]{32}\b",54 "hash_sha256": r"\b[a-f0-9]{64}\b",55}5657def extract_iocs(text: str) -> dict:58 return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}59```60611. **Define Objectives** — Clarify the goals and scope for phishing simulation campaign.622. **Gather Resources** — Collect tools, data, and access needed for phishing simulation campaign.633. **Execute Process** — Carry out phishing simulation campaign operations methodically.644. **Verify Quality** — Check results against acceptance criteria.655. **Document Outcomes** — Record findings, decisions, and next steps.6667## Tools6869- **Analysis Platform** — Data processing and visualization70- **Collaboration Tools** — Team coordination and knowledge sharing717273## Process74751. **Reconnaissance** — Gather target information, identify attack surface, enumerate services761. **Analysis/Exploitation** — Execute the technique, analyze results, document findings771. **Reporting** — Document IOCs, write findings, provide remediation recommendations7879## Verification8081- [ ] All phishing simulation campaign procedures executed completely and documented82- [ ] Findings validated against multiple data sources83- [ ] False positives identified and filtered84- [ ] Results documented with evidence and timestamps85- [ ] Recommendations provided with risk-based prioritization8687## Anti-Rationalization Table8889| Rationalization | Reality |90|---|---|91| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |92| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |93| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |