Phishing operations: from zero to one
A one-day intensive workshop on planning, running and measuring phishing campaigns in authorised engagements.
This training is delivered in Portuguese (pt-BR). All sessions, materials and exercises are in Portuguese.
To build the capacity to plan, run and measure a phishing campaign in an authorised engagement, from initial reconnaissance to the delivery of the report.
The course walks the full lifecycle of a campaign, treating each stage as a decision to be justified rather than a procedure to be repeated. The pretext comes out of the reconnaissance; the infrastructure comes out of the pretext; and the results only mean anything in light of both. By the end, participants should be able to run a complete campaign and defend the technical and scoping choices they made along the way.
All content is presented in the context of authorised engagements, with formal authorisation and rules of engagement agreed before any execution.
BY THE END OF THE TRAINING, YOU WILL BE ABLE TO
- Plan a campaign from reconnaissance of the target rather than from a ready-made template
- Collect and validate email addresses without alerting the organisation being tested
- Build and protect campaign infrastructure: domains, email authentication, landing pages and redirectors
- Run a complete campaign with GoPhish, from sending through to monitoring
- Build spear phishing pretexts and assess techniques that depend on user action
- Demonstrate the impact of 2FA bypass through session capture, within the limits of the scope
- Choose and interpret campaign metrics, and write a report that stands behind the decisions taken
WHO IT IS FOR
- Pentesters and red teamers
- Offensive security engineers
- Incident response analysts
- Teams that commission or assess phishing simulations
- Professionals running security awareness programs
SYLLABUS
-
30min
Fundamentals and engagement framing
- What phishing is, and how it differs from other social engineering techniques
- Anatomy of a campaign: pretext, vector and objective
- Real examples and what made each of them work
- Scope, formal authorisation and rules of engagement
-
1h00
Target reconnaissance and address collection
- The organisation's public surface: people, technologies and suppliers
- Internal language, processes and calendar as raw material for the pretext
- Identifying the email controls and the provider in use
- Address sources, corporate naming conventions and breach data
- Validating addresses without alerting the target
- How reconnaissance determines the approach, rather than the other way round
-
1h00
Campaign infrastructure
- Domain selection, aging and categorisation
- Lookalike domains and how a target actually reads them
- SPF, DKIM and DMARC from the sender's perspective
- Deliverability: why a message arrives, or does not
- Landing page hosting, TLS and redirectors
-
30min
Coffee break
-
30min
Protecting the infrastructure
- Traffic filtering: who gets to see the landing page
- Evading crawlers, sandboxes and URL analysis services
- Separating sending from capture, and closing out the engagement
-
50min
Execution and delivery with GoPhish
- Modelling campaigns, templates and landing pages
- Instrumentation and event tracking
- Sending windows, pacing and segmentation
- Monitoring a campaign in flight
-
1h00
Spear phishing, ClickFix and 2FA bypass
- Spear phishing: a pretext tailored from the reconnaissance
- ClickFix and techniques that depend on user action
- Evilginx: reverse proxy and session capture
- What 2FA bypass changes in the organisation's threat model
-
40min
Impact, metrics and reporting
- Demonstrating impact within the limits of the scope
- Delivery, click, submission and session metrics — and what each one actually says
- Report rate and what it reveals about the organisation
- Report structure: narrative, evidence and debrief
-
30min
Integrative exercise
- An end-to-end campaign in a controlled environment
- Discussion of the decisions taken and the alternatives discarded
METHODOLOGY
- Concepts presented through real campaigns from industry
- Hands-on demonstrations of building and protecting infrastructure
- Guided discussions on scope, authorisation and the limits of an engagement
- Analysis of what made real campaigns work or fail
- Final end-to-end practical exercise
MATERIALS PROVIDED
- Slides
- Workbook
- Certificate of completion
PREREQUISITES
- Basic knowledge of networking, DNS and HTTP
- Familiarity with the command line in a Linux environment
- Working understanding of how email (SMTP) operates
- No prior experience with phishing campaigns is required
Content is calibrated to the room during the session, going deeper according to the participants' experience and keeping the exercises close to real-world situations.
TECHNICAL REQUIREMENTS
- Your own workstation running Linux, macOS or Windows
- Minimum of 8GB of RAM
- Between 20GB and 30GB of free disk space
- Virtualisation enabled for the course lab
- Linux is recommended as the primary environment
INSTRUCTOR
Heitor Gouvêa
Information security researcher with a background in software engineering. For nearly a decade he has worked in contexts involving data protection and application security, covering threat modeling, vulnerability identification, security tooling, and the development of practices for risk reduction.
Over his career he has worked at major Brazilian companies such as Globo and Nubank, as well as with security vendors and in applied research. As a researcher, he has reported vulnerabilities to companies and projects including Activision, MISP, D-Link and Oracle, among others.
INVESTMENT
Pricing is tiered by order of confirmed registration. Each tier closes once its seats are taken, and the next one applies.
- Tier 1 3 seats R$ 500
- Tier 2 5 seats R$ 800
- Tier 3 2 seats R$ 900
The cohort only runs once a minimum quorum of 5 participants is reached.
We can offer discounts of up to 50% if you belong to a minority group or are in a situation of social vulnerability and cannot afford the full price. Write to [email protected] and we will assess it case by case, subject to seat availability.
CANCELLATION AND REFUND POLICY
Right of withdrawal. Within 7 calendar days of registering you may cancel and receive 100% of the amount paid, with no need to give a reason. This guarantee takes precedence over the tiers below.
After that period, the refund varies according to how far in advance the request is made relative to the training start date.
- 30 days or more before the start date 90% refund
- Between 7 and 29 days before the start date 50% refund
- Fewer than 7 days before the start date No refund
Within 7 days of the start date, even where no refund applies, the seat can be transferred to another person or to the next cohort.
IMPORTANT NOTE In all cancellation cases, the refund amount is calculated on the total amount paid for the registration, less any taxes, fees, interest or penalties charged by the payment processor (credit card, bank, etc.), regardless of the payment method used.