惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Apple Machine Learning Research
Apple Machine Learning Research
博客园 - 三生石上(FineUI控件)
雷峰网
雷峰网
WordPress大学
WordPress大学
S
SegmentFault 最新的问题
博客园 - 叶小钗
The Cloudflare Blog
T
Tailwind CSS Blog
Hugging Face - Blog
Hugging Face - Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
月光博客
月光博客
小众软件
小众软件
罗磊的独立博客
酷 壳 – CoolShell
酷 壳 – CoolShell
大猫的无限游戏
大猫的无限游戏
阮一峰的网络日志
阮一峰的网络日志
V
V2EX
美团技术团队
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 聂微东
量子位
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
宝玉的分享
宝玉的分享

Black Hills Information Security, Inc.

Bad Habits: An ANTISOC Operation Same Problem, Different Angles: When Red Team and Blue Team Actually Talk to Each Other How to Identify and Exploit New Vulnerabilities Swapper – A Pure Regex Match/Replace Burp Extension A Practical Guide to BloodHound Data Collection Network Engineering Basics Signed, Trusted, and Abused: Proxy Execution via WebView2 Getting Started In Pentesting – Advice From The BHIS Pentest Lead Cloud Security: Tips and Resources for Securing the Cloud Lessons From A Chatbot Incident How to Lead Effective Tabletops Understanding GRC: How to Navigate Risks and Compliance Standards The “P” in PAM is for Persistence: Linux Persistence Technique Malware Analysis: How to Analyze and Understand Malware OSINT: How to Find, Use, and Control Open-Source Intelligence What to Do with Your First Home Lab When the SOC Goes to Deadwood: A Night to Remember Social Engineering and Microsoft SSPR: The Road to Pwnage is Paved with Good Intentions Common Cyber Threats Finding the Right Penetration Testing Company Deceptive-Auditing: An Active Directory Honeypots Tool The Curious Case of the Comburglar How to Set Smart Goals (That Actually Work For You) Inside the BHIS SOC: A Conversation with Hayden Covington Abusing Delegation with Impacket (Part 3): Resource-Based Constrained Delegation Why You Got Hacked – 2025 Super Edition Abusing Delegation with Impacket (Part 2): Constrained Delegation Abusing Delegation with Impacket (Part 1): Unconstrained Delegation GoSpoof – Turning Attacks into Intel Model Context Protocol (MCP)
Webcast: How to Build a Phishing Engagement – Coding TTP’s
BHIS · 2021-07-14 · via Black Hills Information Security, Inc.

, , , , , , , ,





Building a phishing engagement is hard. While the concept is straightforward, real-world execution is tricky. Being successful takes enormous amounts of up-front setup and knowledge in quickly evolving phishing tactics. While there is always a need to craft a custom email, the most considerable amount of work is setting up an infrastructure to make it all work.

Wouldn’t it be nice if you had a playbook of how to set everything up to save time and prevent mistakes?

What if we coded this playbook so we could share this with others and modify our tactics when things change?

In this Black Hills Information Security (BHIS) webcast, we’re going to do just that. We will take a top-down look at how a phishing engagement is designed. Then we will work through coding this design, so we don’t have to keep building a phish. Lastly, we will touch on how to fly under the radar and how coding TTP’s help save time and guarantee accuracy.

Join the BHIS Community Discord: https://discord.gg/bhis

Music By Beau: https://www.nobandwidth.io

00:00 – FEATURE PRESENTATION: How to Build a Phishing Engagement – Coding TTP’s

01:06 – About Ralph May

01:58 – Disclaimers

03:19 – Overview

03:56 – Phishing is Hard

06:33 – Infrastructure

07:12 – Operational Security

08:39 – Designing a Phish

13:18 – Phishing Emails

15:48 – 1st Tool: EVILGINX2

17:30 – EVILGINX IOC’s

18:20 – 2nd Tool: GoPhish

19:08 – GoPhish IOC’s

20:52 – 3rd Tool: NGINX

22:08 – 4th Tool: Digital Ocean Cloud Provider

22:33 – 5th Tool: Mailgun Email Service

23:17 – 6th Tool: CDN-Azure

23:57 – Coding a Phish – 1st Tool: Ansible

26:33 – 2nd Tool: Terraform

29:01 – 3rd Tool: Docker

30:49 – Combining Ansible and Terraform

32:41 – Ansible Secrets

34:32 – DEMO: Executing a Phishing Engagement

42:40 – What’s Next

44:03 – QnA

57:08 – PostShow Banter™ — Ohs and Ahs

Want to learn more from Ralph? Check out his class below!

HackerOps

Available on-demand!