Guides spearphishing simulation campaigns for red teaming: develops OSINT-based pretexts, builds evasive payloads, sets up email infrastructure, executes tracking-enabled attacks, and analyzes MITRE ATT&CK-mapped results.
npx claudepluginhub killvxk/cybersecurity-skills-zhThis skill uses the workspace's default tool permissions.
鱼叉式钓鱼(Spearphishing)模拟是红队用于获取初始访问权限的定向社会工程学(Social Engineering)攻击向量。与广泛的钓鱼活动不同,鱼叉式钓鱼使用 OSINT 情报精心制作高度个性化的消息,针对特定个人。本技能涵盖开发借口、构建载荷、设置邮件基础设施、执行活动和跟踪结果。
Simulates spearphishing campaigns for red-teaming: develops pretexts from OSINT, builds payloads, sets up email infra, executes with tracking, maps to MITRE ATT&CK.
Guides red teams in spearphishing simulations for security assessments: pretext development, payload creation, email infrastructure setup, campaign execution, and result tracking.
Executes authorized phishing simulations using GoPhish: designs pretext scenarios, builds credential harvesting infrastructure, sends targeted emails, tracks open/click/submit rates for security awareness assessment.
Share bugs, ideas, or general feedback.
鱼叉式钓鱼(Spearphishing)模拟是红队用于获取初始访问权限的定向社会工程学(Social Engineering)攻击向量。与广泛的钓鱼活动不同,鱼叉式钓鱼使用 OSINT 情报精心制作高度个性化的消息,针对特定个人。本技能涵盖开发借口、构建载荷、设置邮件基础设施、执行活动和跟踪结果。
| 工具 | 用途 | 许可证 |
|---|---|---|
| GoPhish | 钓鱼活动管理 | 开源 |
| Evilginx2 | 带 MFA 绕过的实时凭据收割 | 开源 |
| King Phisher | 钓鱼活动工具包 | 开源 |
| SET(社会工程学工具包) | 多向量社会工程学 | 开源 |
| Modlishka | 反向代理钓鱼 | 开源 |
| CredSniper | 凭据收割框架 | 开源 |
| Fierce Phish | 钓鱼框架 | 开源 |