GoPhish is an open-source phishing simulation framework used by security teams to conduct authorized phishing awareness campaigns. It provides campaign management, email template creation, landing pag
cybersecurity
phishing-defense
phishing
email-security
social-engineering
dmarc
awareness
gophish
simulation
1.0
mahipal
Apache-2.0
PR.AT-01
DE.CM-09
RS.CO-02
DE.AE-02
T1566
T1598
T1534
T1036
version
tactics
techniques
1.1
resource-development
initial-access
reconnaissance
id
name
tactic
source
T1660
Phishing
initial-access
attack
id
name
tactic
source
T1598
Phishing for Information
reconnaissance
attack
id
name
tactic
source
F1020.002
Create Fake Materials: Fake Website
resource-development
f3
id
name
tactic
source
T1583.001
Acquire Infrastructure: Domains
resource-development
attack
id
name
tactic
source
T1557
Adversary-in-the-Middle
initial-access
attack
id
name
tactic
source
F1031
Impersonate Account Holder
initial-access
f3
Performing Phishing Simulation with GoPhish
Overview
GoPhish is an open-source phishing simulation framework used by security teams to conduct authorized phishing awareness campaigns. It provides campaign management, email template creation, landing page cloning, and comprehensive reporting. This skill covers deploying GoPhish, creating realistic phishing scenarios, and analyzing campaign results to measure and improve organizational resilience.
When to Use
When conducting security assessments that involve performing phishing simulation with gophish
When following incident response procedures for related security events
When performing scheduled security testing or auditing activities
When validating security controls through hands-on testing