BeginnerPhishing with OSINT9h of content · 1 guided labAudio:ES500 XP

Phishing with OSINT Beginner

Detect, analyze, and investigate phishing campaigns end-to-end, from email headers and malicious URLs to SSL certificates, PDF/Office document analysis, and attacker infrastructure tracking with professional OSINT tools.

14-day money-back guarantee · No subscription · Lifetime access

Preview the student experience

No login · Free interactive demo

Try demo →

1

Guided lab

Isolated VM environment

9h

Of content

Videos + labs + practice + exams

4

Modules

Progressive difficulty

2–4h

Per lab session

Unlimited restarts

HTKWhat's included
  • Full Beginner course (video lessons + written content)
  • 1-2 guided hands-on labs in an isolated VM
  • Per-module exams
  • HTK Beginner certificate
  • Lifetime access, unlimited lab restarts
  • Expert instructor reviews your reports & assignments
119159

One-time payment, no subscription

Start Learning →

Lab tools you will use

urlscan.ioScannerVirusTotalScannerWHOISReconShodanReconCensysReconMaltegoOSINTPhishTankThreat intelGoPhishSimulationurlscan.ioScannerVirusTotalScannerWHOISReconShodanReconCensysReconMaltegoOSINTPhishTankThreat intelGoPhishSimulation
EvilginxProxyMXToolBoxDNSDomainToolsReconpdfidDoc analysisolevbaDoc analysisCyberChefDecodertheHarvesterReconEmailRepReputationEvilginxProxyMXToolBoxDNSDomainToolsReconpdfidDoc analysisolevbaDoc analysisCyberChefDecodertheHarvesterReconEmailRepReputation

Before you start — quick answers

Not for beginner courses. They start from scratch with guided, step-by-step instructions.

Each lab session opens a 2–4 hour maximum VM session window. You can restart it as many times as you need — unlimited restarts are included with your purchase.

Yes. Unlimited restarts are included with your purchase. Practice as much as you want.

Yes. Your HTK certificate is issued upon completing the final lesson of the last module. Course progress is sequential — each lesson unlocks the next.

Course Syllabus

4 modules · 9h of content

Each phase maps to a module in this course. Scroll to see how the curriculum builds, module by module.

1

Module 1

Beginner

Introduction to Phishing & OSINT Methodology

  • Phishing taxonomy: email, SMS (smishing), voice (vishing), QR (quishing), pop-up, DNS pharming, watering hole
  • Anatomy of a phishing attack: phases, impersonation techniques, social engineering, and common attacker resources
  • Real-world impact: identity theft, financial fraud, reputational damage, and remediation costs
  • OSINT applied to phishing: threat monitoring, actor investigation, and IOC correlation
  • Key OSINT sources: social media, WHOIS, search engines, public databases, certificate transparency logs
  • Tools introduction: Shodan, Censys, Maltego, theHarvester, WHOIS Lookup, DomainTools, EmailRep, Have I Been Pwned
  • Case study analysis: DNC breach, Google/Facebook BEC, real-world spear phishing campaigns
  • Module theory exam
2

Module 2

Beginner

Phishing Types, Detection & Response

  • Email phishing indicators: sender verification, domain inspection, link analysis, attachment red flags
  • Spear phishing, whaling, and CEO fraud: OSINT-driven personalization, urgency, and internal impersonation
  • DNS-based attacks: pharming, malicious redirections, and fraudulent infrastructure
  • Clone phishing and legitimate conversation hijacking techniques
  • WiFi-based attacks (Evil Twin) and watering hole campaigns
  • Quishing (QR code phishing), pop-up phishing, smishing, and vishing techniques
  • Telephony risks: SS7 protocol exploitation, CLI spoofing, SMS 2FA theft, and SIM swapping
  • Response protocol: out-of-band validation, identity verification, and internal reporting procedures
  • Module exam
3

Module 3

Beginner

SSL/TLS Certificate Analysis for Phishing Detection

  • Certificate fundamentals: DV, OV, EV types, trust chains, and validity periods
  • Risks of self-signed certificates on fraudulent websites
  • SSL/TLS concepts: integrity, confidentiality, and Certificate Transparency (CT) logs
  • Correlating domains and campaigns through certificate fingerprint data
  • Tools: PhishTank API, SSL Checker (SSLShopper), SSL Labs, DigiCert Diagnostics
  • Censys for certificate pivoting: issuers, serials, and infrastructure change tracking
  • Practical exercises: tracing malicious domains via certificate fingerprints
  • Generating technical reports based on TLS artifact evidence
  • Module exam
4

Module 4

Beginner

Open-Source Tools & Controlled Phishing Simulation + Certification

  • Introduction to phishing simulation frameworks (authorized lab environments only)
  • Tools overview: Blackeye, SET (Social Engineering Toolkit), Zphisher, GoPhish, Evilginx, TeamsPhisher
  • Creating and importing phishing templates for awareness testing and internal assessments
  • AiTM concepts: cookie/session theft risks in MFA bypass scenarios
  • Lab: deploying a controlled phishing simulation with GoPhish and measuring results in real time
  • Cheatsheet: malicious PDF analysis with pdfid, pdf-parser, and peepdf
  • Cheatsheet: malicious Office document analysis with oledump.py, oleid, olevba, and macro detection
  • Cheatsheet: online verification and sandboxing tools (VirusTotal, Any.run, Hybrid Analysis, Google Safe Browsing)
  • HTK final certification exam

What you will learn

  • Identify phishing campaigns across all vectors: email, SMS, voice, QR, DNS, and WiFi
  • Analyze SSL/TLS certificates to trace and correlate fraudulent infrastructure
  • Triage malicious PDFs and Office documents for embedded threats
  • Use professional OSINT tools: urlscan.io, VirusTotal, WHOIS, Censys, Maltego, PhishTank
  • Deploy controlled phishing simulations with GoPhish for awareness testing

Hands-on Lab

Receive artifacts from a real phishing campaign: suspicious emails, malicious URLs, registered domains, and document attachments. Reconstruct the attacker's entire infrastructure using WHOIS, urlscan.io, VirusTotal, Censys certificate analysis, and passive DNS. Analyze malicious PDFs with pdfid/peepdf and Office macros with olevba. Deploy a controlled phishing simulation with GoPhish. Flags automatically validate each finding you discover.

1⬡ 1 guided lab
2–4hSession window
UnlimitedRestarts
AutoFlag validation
Experience a lab preview →

Requirements

  • ·Modern web browser
  • ·Stable internet connection
  • ·No local installation required
  • ·Basic technical English recommended

Frequently Asked Questions

Complete answers about this course, labs, certificates, and refunds

Not for beginner courses. They start from scratch with guided, step-by-step instructions.

Each lab session opens a 2–4 hour maximum VM session window. You can restart it as many times as you need — unlimited restarts are included with your purchase.

Yes. Unlimited restarts are included with your purchase. Practice as much as you want.

Yes. Your HTK certificate is issued upon completing the final lesson of the last module. Course progress is sequential — each lesson unlocks the next.

Yes. 14-day money-back if lesson progress is below 20% and you have not completed the HTK certificate path (all lessons + labs) for that course. Details in our Refund Policy.

Yes. Once purchased, you have permanent access to all course materials and future updates.

Yes. All professional tools come pre-installed and configured in the VM, no local setup needed.

Most students complete the course in 2–4 weeks studying part-time. You set your own pace.

Ready for the next level?

Phishing with OSINT Intermediate

You've covered the fundamentals. Phishing with OSINT Intermediate builds on this course with more complex real-world scenarios, higher-difficulty labs, and advanced analysis workflow.

15h of content2 guided labs159
View Intermediate Course →
Ready to level up?

Build real Phishing with OSINT skills

Get hands-on with real Phishing with OSINT scenarios, professional-grade tools, and validated flag objectives. No prior experience needed.

From119or 199 € for the complete path
One-time payment, no recurring chargesLifetime access, course updates included14-day money-back guarantee