Each phase maps to a module in this course. Scroll to see how the curriculum builds, module by module.
1Introduction to Phishing & OSINT Methodology
- •Phishing taxonomy: email, SMS (smishing), voice (vishing), QR (quishing), pop-up, DNS pharming, watering hole
- •Anatomy of a phishing attack: phases, impersonation techniques, social engineering, and common attacker resources
- •Real-world impact: identity theft, financial fraud, reputational damage, and remediation costs
- •OSINT applied to phishing: threat monitoring, actor investigation, and IOC correlation
- •Key OSINT sources: social media, WHOIS, search engines, public databases, certificate transparency logs
- •Tools introduction: Shodan, Censys, Maltego, theHarvester, WHOIS Lookup, DomainTools, EmailRep, Have I Been Pwned
- •Case study analysis: DNC breach, Google/Facebook BEC, real-world spear phishing campaigns
- •Module theory exam
2Phishing Types, Detection & Response
- •Email phishing indicators: sender verification, domain inspection, link analysis, attachment red flags
- •Spear phishing, whaling, and CEO fraud: OSINT-driven personalization, urgency, and internal impersonation
- •DNS-based attacks: pharming, malicious redirections, and fraudulent infrastructure
- •Clone phishing and legitimate conversation hijacking techniques
- •WiFi-based attacks (Evil Twin) and watering hole campaigns
- •Quishing (QR code phishing), pop-up phishing, smishing, and vishing techniques
- •Telephony risks: SS7 protocol exploitation, CLI spoofing, SMS 2FA theft, and SIM swapping
- •Response protocol: out-of-band validation, identity verification, and internal reporting procedures
- •Module exam
3SSL/TLS Certificate Analysis for Phishing Detection
- •Certificate fundamentals: DV, OV, EV types, trust chains, and validity periods
- •Risks of self-signed certificates on fraudulent websites
- •SSL/TLS concepts: integrity, confidentiality, and Certificate Transparency (CT) logs
- •Correlating domains and campaigns through certificate fingerprint data
- •Tools: PhishTank API, SSL Checker (SSLShopper), SSL Labs, DigiCert Diagnostics
- •Censys for certificate pivoting: issuers, serials, and infrastructure change tracking
- •Practical exercises: tracing malicious domains via certificate fingerprints
- •Generating technical reports based on TLS artifact evidence
- •Module exam
4Open-Source Tools & Controlled Phishing Simulation + Certification
- •Introduction to phishing simulation frameworks (authorized lab environments only)
- •Tools overview: Blackeye, SET (Social Engineering Toolkit), Zphisher, GoPhish, Evilginx, TeamsPhisher
- •Creating and importing phishing templates for awareness testing and internal assessments
- •AiTM concepts: cookie/session theft risks in MFA bypass scenarios
- •Lab: deploying a controlled phishing simulation with GoPhish and measuring results in real time
- •Cheatsheet: malicious PDF analysis with pdfid, pdf-parser, and peepdf
- •Cheatsheet: malicious Office document analysis with oledump.py, oleid, olevba, and macro detection
- •Cheatsheet: online verification and sandboxing tools (VirusTotal, Any.run, Hybrid Analysis, Google Safe Browsing)
- •HTK final certification exam