IntermediatePhishing with OSINT15h of content · 2 guided labsAudio:ES750 XP

Phishing with OSINT Intermediate

Advanced phishing investigation: analyze polymorphic kits and PhaaS infrastructure, perform domain and DNS forensics, dissect email authentication bypasses (SPF/DKIM/DMARC/ARC), and produce actionable threat intelligence reports with campaign attribution.

14-day money-back guarantee · No subscription · Lifetime access

Preview the student experience

No login · Free interactive demo

Try demo →

2

Guided labs

Isolated VM environment

15h

Of content

Videos + labs + practice + exams

4

Modules

Progressive difficulty

2–4h

Per lab session

Unlimited restarts

HTKWhat's included
  • Full Intermediate course (video lessons + written content)
  • 2-4 guided labs — less guided, more complex than Beginner
  • Advanced per-module exams
  • HTK Intermediate certificate
  • Lifetime access, unlimited lab restarts
  • Expert instructor reviews your reports & assignments
159

One-time payment, no subscription

Start Learning →

Lab tools you will use

urlscan.ioScannerVirusTotalScannerWHOISReconShodanReconCensysReconMaltegoOSINTPhishTankThreat intelGoPhishSimulationurlscan.ioScannerVirusTotalScannerWHOISReconShodanReconCensysReconMaltegoOSINTPhishTankThreat intelGoPhishSimulation
EvilginxProxyMXToolBoxDNSDomainToolsReconpdfidDoc analysisolevbaDoc analysisCyberChefDecodertheHarvesterReconEmailRepReputationEvilginxProxyMXToolBoxDNSDomainToolsReconpdfidDoc analysisolevbaDoc analysisCyberChefDecodertheHarvesterReconEmailRepReputation

Before you start — quick answers

Not for beginner courses. They start from scratch with guided, step-by-step instructions.

Each lab session opens a 2–4 hour maximum VM session window. You can restart it as many times as you need — unlimited restarts are included with your purchase.

Yes. Unlimited restarts are included with your purchase. Practice as much as you want.

Yes. Your HTK certificate is issued upon completing the final lesson of the last module. Course progress is sequential — each lesson unlocks the next.

Course Syllabus

4 modules · 15h of content

Each phase maps to a module in this course. Scroll to see how the curriculum builds, module by module.

1

Module 1

Intermediate

Advanced Phishing Techniques & Kit Analysis

  • Polymorphic phishing for signature-based filter evasion
  • Phishing-as-a-Service (PhaaS) ecosystem and underground kit marketplace
  • HTTPS in phishing: the false confidence of the padlock icon
  • Evasion techniques: image inversion, malicious HTML, open redirects, and cloaking
  • Resilient infrastructure: Fast Flux domains and DGA/RDGA-based resolution
  • Attacks on strong authentication: MFA fatigue and Adversary-in-the-Middle (AiTM)
  • Impact chain: session theft → email compromise → BEC fraud
  • Phishing kit architecture: HTML, PHP, JS, CSS components, and exfiltration traces analysis
  • Module exam
2

Module 2

Intermediate

Domain Analysis & Infrastructure Forensics

  • Domain taxonomy: gTLD, sTLD, ccTLD, TLDs most abused in phishing campaigns
  • Domain lifecycle analysis: registration, activity, expiration, and expired domain abuse
  • DNS fundamentals for phishing analysis: record types, DNS attacks, and DNSSEC mitigations
  • Domain-to-email correlation via SMTP TLS/SMTPS for legitimacy validation
  • Tools: VirusTotal, DevTools, Urlscan.io, Nmapper, WhoisXMLApi, ExpiredDomains, DomainTools
  • Advanced tools: OpenSquat, EvilURL, Screaming Frog, Shodan, PhishCheck, Browserling, Maltego
  • Practical cases: analyzing suspicious domains and generating evidence-based phishing reports
  • Module exam
3

Module 3

Intermediate

Email Analysis & Sender Authentication Forensics

  • Email architecture: MTA, MUA, MDA, SMTP, POP3, IMAP4, mail delivery flow
  • Authentication and anti-spoofing protocols: SPF, DKIM, DMARC, ARC, and BIMI
  • HTML URL concealment techniques used in phishing emails
  • Body analysis patterns: fraud indicators, urgency, fake prizes, package delivery, tax/payment lures
  • Header analysis: From, Return-Path, Received, Message-ID, Received-SPF, X-Headers deep dive
  • Tools: EmailRep, Google MessageHeader, Network-Tools, Azure Message Header Analyzer, MXToolBox
  • Practical: real header parsing, hop tracing, sender reputation verification, and OSINT correlation for alert prioritization
  • Module exam
4

Module 4

Intermediate

Advanced Simulation & Campaign Report + Certification

  • Advanced lab operations with Blackeye, SET, Zphisher, GoPhish, Evilginx, and TeamsPhisher
  • Campaign simulation design: evaluating human vectors and technical controls
  • Advanced session, 2FA, and corporate messaging risks with AiTM techniques
  • Safe usage recommendations: authorized environments only, educational objectives, controlled red teaming
  • Designing awareness exercises and detection drills for SOC/blue team
  • Measuring campaign indicators: click rates, simulated credential submissions, SOC response metrics
  • Full campaign timeline reconstruction with evidence chain and stakeholder briefing
  • HTK intermediate certification exam

What you will learn

  • Analyze polymorphic phishing kits and PhaaS infrastructure at the code level
  • Perform deep domain forensics: WHOIS correlation, expired domain abuse, DNS attack analysis
  • Dissect email headers and verify SPF, DKIM, DMARC, and ARC authentication
  • Simulate advanced MFA bypass attacks with Evilginx in controlled environments
  • Produce actionable threat intelligence reports with campaign timelines and actor profiles

Hands-on Lab

Investigate sophisticated multi-stage phishing campaigns with bulletproof hosting, fast-flux DNS, DGA/RDGA domains, and MFA bypass techniques (AiTM). Analyze phishing kits at the code level (HTML, PHP, JS, exfiltration traces), perform deep domain forensics with WHOIS correlation and expired domain abuse analysis, dissect email headers to verify SPF, DKIM, DMARC, and ARC authentication, and deploy advanced simulations with Evilginx. Produce actionable threat intelligence reports with campaign timelines, actor profiles, and infrastructure maps.

2⬡ 2 guided labs
2–4hSession window
UnlimitedRestarts
AutoFlag validation
Experience a lab preview →

Requirements

  • ·Modern web browser
  • ·Stable internet connection
  • ·No local installation required
  • ·Basic technical English recommended

Frequently Asked Questions

Complete answers about this course, labs, certificates, and refunds

Not for beginner courses. They start from scratch with guided, step-by-step instructions.

Each lab session opens a 2–4 hour maximum VM session window. You can restart it as many times as you need — unlimited restarts are included with your purchase.

Yes. Unlimited restarts are included with your purchase. Practice as much as you want.

Yes. Your HTK certificate is issued upon completing the final lesson of the last module. Course progress is sequential — each lesson unlocks the next.

Yes. 14-day money-back if lesson progress is below 20% and you have not completed the HTK certificate path (all lessons + labs) for that course. Details in our Refund Policy.

Yes. Once purchased, you have permanent access to all course materials and future updates.

Yes. All professional tools come pre-installed and configured in the VM, no local setup needed.

Most students complete the course in 2–4 weeks studying part-time. You set your own pace.

Start from the beginning?

Phishing with OSINT Beginner

Not ready for intermediate yet? Phishing with OSINT Beginner covers the foundational skills and guided labs you need before tackling the advanced material.

9h of content1 guided lab119
View Beginner Course →
Ready to level up?

Build real Phishing with OSINT skills

Get hands-on with real Phishing with OSINT scenarios, professional-grade tools, and validated flag objectives. No prior experience needed.

From159or 199 € for the complete path
One-time payment, no recurring chargesLifetime access, course updates included14-day money-back guarantee