◈ Path Bundle

Phishing with OSINT

Detect, analyze, and investigate phishing campaigns end-to-end, email forensics, SSL/TLS analysis, domain intelligence, malicious document triage, and threat actor attribution with professional OSINT tools.

Save 79 EUR

Lab tools you will use

urlscan.ioScannerVirusTotalScannerWHOISReconShodanReconCensysReconMaltegoOSINTPhishTankThreat intelGoPhishSimulationurlscan.ioScannerVirusTotalScannerWHOISReconShodanReconCensysReconMaltegoOSINTPhishTankThreat intelGoPhishSimulation
EvilginxProxyMXToolBoxDNSDomainToolsReconpdfidDoc analysisolevbaDoc analysisCyberChefDecodertheHarvesterReconEmailRepReputationEvilginxProxyMXToolBoxDNSDomainToolsReconpdfidDoc analysisolevbaDoc analysisCyberChefDecodertheHarvesterReconEmailRepReputation

Courses Included

Beginner

Phishing with OSINT

paypa1-secure.com SPOOFED
◎ BEGINNER500 XPAudio:ES

Phishing with OSINT Beginner

Learn to detect, analyze, and investigate phishing campaigns, from email indicators and SSL certificate analysis to malicious document triage, attacker infrastructure tracking, and controlled simulation with GoPhish.

1 guided lab9h of content

119 EUR

View course →
Intermediate

Phishing with OSINT

SPF fail
DKIM fail
DMARC p=none
▲ INTERMEDIATE750 XPAudio:ES

Phishing with OSINT Intermediate

Advanced phishing investigation: polymorphic kit analysis, domain forensics, email authentication bypass (SPF/DKIM/DMARC), MFA attack simulation with Evilginx, and professional threat intelligence reporting.

2 guided labs15h of content

159 EUR

View course →

Why Choose the Full Pack?

Get the Beginner + Intermediate courses bundled together and unlock exclusive extras.

Beginner + Intermediate courses (24h of content)
All 4 guided labs with isolated VMs
2 HTK certificates (Beginner + Intermediate)
1 exclusive bonus consolidation lab
Direct instructor support
Access to the HTK community
199278
Save 79

Your Learning Roadmap

Each phase maps to a course module. Scroll to assemble your full progression — from beginner fundamentals to intermediate mastery.

1

Phase 1

Beginner

Reading a message properly

A reported email is the raw material. You learn to open it safely and extract what it will not tell you voluntarily.

  • Work from the original message rather than a forward that destroys evidence
  • Follow the hop chain back to where it genuinely originated
  • Read authentication results and spot a spoofed sender that still passes SPF
2

Phase 2

Beginner

Attachments and links, safely

The payload arrives as a document or a URL. Both can be examined without ever letting them execute or phoning home.

  • Pull macros and embedded objects out of Office and PDF lures
  • Peel back the encoding layers used to hide the real destination
  • Inspect a live page through an intermediary instead of your own browser
3

Phase 3

Beginner

Profiling the domain

Every domain carries a public paper trail. This phase is about reading it without sending the attacker a single packet.

  • Query structured registration data and read what a creation date implies
  • Map name servers, mail records and hosting
  • Understand where passive ends and active recon legally begins
4

Phase 4

Beginner

Writing it up so it counts

An investigation nobody can act on was wasted. You learn the reporting conventions the industry actually uses.

  • Defang indicators so nobody detonates them by accident
  • Attach a confidence level and a source to every claim
  • Route the report to the registrar, host or brand that can act
5

Phase 5

Intermediate

The certificates give them away

Public certificate logs are the highest-yield source in the discipline, because attackers publish to them without meaning to.

  • Enumerate subdomains the operator believed were private
  • Find sibling campaign domains sharing one certificate
  • Reconstruct a deployment timeline from issuance dates
6

Phase 6

Intermediate

From one host to the whole estate

A single address is a starting point. Pivoting turns it into a map — provided you know when a correlation means nothing.

  • Move between address, hosting provider and neighbouring domains
  • Use resolution history to group campaigns over time
  • Judge when shared hosting or a CDN makes a link worthless
7

Phase 7

Intermediate

Fingerprinting the kit

Phishing kits are deployed unmodified, so they carry constants. Find one and you find every other deployment.

  • Derive a favicon hash and search it across the internet
  • Fingerprint kits by page structure and response headers
  • Generate and check lookalike domains against your own brand
8

Phase 8

Intermediate

Tracking a campaign, not an email

The final step is following an actor across time and knowing where evidence stops and speculation starts.

  • Correlate infrastructure and mail artefacts across waves
  • Build a pivot graph an analyst can reproduce from your notes
  • Recognise the limits of attribution and say so in writing

What this path is

The Phishing with OSINT path covers the full lifecycle of a phishing investigation: from the message landing in an inbox, through the headers that reveal where it really came from, to mapping the attacker's wider infrastructure and writing it up so somebody can act on it.

It is deliberately two disciplines in one. Phishing analysis without OSINT tells you a single email was malicious. OSINT without phishing analysis produces interesting data with nothing anchoring it. Together they let you answer the question that actually matters to an organisation: is this one message, or the visible edge of a campaign aimed at us?

The work is passive by design. You will learn where the line sits between querying public records and touching the attacker's infrastructure, why crossing it both compromises the investigation and can be a criminal offence, and how to get what you need without ever sending the target a packet.

Who it's for

  • SOC and helpdesk analysts who triage reported phishing and want to go beyond "block and delete"
  • Threat intelligence analysts who need repeatable infrastructure pivoting
  • Brand protection and fraud teams tracking impersonation of their own domains
  • Anyone moving into CTI who needs investigative work they can show

Who it's not for

  • ·Anyone wanting to run phishing campaigns — the offensive tooling here is covered for detection, not delivery
  • ·People expecting fully automated attribution; the path teaches judgement, including when not to attribute

What you need before starting

  • Understanding of how email travels: SMTP, DNS, and what a mail header is
  • Basic command line for tools such as dig and curl
  • No prior OSINT experience needed
  • A willingness to document carefully — half this discipline is note-taking

The tools, and what each one is for

The path uses more tools than fit here. These are the ones that define the work.

ToolCategoryWhat for
urlscan.ioSafe browsingVisiting a suspicious site on your behalf so your IP never reaches the attacker
Certificate TransparencyInfrastructureFinding subdomains and sibling campaign domains through public certificate logs
Shodan / CensysInfrastructureLocating other servers running the same phishing kit by fingerprint
MaltegoAnalysisBuilding the pivot graph visually when an investigation grows past a few nodes
olevba / pdfidDocument triageExtracting macros and embedded objects from malicious attachments
MXToolBoxMail forensicsChecking SPF, DKIM and DMARC alignment on a suspect message
theHarvesterReconnaissanceUnderstanding what an attacker can learn about your own organisation
CyberChefDecodingUnwrapping the layers of encoding phishing kits use to hide their payloads

What you finish with

A phishing investigation report

With indicators, sources and explicit confidence levels for each finding

An infrastructure pivot map

Showing how one domain connects to the rest of the actor's estate

A defanged indicator set

Formatted so a detection team can ingest it directly

An email header analysis

Reading the hop chain and authentication results down to the true origin

Where it leads

Phishing remains the most common initial access vector, so investigating it well is directly useful in almost any defensive role — and it is one of the few specialisms you can practise without privileged access to anything.

SOC Analyst

Triages reported messages and decides what is campaign and what is noise

Threat Intelligence Analyst

Tracks campaigns and infrastructure across time and victims

Incident Responder

Determines scope once a phish has succeeded

Brand Protection Analyst

Finds and takes down domains impersonating the organisation

Frequently Asked Questions

Complete answers about this path, labs, certificates, and refunds

Querying public sources — registration records, certificate transparency logs, passive DNS — is legal, since that data is deliberately published. The path is explicit about where the line to active interaction sits, and why staying on the passive side protects both you and the investigation.

No. The path is built around what free tiers and public sources provide, which is considerably more than most people expect. Commercial platforms are discussed so you know what they add, but no lab depends on one.

Only incidentally. Tools such as GoPhish and Evilginx are covered so you understand what the attacker's side looks like and can recognise its traces — the path is investigative, not offensive.

Most of it. Infrastructure pivoting, certificate transparency and passive DNS are the same techniques used to track malware C2 and scam infrastructure. Phishing is the vehicle for teaching a general method.

No. A little scripting helps automate repetitive lookups and the path shows where, but every lab can be completed with command-line tools and web interfaces.

A repeatable investigative method and completed case write-ups from real infrastructure — which, for interviews, demonstrates rather more than a certificate does on its own.