Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.
A direct command skips the review prompt. Inspect the source before running it.
test-cases.md — 12 structured test cases (TC-ED-001 through TC-ED-012) covering infrastructure stand-up, AiTM capture, gateway evasion, reputation warm-up, payload delivery, telemetry, and FIDO2 pivot
guides/email-security-deep-playbook.md — end-to-end playbook from pretext design through infrastructure build, gateway-evasion tuning, payload staging, AiTM session theft, and clean exit
guides/email-security-deep-deep-dive.md — AiTM phishing campaign emulation lab walkthrough (hands-on, step by step, with exercises)
Summary
Email Security Deep covers the campaign-operations layer of email-based compromise: standing up phishing infrastructure (evilginx2, modlishka, evilgophish, gophish, King-Phisher), bypassing enterprise email gateways (Proofpoint, Mimecast, Cisco ESA, Microsoft Defender for Office), executing adversary-in-the-middle MFA bypass, running email-bomb flooding, and engineering sender reputation for spoofing success. This is the application/social-engineering layer above raw SMTP protocol abuse.
Rule of thumb: if the question is "can I make this mail server accept a forged message?" → email-protocol-attack. If the question is "can I run a campaign that lands in the inbox AND captures MFA tokens via AiTM?" → this skill. They chain together — protocol-level forgery feeds campaign delivery — but the focus differs.
Also distinct from social-engineering: that skill covers the human-psychology layer (pretext design, vishing, tailgating, USB baiting). This skill is the infrastructure layer: how to actually stand up the phishing platform, route mail past gateways, and capture sessions. Real engagements use both.
Use Cases
Authorized red-team phishing campaign — Stand up a full gophish + evilginx2 stack to test an organization's email gateway, EDR, and user-click response rate, with MFA bypass via AiTM where in-scope.
Email gateway bypass assessment — Deliver a benign payload past Proofpoint URL Defense, Mimecast URL expansion, Cisco ESA sandboxing, and Microsoft Defender Safe Links/Attachments to validate gateway efficacy.
AiTM MFA-bypass simulation — Reproduce EvilProxy / NakedTenant style attacks where session cookies are stolen mid-login via evilginx2 reverse proxy, defeating TOTP/SMS/push MFA.
Sender reputation / spoofing success audit — Audit a client's SPF/DKIM/DMARC/BIMI/ARC posture from the attacker's perspective — what sender identities will the gateway trust, and which can be spoofed.
Email bombing / DoS test — Flood a target's mailbox (with authorization) to measure notification fatigue, gateway rate-limiting, and downstream incident-response behavior.
Phishing landing page + payload staging review — Review HTML-smuggling, decrypted-on-click attachments, and C2 callback patterns used by active threat groups.
FIDO2 / hardware-key resistance test — Detect when a target uses FIDO2 (evilginx2 cannot capture it) and pivot to a different vector (device-code flow, OAuth consent phishing) instead of wasting campaign budget.
Post-click telemetry & campaign measurement — Instrument open/click tracking, beacon design, and C2 callback patterns to produce a metrics report (delivery rate, click rate, credential-capture rate, MFA-bypass rate).
Real-world AiTM campaign reproduction — Reproduce the CozyCar / EvilProxy / NakedTenant kill chain in a lab to validate detection rules and user-training efficacy.
Clean-exit / OPSEC review — After a campaign, ensure no orphaned infrastructure, no leaked credentials in logs, and that all captured session cookies have been lawfully destroyed per engagement scope.
Phase 1: Pretext & Target Profiling — Build the campaign narrative. Use OSINT (LinkedIn, theHarvester, recon-ng — see skills/osint/, skills/social-engineering/) to enumerate recipients, then craft a pretext (IT password reset, package delivery, executive urgent directive, shared-doc notification). Define the desired post-click action (credential submit, MFA approval, payload execute).
Phase 2: Infrastructure Stand-up — Register look-alike domains (micros0ft-login.com, paypa1-verify.com), obtain TLS certs (Let's Encrypt or pre-staged wildcards), configure DNS (A, MX, SPF, DKIM, DMARC for the spoofed identity if reputation-tolerant), and deploy gophish + evilginx2 on a hardened VPS with redirectors to mask the true origin IP.
Phase 3: Gateway Evasion Tuning — Pre-flight each gateway the target uses. Proofpoint rewrites URLs (urldefense.proofpoint.com/v2/url?u=...) — test that your landing domain survives rewriting and that the un-rewritten click-through works. Mimecast expands URLs at click time and may sandbox. Cisco ESA runs attachment sandboxing. Microsoft Defender Safe Links rewrites and Safe Attachments detonates. Tune sender reputation (DKIM-signed, SPF-aligned, DMARC-aligned, BIMI if applicable, warmed-up IP) until deliverability is acceptable.
Phase 4: Payload Delivery — Send the campaign via gophish (or evilgophish combined stack). For payloads, prefer HTML smuggling (the attachment contains JS that reconstructs the malicious binary client-side — gateway sees only benign HTML/JS) and decrypted-on-click attachments (encrypted zip that the gateway cannot unzip without the password). Track opens (1x1 beacon) and clicks (redirect link).
Phase 5: AiTM / Click-Time — When a victim clicks through to the AiTM landing page, evilginx2 proxies the login to the real service, captures the credential, captures the MFA token (live, as the victim completes MFA), and — critically — captures the session cookie that authenticates the victim post-MFA. The attacker then imports the session cookie into their own browser and is now logged in as the victim, having "passed" MFA without ever needing to phish the MFA secret itself.
If the target uses FIDO2 (isUserVerifyingPlatformAuthenticatorAvailable() returns true and the visible MFA prompt is a security key, not a TOTP/push), AiTM will fail — detect this in-browser and pivot to device-code flow, OAuth consent phishing, or a different target. Document this in the report as a control strength.
Phase 6: Exfil & Exit — Aggregate captured sessions, rotate session cookies into a separate browser profile, perform authorized post-exploitation (per engagement scope), then tear down infrastructure: destroy captured credentials/cookies per the engagement scope, delete gophish database, revoke DNS, retire VPS, and produce the campaign telemetry report (delivery rate, open rate, click rate, credential-capture rate, MFA-bypass rate, FIDO2-blocked count).
Detailed payloads in payloads.md, complete test checklist in test-cases.md. Below is a summary of the six-phase workflow with representative commands.
Step 1: Infrastructure Stand-up
# Register look-alike domain (use authorized registrar only)
# Configure DNS for both spoofing identity and landing page host
# A record for landing host
echo "login.micros0ft-secure.com. IN A 198.51.100.10" >> zone.txt
# MX record (for replies if engagement wants reply capture)
echo "micros0ft-secure.com. IN MX 10 mail.micros0ft-secure.com." >> zone.txt
# SPF aligned with sending IP
echo 'micros0ft-secure.com. IN TXT "v=spf1 ip4:198.51.100.10 -all"' >> zone.txt
# DMARC aligned with SPF
echo '_dmarc.micros0ft-secure.com. IN TXT "v=DMARC1; p=none; rua=mailto:postmaster@micros0ft-secure.com"' >> zone.txt
# Launch evilginx2 (AiTM reverse proxy)
sudo ./evilginx -p phishlets
# Inside evilginx CLI:
# config domain micros0ft-secure.com
# config ip 198.51.100.10
# phishlets hostname office365 login.micros0ft-secure.com
# phishlets enable office365
# lures create office365
# lures get-url 0
# Launch gophish on the same VPS (or separate)
./gophish # web UI on https://127.0.0.1:3333
# Default creds admin / gophish (CHANGE FIRST)
Step 2: Gateway Evasion Pre-Flight
# Check client's gateway by sending a probe mail and inspecting received headers
swaks --to probe@target.com --from test@micros0ft-secure.com \
--server mail.target.com --header "Subject: probe" --body "open me"
# Inspect received headers on the target side
# Look for: X-Proofpoint-Spam-Details, X-Mimecast-, X-IronPort- (Cisco ESA),
# X-MS-Exchange-Organization- (Defender for Office)
# Verify sender reputation from attacker's side
checkdmarc target.com # victim's posture
python3 espoofer.py -i test_email.txt --spoof micros0ft-secure.com
# Warm up sender IP gradually (volume ramp over 7 days)
# Day 1-3: low volume to internal test addresses
# Day 4-7: ramp to half campaign volume
# Day 8+: full campaign
Proofpoint URL Defense, Mimecast URL expansion, Defender Safe Links — rewrites URLs at click time so a domain that "looked clean" at delivery is re-checked against fresh threat intel. Defeats benign-at-delivery / malicious-at-click.
CRITICAL
Safe Attachments / sandbox detonation
Microsoft Defender Safe Attachments, Cisco ESA sandbox — detonates attachments in VM before delivery. Defeats most macro and executable payloads; pairs with HTML-smuggling defense (JS sandbox).
HIGH
Strict DMARC (p=reject) + DKIM enforcement
Stops spoofing at the gateway. Even sender-reputation-engineered attacks must use a look-alike domain (visible to user) rather than spoof the real one.
HIGH
BIMI + ARC trust signals
Brand Indicators for Message Identification (visible logo) trains users to expect a visible brand mark; absence becomes a tell. ARC preserves auth across forwarding.
MEDIUM
User training — link inspection, FIDO2-first narrative
Train users to inspect URLs (gateway rewriting makes this hard — supplement with "if it asks for password, verify out-of-band"). Roll out FIDO2 first for high-value accounts.
HIGH
Anomalous-session detection
UEBA / Azure AD Identity Protection — flag sessions from new geos, impossible travel, or non-compliant IP even when the cookie is "valid".
HIGH
Email-bomb rate limiting
Gateway-side per-recipient rate limit (e.g., max 10 msgs/min to single inbox from external senders); auto-quarantine floods.
MEDIUM
Out-of-band verification for credential entry
Any "reset password" / "verify login" flow that arrives via email should require a second channel (push to known device, callback to known number).
HIGH
Detection Methods
Advanced Email Threats
AiTM (Adversary-in-the-Middle): Reverse proxy traffic to legitimate IdP (Modlishka, Evilginx).
BEC patterns: Executive impersonation + urgent wire transfer request.
Quishing (QR phishing): QR codes in email body (bypasses URL scanners).
Conversation hijacking: Reply to existing thread with malicious link.
SIEM Detection Rules
Splunk SPL: index=email | where body matches "(wire transfer|CEO request|urgent)" | stats count by sender
SOAR playbooks: Auto-disable user account after click on known-bad URL.
Abnormal Security / Armorblox: ML-based email security with BEC detection.
Domain rotation: Use many lookalike domains; rotate as detected.
Quishing Stealth
QR code in image: Bypasses email URL scanners (can't extract URL from image).
QR code in attachment: PDF attachment with QR code; some scanners don't extract from PDF.
Redirect chain: QR → legitimate URL → attacker-controlled redirect.
Thread Hijack
Compromise one party: Reply to legitimate thread with malicious content.
Email rule creation: Hide replies in custom folder; user doesn't see responses.
Cross-References
skills/email-protocol-attack/SKILL.md — Sibling skill. Protocol-level SMTP/IMAP/Exchange abuse (enumeration, forgery, SPF/DKIM/DMARC bypass at protocol level, mailbox compromise). This skill's Phase 2 (sender reputation) builds on email-protocol-attack's protocol-level mail-auth bypass techniques; this skill does NOT re-cover protocol-level bypass — it covers reputation-engineering for spoofing success and campaign-operations on top.
skills/social-engineering/SKILL.md — Adjacent skill. Covers the human-psychology layer (pretext design, vishing, USB baiting, OSINT profiling). This skill is the infrastructure layer that executes the pretext via email.
skills/password-attack/SKILL.md — Credential attacks against captured credentials (hash cracking, password spraying) — relevant for post-campaign exploitation of harvested credentials.
skills/web-auth-bypass/SKILL.md — Session and access-control abuse; relevant for understanding why session-cookie theft (via AiTM) is so damaging.
skills/cloud-identity-attack/SKILL.md — O365 / Azure AD / Workspace identity attacks — AiTM-captured O365 sessions feed directly into this skill's cloud-identity post-exploitation.
skills/payload-generation/SKILL.md — Payload craft for the attachment path (macros, shellcode, HTA) — this skill handles delivery (HTML smuggling, decrypted-on-click), payload-generation handles what the payload does on execution.
skills/av-edr-evasion/SKILL.md — Evasion of endpoint defenses once the payload runs.
skills/osint/SKILL.md & skills/recon-osint/SKILL.md — OSINT for recipient enumeration, the input to Phase 1 (pretext).
skills/engagement-manager/SKILL.md — Scoping, authorization, rules of engagement for phishing campaigns (CRITICAL — phishing infra is high-risk, must be scoped in writing).
Threat Landscape
The email-security-deep threat landscape is shaped by commodity and APT actors who use AiTM phishing-as-a-service (PaaS) platforms to bypass MFA at scale. Understanding the active actors, their preferred techniques, and their typical infrastructure fingerprints helps red teams emulate realistic campaigns and helps blue teams tune detection rules.
Targeted email flooding as a smokescreen for credential theft
Any individual mailbox
Per-recipient rate limiting; alert on sender diversity spikes
Common Infrastructure Fingerprints
Indicators that reveal AiTM infrastructure in the wild:
TLS certificate age — newly issued (hours/days old) for a look-alike domain
Certificate Transparency log entries — crt.sh catches new look-alikes at issuance
DNS records — A record + SPF + DMARC p=none on a brand-new domain
Hosting provider — bulletproof hosting (e.g., certain Russian, Bulgarian, Moldovan providers) frequently used by PaaS operators
Phishlet signatures — specific JS injection patterns used by evilginx2/modlishka
Defensive Counter-Landscape
Threat-intel feeds: subscribe to brand-protection services (e.g., ZeroFox, Proofpoint ETP) that flag new typosquat registrations
CT log monitoring: monitor crt.sh for certificates matching patterns like micro[s5]oft.*, payp[a4]l.*
Gateway reputation feeds: keep Proofpoint/Mimecast/Defender threat intel up to date
User reporting pipeline: make it one-click for users to report suspicious mail; route to SOAR for triage
AiTM detection rules: see the KQL rule in guides/email-security-deep-deep-dive.md Step 14
Tool Comparison Matrix
Choosing the right tool for each phase depends on the target environment, scope, and depth required.
AiTM Proxy Comparison
Tool
Phishlet Model
MFA Bypass
FIDO2 Resistance
Configuration
Use Case
evilginx2
Per-service YAML phishlets
TOTP, push, SMS
FIDO2 defeats it
Declarative YAML
Standard O365/Google AiTM; most polished
modlishka
Generic with JS template injection
TOTP, push, SMS
FIDO2 defeats it
Imperative flags
Niche services without phishlets; highly customizable
evilgophish
Wraps evilginx2 + gophish
Same as evilginx2
FIDO2 defeats it
Single orchestration script
Combined AiTM + campaign management
Campaign Platform Comparison
Platform
Strength
Weakness
Best For
gophish
Open-source, REST API, large community
Basic landing-page builder
Engineering-led red teams who want API control
King-Phisher
GTK desktop UI, awareness-training features
Smaller community
Awareness training programs, HR-led campaigns
ThePhish
AI-assisted classification
Defensive tool, not offensive
SOC teams triaging reported phish
Commercial (Cofense, KnowBe4)
Polished, integrated, support
Closed-source, costly
Enterprises wanting turnkey solution
Gateway Bypass Tool Selection
Scenario
Recommended Tool
Alternative
Test URL Defense rewriting
swaks + custom HTML
MailSpoof
Verify DMARC enforcement
checkdmarc
Manual dig TXT _dmarc.<domain>
Spoofing success verification
espoofer
Manual swaks with crafted headers
Sender reputation audit
mailspoof-check
Manual checks across reputation DBs
Attachment sandbox bypass
encrypted-zip + swaks
HTML smuggling via landing page
Lab and Training Environment
For skill development without risking production systems, use isolated lab environments. The deep-dive guide (guides/email-security-deep-deep-dive.md) provides a complete end-to-end lab walkthrough.
Minimum Lab Setup
Microsoft 365 Developer Program tenant — free E5 dev tenant with 25 licenses
Linux VPS — Ubuntu 22.04+, 2 vCPU / 4 GB RAM
Registered domain — for DNS and TLS (use a clearly fictional one like securitytest.local plus real DNS)
Three test users with different MFA factors (TOTP, push, FIDO2) to measure AiTM effectiveness
Exercises: 4 hands-on exercises at the end of the deep-dive
What the Lab Does NOT Cover
For real engagements, additional skills are required:
Pretext design and OSINT — see skills/social-engineering/ and skills/osint/
Payload craft beyond HTML smuggling — see skills/payload-generation/
Endpoint evasion — see skills/av-edr-evasion/
Post-exploitation of captured sessions — see skills/cloud-identity-attack/
Protocol-level mail-auth bypass — see skills/email-protocol-attack/
Safety Notes
AUTHORIZATION IS NON-NEGOTIABLE: Phishing infrastructure is high-risk. Stand up phishing campaigns, AiTM proxies, and email-bomb tools ONLY with a signed Statement of Work that explicitly names the target recipients, the sender identities you may use, the test window, and the data-handling requirements for captured credentials/sessions. Unscoped phishing is a crime in most jurisdictions (US CFAA, UK Computer Misuse Act, EU equivalents) and causes real harm.
Capture scope limits: Captured credentials and session cookies are sensitive personal data. Per engagement scope, define: (a) what you may capture, (b) where you store it (encrypted at rest), (c) when you destroy it (typically at engagement close), (d) who may access it (named individuals only).
FIDO2 / phishing-resistant auth is the correct control: When your campaign repeatedly fails against a target, that is good — the control is working. Document the failure as a control strength in the report; do not "find a way around" without explicit re-scoping.
Email bombing is a DoS: Even with authorization, email bombing consumes victim inbox quota, can bounce legitimate mail, and can interfere with the victim's incident response. Use small volumes (e.g., 100-200 messages) only when the test objective is notification-fatigue measurement, not denial-of-service impact.
Real-world AiTM tooling (evilginx2, modlishka) is dual-use: These tools are legitimately used by red teams and security researchers AND by criminal actors. Operating them leaves fingerprints (TLS cert, DNS history, infra IP) that may be flagged by threat intel — operate only from authorized infra and expect detection.
Look-alike domains: Registering micros0ft-secure.com is typosquatting and may violate trademark law even with authorization. Where possible, use a clearly-fictional domain (security-test.local) plus an authorized subdomain of the client's own domain (securitytest.client.com) rather than typosquats.
Clean exit: At engagement close, destroy captured credentials/cookies per SoW, tear down gophish database, revoke DNS records, retire the VPS, and produce a telemetry report. Leaving phishing infra running invites abuse by third parties.
Hacker Laws
Trust but Verify — Email headers and sender display names are forgeable. Gateway rewriting (Proofpoint URL Defense, Safe Links) can itself be a vector if the rewritten URL is manipulated. Verify the true destination of any link out-of-band.
Assume Breach — When designing the client's defense, assume the attacker will get a credential. The question is whether they can convert it to a session (AiTM defeats MFA) and whether the session survives device-conditional-access (FIDO2 / CAE defeats AiTM).
Defense in Depth — No single email control suffices. Layer gateway rewriting (click-time reputation) + sandbox detonation + strict DMARC + conditional access + FIDO2 + user training. The attacker has to defeat each layer.
Economy of Mechanism — Simpler defenses are more reliable. FIDO2 (one primitive, phishing-resistant by design) beats complex multi-step MFA bypass detection.
Least Privilege — Recipient Minimization — The fewer recipients in a campaign, the smaller the blast radius if a click occurs. Targeted spearphishing is more effective AND more containable than spray-and-pray.
Learning Resources
This skill's supplementary files: payloads.md, test-cases.md