跳到主要内容
知仓学习社ZHICANG

phishing-simulation-skill

Phishing simulation campaign execution and analysis for security awareness assessment

不碰外部(只输出文字)无严重或高危命中a5c-ai/babysitter

它会碰到什么

扫了多少2 个文本文件,9 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Phishing Simulation Skill

Purpose

Execute and analyze phishing simulation campaigns to assess organizational security awareness, identify high-risk users, and measure the effectiveness of security training programs.

Capabilities

Campaign Template Generation

  • Create realistic phishing email templates
  • Design landing pages for credential harvesting simulations
  • Generate attachment-based simulation scenarios
  • Create spear-phishing templates using OSINT
  • Develop pretexting scenarios
  • Build multi-stage attack simulations

Campaign Execution

  • Schedule and launch simulation campaigns
  • Manage target user groups
  • Configure sending parameters (timing, throttling)
  • Handle bounce and delivery tracking
  • Implement safe landing pages
  • Manage campaign duration and scope

User Response Tracking

  • Track email open rates
  • Monitor link click rates
  • Record credential submission attempts
  • Track attachment opens
  • Measure response times
  • Identify repeat offenders

Awareness Reporting

  • Generate campaign summary reports
  • Create department-level breakdowns
  • Produce trend analysis over time
  • Compare against industry benchmarks
  • Generate executive dashboards
  • Export data for further analysis

Risk User Identification

  • Identify users who clicked links
  • Flag users who submitted credentials
  • Track repeat high-risk behavior
  • Score user security awareness
  • Prioritize users for additional training

Training Recommendations

  • Recommend targeted training modules
  • Suggest remedial training assignments
  • Track training completion rates
  • Correlate training with behavior improvement
  • Generate training effectiveness reports

Simulation Types

| Type | Description | Risk Level |

|------|-------------|------------|

| Mass Phishing | Broad awareness testing | Low |

| Spear Phishing | Targeted attacks | Medium |

| Whaling | Executive targeting | High |

| Vishing | Voice phishing | Medium |

| Smishing | SMS phishing | Medium |

| BEC | Business email compromise | High |

Template Categories

  • Password reset notifications
  • IT support messages
  • Package delivery notifications
  • Invoice/payment requests
  • HR communications
  • Executive requests
  • Cloud service notifications
  • Social media alerts

Integrations

  • KnowBe4: Security awareness training platform
  • Proofpoint: Security awareness and phishing simulation
  • GoPhish: Open-source phishing framework
  • Cofense: Phishing defense solutions
  • Microsoft Defender: Attack simulation training

Target Processes

  • Security Awareness Training Program
  • Human Risk Assessment
  • Social Engineering Testing
  • Compliance Training Verification

Input Schema

{
  "type": "object",
  "properties": {
    "campaignType": {
      "type": "string",
      "enum": ["mass", "spear", "whaling", "department", "new-hire"],
      "description": "Type of phishing simulation"
    },
    "templateCategory": {
      "type": "string",
      "enum": ["password-reset", "it-support", "delivery", "invoice", "hr", "executive", "cloud-service"],
      "description": "Phishing template category"
    },
    "targetGroups": {
      "type": "array",
      "items": { "type": "string" },
      "description": "Target user groups or departments"
    },
    "schedule": {
      "type": "object",
      "properties": {
        "startDate": { "type": "string", "format": "date-time" },
        "endDate": { "type": "string", "format": "date-time" },
        "sendingWindow": { "type": "string" }
      }
    },
    "difficulty": {
      "type": "string",
      "enum": ["easy", "medium", "hard", "expert"],
      "description": "Simulation difficulty level"
    },
    "landingPageAction": {
      "type": "string",
      "enum": ["awareness", "training-redirect", "credential-capture"],
      "description": "Action when user clicks link"
    },
    "customTemplate": {
      "type": "string",
      "description": "Path to custom template file"
    }
  },
  "required": ["campaignType", "targetGroups"]
}

Output Schema

{
  "type": "object",
  "properties": {
    "campaignId": {
      "type": "string"
    },
    "campaignType": {
      "type": "string"
    },
    "executionPeriod": {
      "type": "object",
      "properties": {
        "startDate": { "type": "string" },
        "endDate": { "type": "string" }
      }
    },
    "targetSummary": {
      "type": "object",
      "properties": {
        "totalTargets": { "type": "integer" },
        "emailsSent": { "type": "integer" },
        "emailsDelivered": { "type": "integer" },
        "bounced": { "type": "integer" }
      }
    },
    "results": {
      "type": "object",
      "properties": {
        "emailsOpened": { "type": "integer" },
        "openRate": { "type": "number" },
        "linksClicked": { "type": "integer" },
        "clickRate": { "type": "number" },
        "credentialsSubmitted": { "type": "integer" },
        "submissionRate": { "type": "number" },
        "attachmentsOpened": { "type": "integer" },
        "reportedPhishing": { "type": "integer" },
        "reportRate": { "type": "number" }
      }
    },
    "departmentBreakdown": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "department": { "type": "string" },
          "clickRate": { "type": "number" },
          "riskScore": { "type": "number" }
        }
      }
    },
    "highRiskUsers": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "userId": { "type": "string" },
          "actions": { "type": "array" },
          "repeatOffender": { "type": "boolean" }
        }
      }
    },
    "trainingRecommendations": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "userGroup": { "type": "string" },
          "recommendedModules": { "type": "array" },
          "priority": { "type": "string" }
        }
      }
    },
    "benchmarkComparison": {
      "type": "object",
      "properties": {
        "industryAvgClickRate": { "type": "number" },
        "organizationClickRate": { "type": "number" },
        "performanceRating": { "type": "string" }
      }
    }
  }
}

Usage Example

skill: {
  name: 'phishing-simulation-skill',
  context: {
    campaignType: 'mass',
    templateCategory: 'password-reset',
    targetGroups: ['all-employees'],
    difficulty: 'medium',
    landingPageAction: 'awareness'
  }
}

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

它属于哪个仓库

星标★ 1,796
本站分层T1
该仓技能数2115
原文件路径library/specializations/security-compliance/skills/phishing-simulation-skill/SKILL.md

同一个仓库里的其他技能

看这个仓库的全部 2115 个技能