Talkin' About [Infosec] News, Powered by Black Hills Information Security

Webcast: How to Build a Phishing Engagement – Coding TTP’s


Listen Later























Building a phishing engagement is hard. While the concept is straightforward, real-world execution is tricky. Being successful takes enormous amounts of up-front setup and knowledge in quickly evolving phishing tactics. While there is always a need to craft a custom email, the most considerable amount of work is setting up an infrastructure to make it all work.



Wouldn’t it be nice if you had a playbook of how to set everything up to save time and prevent mistakes?



What if we coded this playbook so we could share this with others and modify our tactics when things change?



In this Black Hills Information Security (BHIS) webcast, we’re going to do just that. We will take a top-down look at how a phishing engagement is designed. Then we will work through coding this design, so we don’t have to keep building a phish. Lastly, we will touch on how to fly under the radar and how coding TTP’s help save time and guarantee accuracy.



Join the BHIS Community Discord: https://discord.gg/bhis



Music By Beau: https://www.nobandwidth.io



00:00 – FEATURE PRESENTATION: How to Build a Phishing Engagement – Coding TTP’s



01:06 – About Ralph May



01:58 – Disclaimers



03:19 – Overview



03:56 – Phishing is Hard



06:33 – Infrastructure



07:12 – Operational Security



08:39 – Designing a Phish



13:18 – Phishing Emails



15:48 – 1st Tool: EVILGINX2



17:30 – EVILGINX IOC’s



18:20 – 2nd Tool: GoPhish



19:08 – GoPhish IOC’s



20:52 – 3rd Tool: NGINX



...more
View all episodesView all episodes
Download on the App Store

Talkin' About [Infosec] News, Powered by Black Hills Information SecurityBy Black Hills Information Security

  • 4.8
  • 4.8
  • 4.8
  • 4.8
  • 4.8

4.8

90 ratings


More shows like Talkin' About [Infosec] News, Powered by Black Hills Information Security

View all
Risky Business by Patrick Gray

Risky Business

365 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

636 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

366 Listeners

Hacked by Hacked

Hacked

183 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,009 Listeners

Smashing Security by Graham Cluley & Carole Theriault

Smashing Security

312 Listeners

Click Here by Recorded Future News

Click Here

414 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

7,909 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

166 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

189 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

74 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

127 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

43 Listeners

Hacker And The Fed by Chris Tarbell & Hector Monsegur

Hacker And The Fed

167 Listeners