Offensive security assessments
Phishing Assessment Methodology
A phishing assessment measures how an organisation's people, processes, and technical
- SOC
- Pentest
- Phishing Assessment
- Phishing Assessment Methodology
Why it matters
A phishing assessment measures how an organisation's people, processes, and technical controls stand up to social-engineering attacks. The goal is to improve resilience, not to embarrass employees, so scope, consent, and care matter at every step.
How we test it
Our operators follow a structured checklist for this topic, adapted to your API surface and authentication model.
Testing approach
- Explicit written authorization is mandatory, including approved targets, timing, and
- Agree what is out of scope (e.g. credential capture vs. just click tracking, home
- Handle any captured data securely and delete it after reporting.
- Coordinate with the blue team / IT so a real incident is not confused with the test.
- Reconnaissance (OSINT): identify the organisation's email format, public employees, technologies, and themes that make a believable pretext
- Pretext design: craft a scenario aligned to the test goal (credential harvest, attachment execution, MFA fatigue, etc.)
- Keep it realistic and ethical
- Infrastructure setup: register a look-alike domain, configure mail authentication (SPF/DKIM/DMARC) to maximise deliverability, and stand up a landing page / payload host
What we look for
- Explicit written authorization is mandatory, including approved targets, timing, and
- Agree what is out of scope (e.g. credential capture vs. just click tracking, home
- Handle any captured data securely and delete it after reporting.
- Coordinate with the blue team / IT so a real incident is not confused with the test.
- Reconnaissance (OSINT): identify the organisation's email format, public employees, technologies, and themes that make a believable pretext
- Pretext design: craft a scenario aligned to the test goal (credential harvest, attachment execution, MFA fatigue, etc.)
- Keep it realistic and ethical
- Infrastructure setup: register a look-alike domain, configure mail authentication (SPF/DKIM/DMARC) to maximise deliverability, and stand up a landing page / payload host