- Phishing infrastructure architecture and OPSEC
- Authentication abuse and token manipulation
- Reverse proxy–based Adversary-in-the-Middle (AiTM) tradecraft
- MFA downgrade and identity bypass techniques
- Consent grant manipulation across cloud identity providers
- Living-off-user execution vectors

The course content is divided across 3 sections listed below:
Foundations of Phishing
- Phishing methods (Email, SMS, Vishing, AiTM, BiTB)
- Real-world case studies
- Security controls (Email gateways, SWGs)
- Phishing artifacts (Domain, DNS, TLS, Proxies)
- Authentication fundamentals (OAuth, OIDC, Device Code)
- Tokens (JWT, Access/Refresh/ID)
- MFA mechanisms (TOTP, FIDO2, WebAuthN, Windows Hello)
OpSec-Focused Phishing Infrastructure
- Infrastructure components (Email servers, Redirectors, Reverse proxies, GoPhish)
- Domain & email OPSEC
- DNS proxying & CDN fronting
- Evilginx3 setup & phishlet development
- Serverless phishing (Cloudflare Workers, AWS, Azure, GCP)
- Automated deployment (RedInfraCraft)
- Bot detection & blocking (JA3, JA4, JARM, CAPTCHA, interaction filtering)
Offensive Phishing Operations
- Pretext development & BiTB mechanisms
- Device Code phishing
- Living-Off-User execution techniques
- Consent grant manipulation (Azure & Google)
- MFA downgrade tradecraft
- SWG bypass
Pre-requisites
Following are the requirements:
- System with 8GB+ RAM
- Ability to run a hypervisor (VMware / VirtualBox / Hyper-V)
- Basic understanding of:
- Networking concepts
- HTTP requests & responses
- DNS fundamentals
- TLS basics
- Familiarity with:
- Linux command line
- Web technologies (HTML, JS basics)
- Basic scripting knowledge (Python/JS preferred)
Target Audience
Targeted Audience may include the following group of people:
- Red Teamers & Offensive Security Professionals
- Security Researchers
- Pentesters
- Detection Engineers wanting attacker insight
- Identity & IAM Security Professionals
- Cloud Security Engineers
- Advanced Blue Team members seeking adversary simulation knowledge

Premium Version
Offensive Phishing Operations (OPO)
$49 ($̶9̶9̶)
Top features:
- Full HD video training
- Comprehensive PDF study material
- Infrastructure deployment exercises
- Certificate of Completion




































