PhishCraft

Train your team against the attacks they actually face

  • Email, SMS, WhatsApp, QR
  • Techniques that get past MFA
  • Automatic remediation
phishcraft / dashboard
PhishCraft campaign dashboard

One campaign, one picture of the risk

SAMPLE CAMPAIGN, 1,000 RECIPIENTS
Delivered 1.000

100%

Opened 642

64%

Clicked 218

22%

Credentials 74

8%

Trained 218

22%

Campaign flow

From bait to report, one line you can trace

Every stage leaves an auditable trace, so the simulation result does not stop at a click count.

01

Scoping

Target groups, schedule, and rules of engagement are agreed up front.

02

Bait

Templates and channels are chosen, and every recipient gets a unique link of their own.

03

Interaction

Opens, clicks, replies, and QR scans are all recorded with their timestamps.

04

Capture

The credential page records the attempt without ever storing the real password.

05

Remediation

Whoever fails is enrolled straight into the relevant course, automatically.

06

Report

Risk scores per department and a summary ready for the board meeting.

Campaign channels

Test through the same routes a real attacker uses

To the whole finance team tracking pixel
Notice of payslip adjustment for this period

An HTML template with a tracking pixel, reply tracking, and a beaconed attachment. Every recipient gets a unique link, so interaction can be mapped person by person.

  • Open rate
  • Reply tracking
  • Attachment beacon
  • Landing page
Advanced techniques

Five techniques that mirror today attack chains

Not just a fake link. This set tests how ready the team is against techniques attackers already use in the field.

gets past MFA

Browser-in-the-Middle

Real time session hijacking through headless Chrome. It proxies the genuine login page and captures MFA tokens, cookies, localStorage, and the browser profile.

command execution

ClickFix

A fake CAPTCHA page or system prompt that walks the target into running a PowerShell command. Cloudflare, reCAPTCHA, and Windows Update templates are included.

OAuth abuse

ConsentFix

An OAuth phishing simulation: the user logs in normally, then is asked to copy a URL containing the authorization code into a malicious page.

Entra ID

Device Code Phishing

An OAuth 2.0 Device Authorization Grant simulation against Microsoft Entra ID, with token capture and reconnaissance through the Microsoft Graph API.

phishlet

AitM Phishing

A transparent MITM proxy for advanced simulations. Each phishlet defines its proxy hosts, credential capture rules, and bait URLs.

Every technique runs inside a written authorisation

Scope, time window, and forbidden actions are agreed before the campaign starts, complete with an emergency stop procedure.

Automatic training

A failed simulation triggers a course, with no manual work

AUTOMATIC TRIGGERS
Bait link clicked Phishing awareness basics course
Credentials submitted Password and MFA protection module
Attachment opened Malicious attachment and macro module

Learning paths arrange the curriculum in order with prerequisites, guiding a participant from the basics through to advanced material.

SCORM 1.2

Upload, edit, and serve SCORM packages with progress tracking, exam scoring, and certificates.

PDF to SCORM

Turn any PDF into an interactive course with AI generated modules and quizzes.

Learning path

A tiered curriculum with prerequisites between modules.

Analytics and reporting

Numbers you can take to the meeting, not only to a ticket

POSTURE SCORE

A real time posture gauge, phishing funnel, activity chart, and a live event feed in one dashboard.

RISK PER DEPARTMENT 30 DAYS
  • Finance 82
  • Operations 64
  • Sales 48
  • Technology 26

Financial impact estimates, annualized loss expectancy, and high risk user identification all follow the same numbers.

Executive summary

A board ready overview with AI insight, industry benchmarks, and export formats.

Campaign comparison

Open rate, click rate, and submission rate side by side across campaigns.

Browser extension

A defence that works where the attack lands

A multi platform extension with browser level monitoring, giving real time protection against phishing, session hijacking, identity abuse, and tracking.

https://login.microsoftonline.com.verify-id.co blocked

Protection

  • Block ClickFix
  • Block ConsentFix
  • Block AiTM
  • Block last mile reassembly

Detection

  • Extension auditor
  • Device code phishing detection
  • Browser-in-the-browser detection

Privacy

  • Fingerprinting shield
  • Tracker pixel blocker
  • Clipboard hijack monitor

Control

  • Safe search enforcer
  • PII shield for AI tools
  • Ad blocker
  • Custom content blocking
SUPPORTED BROWSERS
  • Chrome
  • Firefox
  • Safari
  • Brave
  • Opera
  • Edge
Enterprise security

Firm identity, roles, and data isolation

AUTHENTICATION AND IDENTITY

MFA and 2FA TOTP based two factor authentication
SSO and OIDC OpenID Connect with Okta, Azure AD, and Google Workspace
LDAP and AD sync Automatic import of users, groups, and departments from Active Directory
API key Programmatic access with HMAC signed headers

Granular permissions are enforced on both the frontend and the backend, and multi tenant isolation makes sure data never crosses a workspace boundary.

SIX WORKSPACE ROLES

  • Owner Full access including workspace deletion
  • Admin Every feature except deletion
  • Campaign manager Campaigns, templates, groups, and domains
  • Trainer Courses, enrolment, and learning paths
  • Analyst Dashboards and reports, read only
  • Viewer All data, read only

An AI assistant for campaigns and analysis

Connect the major LLM providers through the Model Context Protocol for real time access to campaign data, template generation, and risk summaries.

  • OpenAI
  • Claude
  • DeepSeek
  • Gemini
  • Groq
  • Mistral
  • Ollama
SCHEDULE A DEMO

Ready to test the most human layer of your defence?

We run one sample campaign together with your team, from building the bait to the risk report you can take into a meeting.

  • Answer within one working day
  • NDA available
  • Pilot campaign
WHATSAPP