Can one well-crafted email still bypass enterprise defenses and teach a whole team about risk? That question drove a hands-on, ethical test that exposed how urgency, authority, and curiosity push users to click and hand over credentials.
Social engineering accounts for a large share of ransomware entry points, and attacks surged during the COVID period. Even with SIEM, IDS/IPS, and endpoint detection and response in place, one click can grant unwanted access.
This brief study used the Social Engineering Toolkit (SET), GoPhish, and Microsoft Defender simulations to build realistic pages, track opens, clicks, submissions, and reporting behavior. The experiment focused on governance, consent, and safe data handling rather than damage.
The goal: give security teams concrete rules of engagement, SMTP and DNS hints, and reporting templates that turn metrics into executive actions. For evidence-based training approaches and measured outcomes, see this practical guide on effective training techniques phishing training that works.
Key Takeaways
- Human factors remain the biggest gap despite technical controls.
- Urgency and authority cues dramatically increase click and submit rates.
- Ethical tests require executive buy-in, consent, and no destructive payloads.
- Use SET, GoPhish, and Defender simulations for layered, measurable tests.
- Translate opens, clicks, and reports into executive summaries and retraining cohorts.
Search intent and why this How-To matters right now
Controlled tests reveal which cues drive users to open, click, and take unsafe actions in workplace emails. This guide gives practical steps to run safe, realistic simulations that boost awareness and satisfy audit requirements.
Readers are searching for a hands-on how-to that turns plans into measurable action. The goal is clear: run defensible campaigns that improve training, document results for auditors, and lower real-world risk across an organization.

Attackers keep weaponizing news, emails, and trending events. Timely simulations help teams adapt lures for email, SMS, and voice channels so defenses match current attacks.
- Depth provided: stakeholder approvals, scope, domain and DNS choices, payloads, launch, analytics, and reporting.
- Compliance value: evidence for HIPAA, ISO 27001, SOC 2, and similar frameworks.
- Success looks like: lower click rates, higher report-to-security rates, and targeted retraining for high-risk users and groups.
Ethics matter: get leadership sponsorship, document rules of engagement, and protect sensitive information. Finally, tools differ—use GoPhish for scheduling and dashboards and deeper social engineering tools when realism and tailored content are required.
Human psychology in social engineering: urgency, authority, and curiosity
Emotional levers—urgency, authority, and curiosity—drive most successful social engineering lures. These forces shape how people read an email and decide to act. They explain why even secure environments can yield credentials on a cloned page.
Urgency turns routine messages into pressure tactics. Deadlines, service suspensions, and payroll alerts force snap decisions. Attackers often send messages late in the day to catch tired users and raise click rates.
Authority bias shortcuts caution. References to executives, HR, legal, or IT increase obedience. Fraudsters spoof familiar names and departments to lower skepticism and speed compliance.
- Curiosity: unexpected invoices or “review message” prompts entice clicks to reveal the unknown.
- Vulnerability clusters: finance, payroll, and high-volume support roles see more targeted attacks.
- Controls: teach users to pause, verify sender domains and links, and report suspicious messages.

| Driver | Typical lure | Practical defense |
|---|---|---|
| Urgency | Payroll delay, account freeze | Pause; confirm via a known channel |
| Authority | Message from CEO or HR | Verify sender domain; call the sender |
| Curiosity | Unexpected invoice or share | Hover links; open files in sandboxed viewers |
Measure outcomes: when urgency and authority combine, expect higher click and submit rates. Use targeted training and realistic simulations to reduce reflexive clicks and raise reporting awareness. For deeper background on social engineering, see social engineering in cybersecurity.
Getting stakeholder buy-in and defining scope before any test
Begin with documented approvals and a short scope statement that lists objectives, excluded tactics, and data handling rules. This aligns sponsors, protects operations, and keeps the exercise defensible.
Who signs off?
Key approvers to include
- Executive management for sponsorship and risk acceptance.
- IT directors for technical boundaries and sender profiles.
- Compliance and audit to confirm regulatory scope and evidence needs.
- Operations and project leads for business continuity and escalation paths.
Rules of engagement
Set a clear objective: test susceptibility (opens and clicks) or validate credential capture under strict controls. Limit collected information to the minimum and define retention rules.
Agree on boundaries: banned lure topics, delivery windows, and escalation steps if an issue arises. Segment recipients into general and spear groups and state whether phone or text will be part of the type of exercise.

- Document approvals and technique scope (email only, credential harvest, drive-by).
- Define success metrics: open, click, submit, and report-to-security thresholds.
- Capture audit artifacts to support SOC 2 and ISO 27001 controls and plan leader communications that emphasize learning, not blame.
Building a smart pre-campaign questionnaire to surface real-world lures
Begin with a short, structured intake that surfaces which services and file types users touch every day. Collect only the minimum information needed to craft believable emails and landing pages while protecting personal data.
Begin by asking clear questions about employee data, daily websites, and common file types. Request permitted attributes such as display name formats, departments, and location to create context-rich templates without overexposing sensitive data.

Essential discovery questions for realistic lures
- Which employee fields will you provide (first and last name, payroll bank)?
- What apps and internal services are used daily (Microsoft 365, Google Workspace, finance portals)?
- Which file types circulate most—PDF, Word, Excel—and which vendors or partners handle invoices?
- Are there repeat offender groups or blacklisted sites to exclude?
- Is the exercise spear or generic, and what are domain/email formats by country?
Follow-up interviews to calibrate difficulty
Schedule a short call to vet initial lures with stakeholders. Calibrate tone so the test offers value—neither trivially easy nor trust-eroding.
| Topic | Sample question | Actionable output |
|---|---|---|
| Employee data | Which name fields are shared? | Safe personalization rules |
| Tech stack | Daily apps and URLs? | Realistic landing pages |
| Training history | Cadence and past failures? | Timing and target cohorts |
Setting up your phishing infrastructure securely
Build an isolated test environment that mirrors inbox and web behavior while protecting production systems. Keep TLS, DNS, and sending profiles explicit so deliverability and safety can be audited.
A dedicated SMTP sending profile prevents rate limits and avoids mixing test mail with live traffic. Store credentials securely and use authenticated providers rather than corporate SMTP relays.
SPF, DKIM, and DMARC for deliverability
Publish and monitor DNS records. Sign messages with DKIM, publish SPF, and set DMARC policies that align the From: name. Track reports to tune sender reputation and reduce spam folder hits.
Hosting and TLS for landing pages
Host landing pages on hardened, isolated servers. Use valid TLS certificates so browsers show no warnings. That preserves realism and avoids alerting cautious users.

- Use unique tracking tokens in each link to attribute clicks without storing extra personal data.
- Separate duties: one team runs infrastructure; another reviews collected data under least-privilege.
- Document choices—providers, DKIM selectors, TLS ciphers—for audits and post-mortems.
Choosing and registering the right phishing domain
A domain’s history often determines whether emails land in the inbox or the spam folder. Choose names that add plausibility but stay inside ethical and legal boundaries set by your rules of engagement.

Expired domains can add deliverability value because reputation and age matter to filters. Evaluate any expired name for past spam records and backlinks; avoid ones with spammy history that will harm sending.
TLD alternatives and subdomain patterns offer authenticity. A regional TLD or a support-style subdomain can match the scenario and make a landing page feel familiar to users.
Typosquatting and IDN lookalikes mimic brands using misspellings (goggle.com), letter-number swaps (g00gle.com), extra words (googleresults.com), or homograph characters. Use these methods only to teach recognition and never to impersonate partners.
- Authenticate chosen domains with SPF, DKIM, and DMARC and monitor alignment to keep emails out of spam.
- Rotate domains across campaigns to preserve reputation and compare results fairly.
- Log ownership and renewal data securely so training operations continue without lapses.
Using the Social Engineering Toolkit to create realistic campaigns
The toolkit can reproduce familiar login journeys and build believable emails that reveal risky responses. Run simulations that respect ethics, encrypt captured data, and return clear training value.
Practical tool workflows let security teams create believable pages and unique tracking links to see which details trigger action.
Cloning login pages and crafting spear emails
Use the site cloner to match HTML/CSS and TLS behavior so a login page feels routine. Tailor templates to be brand-agnostic to avoid legal issues.
- Reference real workflows—IT notices or document shares—to increase plausibility.
- Embed one unique tracking link per recipient to attribute clicks without excess collection.
- Simulate multi-step flows (username then password) but avoid asking for unnecessary fields.
Credential harvesting mechanics and safe handling of captured data
Capture forms must store minimal values, encrypt at rest, and restrict access to named reviewers only.
| Control | Practical detail | Retention |
|---|---|---|
| Encryption | AES-256 for stored submissions | 30 days then purge |
| Access | Two-person review; audit logs | Role-based, time-limited |
| Safety stops | No droppers, no macros, disable scripts | Permanent for awareness tests |

Document scenario names, page versions, and sampling method, then debrief stakeholders to convert results into targeted training and lasting value.
GoPhish vs. SET: when to use each tool
Match the tool to the objective and the team’s skill set. Pick speed, templates, and dashboards when the goal is repeatable awareness. Choose deep cloning and technical flexibility when realism and credential capture are required.
Template building, scheduling, and analytics in GoPhish
GoPhish gives a WYSIWYG editor that cuts HTML errors and speeds template creation. It supports SMTP sending profiles, scheduling across time zones, and dashboards that show sent, opened, clicked, and submitted metrics.
Use its per-user drill-downs to assign targeted training to groups and track training completion tied to specific emails or attachments. Store named templates and sending profiles to test deliverability and reuse proven content.
When SET is the better choice
SET shines for cloning pages and crafting complex social engineering scenarios. It lets technical operators tailor pages and flows for high-fidelity testing.
- Choose GoPhish for rapid campaigns and clear results dashboards.
- Prefer SET for granular engineering tasks and cloned login pages.
- Keep libraries organized: name pages and templates so future campaigns reuse proven elements.
Selecting payloads, themes, and landing pages that mirror daily work
Design scenarios that reflect routine tasks so recipients treat messages as normal and decide quickly. This increases realism and gives clearer data on risky behavior.
Password resets, invoices, and “review message” themes that drive action
Map payloads to roles: password resets for IT, invoice reviews for finance, and “review message” alerts for general staff.
Use urgent executive-style emails sparingly; attachments can boost engagement but keep them benign and safe.
Attachments, links, and login pages: aligning complexity to your goals
Balance difficulty. Mix obvious spelling errors and subtle domain mismatches to teach pattern recognition without causing distrust.
“Real value comes when users can compare a simulated page to the genuine one and spot the differences.”
- Use links to safe cloned pages and limit captured fields.
- Include benign PDFs as an attachment example and track differences in click rates.
- Schedule sends during typical processing windows to test fatigue-driven responses.
| Scenario | Target group | Primary metric |
|---|---|---|
| Password reset | IT staff | Submit rate to cloned page |
| Invoice review | Finance | Click via link |
| Review message | General users | Attachment open vs link click |
Pre-test payloads with a small pilot and rotate scenario names to avoid coaching. After the exercise, provide side-by-side examples to help teams identify phishing and build lasting awareness. For a structured process, see how to run a phishing simulation.
Beyond email: vishing and smishing scenarios to test voice and SMS channels
Simulated calls and texts expose different human responses than email, especially when time pressure and personal details are invoked. Use realistic scenarios to test verification habits and mobile link safety across employees.
Vishing frequently targets payroll and bank accounts. Calls may ask for routing numbers, Social Security digits, or an immediate account update. Testers should mimic HR or a bank, then observe whether users verify caller identity via known channels before sharing data.
Smishing typically delivers a short message with a link that can harvest session tokens or one-time codes. Design safe landing pages to teach link inspection and domain recognition rather than capturing excess data.
Practical scenarios to run
- Payroll change call: caller claims to be HR or the bank; test whether the user requests a callback number and checks identity via official channels.
- Delivery or account SMS: message contains a short link to a safe page that demonstrates how links can forward MFA codes or session data.
- High-pressure timing: place calls or texts during busy windows to mirror attacker tactics and observe rapid decisions.
Measure, train, and coordinate
Track how many users verify via known channels, refuse to share information, or promptly report the message. Align follow-up training to observed gaps: short micro-modules on callback verification, mobile link hygiene, and never sharing one-time codes.
| Scenario | Primary target | Key metric | Recommended follow-up |
|---|---|---|---|
| Payroll impersonation call | Finance, HR | Percent who verify caller ID | Micro-module on callback verification |
| Bank spoof SMS | Employees with direct deposit | Click rate to safe page | Mobile link inspection tutorial |
| MFA code request | All users | Rate of code disclosure | MFA hygiene reminder; reporting steps |
| Delivery alert link | General staff | Report-to-security rate | Quick guide on domain recognition |
Emphasize reporting pathways for voice and SMS: instruct employees to capture caller ID and message content and to stop engaging when suspicion arises. Coordinate tests with telecom and IT to configure ethical caller IDs and short links.
For simulation best practices and referenced materials, include simulated training as part of a broader program and link relevant resources like an established industry guide on phishing simulation.
Launching a simulation in Microsoft Defender Attack simulation training
Use the Attack simulation training wizard in Defender to build, test, and refine realistic scenarios for your users. This area centralizes techniques, payload catalogs, targeting, and follow-up training so campaigns deliver measurable value.
Selecting techniques and payloads
From the portal go to Email & collaboration > Attack simulation training > Simulations. Choose a technique: Credential Harvest, Malware Attachment, Link in Attachment, Drive-by URL, or OAuth Consent Grant. Some templates include QR options for mobile tests.
Pick payloads from global or tenant catalogs. Use filters for complexity, language, theme, brand, industry, and current events. Each payload shows a predicted compromise percentage to help forecast difficulty.
Picking pages, QR options, and test validation
Choose or create a login page that matches the scenario. Include QR-enabled flows where supported.
Always send a test to yourself to validate link behavior and landing page flow on desktop and mobile. Save drafts and resume editing to incorporate stakeholder feedback before launch.
Targeting users, exclusions, and drafting simulations
Target participants by tags, departments, titles, cities, countries, or import a CSV. Apply exclusions to respect opt-outs and legal constraints.
For OAuth scenarios, configure app scopes (for example, read user mail) and branding assets. Make scopes explicit so users see clear consent screens during simulation.
- Wizard steps: name the simulation, pick a technique, select payload and page.
- Targeting: use groups, CSV import, and exclusions to refine users.
- Training: assign modules automatically or manually with due dates of 7, 15, or 30 days.
- Audit: capture results and export artifacts for leadership and future content.
Assigning security awareness training and due dates post-simulation
After a simulation ends, the urgent next step is turning behavior signals into targeted training that changes habits. This keeps lessons fresh and links results to measurable improvement.
Choose assignment mode carefully. Auto-assigned training tailors modules to behavior (opens, clicks, submissions). Manual selection lets leaders curate focused micro-lessons for specific teams or roles.
Auto-assigned or custom: which to use?
- Auto-assigned: delivers modules immediately to users who clicked or submitted, scaling quickly across groups.
- Custom: lets administrators pick content by role, department, or prior history to address targeted gaps.
Set clear due dates that respect workload and urgency. Common windows are 7, 15, or 30 days after the simulation ends. Short deadlines keep the lesson tied to the recent emails and improve completion rates.
| Mode | Typical target | Due date | Primary benefit |
|---|---|---|---|
| Auto-assigned | Users who clicked/submitted | 7–15 days | Fast remediation; scales |
| Manual | High-risk groups or repeat offenders | 15–30 days | Tailored coaching and deeper modules |
| Regulated schedule | Critical roles and auditors | Annual plus quarterly | Compliance and documented evidence |
Communicate expectations and the value of training to employees. Reinforce reporting pathways and reward positive actions like reporting suspicious messages. Track completion and correlate results against campaign metrics to show improvement.
Offer office hours or short Q&A sessions so users can discuss recent suspicious emails or pages. Ensure modules are mobile-friendly and captioned to increase access and completion. Log completions for audits and provide managers dashboards for timely follow-up.
Timing, delivery, and filter evasion: when and how messages land
Timing shapes inbox outcomes; well-timed messages ride news cycles and fatigue to reach users when guards are down. Plan delivery to match believable triggers, then validate placement with seed tests before a broad send.
Press-driven lures and late-day clicks
Schedule messages to align with real events — press releases, vendor notices, or quarter-end finance work — where urgency feels authentic. Late-day sends often catch attention lapses and raise action bias, so track hour-of-day metrics to see the effect on results.
- Seed inbox testing: validate inbox vs. spam placement, then tune SPF, DKIM, and headers to improve delivery without tripping filters.
- Randomize windows: stagger send times across recipients to reduce cross-chatter and preserve clean data.
- Monitor feedback loops: watch for internal blocks or false positives and course-correct quickly so the campaign stays representative.
- Keep pages fast: ensure the landing page and link behavior match the scenario; technical friction will lower interaction rates.
- Align monitoring: schedule delivery when the security team can respond, capturing reports and mitigating issues in real time.
Capture timing impact in reports by correlating clicks and submissions with hour-of-day. Use that data to tune future campaigns and to focus protective controls during high-risk windows.
Measuring what matters: results, percentages, and repeat offenders
Capture the most relevant signals so leaders can see true exposure and drive changes. Focus on percentages and absolute counts to make fair comparisons across groups.
Capture the full funnel: delivery, opens, clicks, form submissions, and reports to security. Each step is a different signal about awareness and process gaps.
Opened, clicked, submitted, and reported signals
Break down counts and percentage rates by users and target groups. Show how many opened emails, clicked the link, visited the page, or submitted credentials. Include vishing disclosures and SMS responses where relevant.
| Metric | Users (count) | Percentage |
|---|---|---|
| Opened | 1,240 | 62% |
| Clicked link | 310 | 15% |
| Submitted form / disclosed | 42 | 2% |
Segmenting by title, location, and groups
Split results by role, office, and department to find vulnerability clusters. Use percentages and absolute counts so small teams aren’t hidden by company totals.
- Identify repeat offenders and assign targeted training automatically.
- Correlate link and page interactions with time-of-day to refine delivery and reduce high-risk windows.
- Apply filters to isolate payload complexity and brand familiarity and test which themes drive higher click rates.
Protect data hygiene: roll up executive reports without personal names, but provide managers with lists for remediation. Share clear recommendations: update allow/block lists, tune filters, and design training modules that address the most effective lures discovered.
Reporting to executives and actioning insights
Lead with a crisp summary that shows top lures, key percentages, and next steps. Deliver short, data-led evidence that converts results into practical remediation for the organization.
Executive reports must include clear details on the type of attack, most and least effective schemes, and total users by category. Present counts for opened, clicked, submitted, and reported so leaders see exposure at a glance.
Most and least effective schemes, user counts, retraining lists
Summarize top-performing lures and low-performing ones. Include repeat offenders and groups needing training.
| Metric | Employees | Results |
|---|---|---|
| Opened | 1,240 | 62% |
| Clicked | 310 | 15% |
| Submitted / disclosed | 42 | 2% |
Embedding culture: ongoing campaigns, filters tuning, policy updates
- Action items: assign owners, timelines, and domain purchases for filter tuning.
- Culture plan: periodic campaigns, micro-training, leadership messages to normalize reporting and boost awareness.
- Cross-team: IT tunes controls, security reviews indicators, compliance tracks evidence, managers enforce completion.
Keep deliverables concise: dashboard snapshots, short narratives, and named owners so the team moves from insight to action and delivers tangible value to the organization.
What I learned from a phishing campaign with SET
A clear lesson: human choices matter more than any single control. One urgent, believable message will often outpace layered defenses and reveal real exposure.
A brief introduction sets context for two practical takeaways below. The goal is education: measure behavior and improve training rather than tally successes.
People over tech: why urgency beats many controls
An urgent prompt short-circuits caution. Well-timed authority cues caused clicks even when detection tools logged the message.
Social engineering leverages attention and trust, so programs must focus on repeated, high-quality training for people rather than one-off technical fixes.
Right-sizing difficulty, ethics, and lasting change
Calibrate scenarios so early wins build confidence and later tests raise the bar. Keep prohibited topics documented, protect collected data, and get executive sponsorship to sustain culture.
- Data-driven adjustments refine payload type, timing, and target groups to increase practical value.
- Blend tools: use SET for deep realism and platform sims for scale and integrated training.
- Behavior focus: reward reporting, share anonymized examples, and version pages and playbooks for continuous improvement.
Conclusion
Run realistic simulations on a steady cadence and act on the results fast. That simple discipline reduces vulnerability, builds trust, and proves training delivers value.
Recap: realistic tests plus timely training shift behavior across users and teams.
Commit to recurring campaigns, review results within days, and assign follow-up modules with clear due dates. This locks learning into daily work and lowers account risk.
Empower users to inspect links, verify sender domains, and report suspicious emails so they can identify phishing attempts before damage occurs.
Improve the ecosystem by tuning filters, defending lookalike names, and keeping pages and templates current as attacks evolve.
Keep leadership engaged: share concise results, named owners, and action plans so sponsorship and resources continue. For a practical how-to on safe simulations, see how to simulate a phishing attack.