Skip to main content
PPPhishPondPhishing Tradecraft Intelligence

Attack · Detection · Validation

CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe
CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe

Research Desk

PhishPond

Phishing tradecraft research desk covering campaign analysis, adversary infrastructure, detection engineering, and validation workflows.

High signal for security teams who need tradecraft, not recycled filler.

Navigate

  • Home
  • Newsroom
  • Research
  • Subscribe

Signals

  • editorial@phishpond.dev
  • Research Mission & Ethics
  • Intel Brief
  • RSS Feed
  • Submit Research Tip
© 2026 PhishPond. Authorized security research use only.

GitHub RadarRed team tool

HailBytes/gophish-training-templates

Professional email templates and landing pages for employee security awareness phishing simulations using GoPhish. Ready-to-deploy campaigns with realistic scenarios, educational content, and customizable branding for enterprise security training programs. Primary language: HTML. 48 stars.

HTML48 stars8 forkspushed Jul 27, 2026MPL-2.0

Project links:Open GitHub projectBack to radar

README Preview

Fetched from GitHub

GoPhish Training Templates

![Security Awareness](https://github.com/HailBytes/gophish-training-templates) ![GoPhish Compatible](https://getgophish.com/) ![License](LICENSE) ![Powered by HailBytes SAT](https://hailbytes.com/sat?utm_source=github&utm_medium=repo_readme&utm_campaign=gophish-training-templates&utm_content=badge)

A comprehensive collection of professionally designed email templates and landing pages for conducting effective employee security awareness phishing simulation campaigns using the GoPhish framework.

---

Deploy These in 5 Minutes with HailBytes SAT

<p align="center"> <img src="docs/sat-ui-preview.png" alt="HailBytes SAT dashboard — template library, campaign analytics, and repeat-offender tracking" width="100%" /> </p>

Running GoPhish yourself means managing infrastructure, maintaining sending profiles, exporting CSVs to track metrics, and stitching together your own reporting. HailBytes SAT gives you all of these templates pre-loaded in a fully managed security awareness training environment — deployed inside your own AWS or Azure account (BYOC) so your data never leaves your cloud.

HailBytes SAT is built for teams that need results without the ops overhead: a hardened enterprise platform, a live metrics dashboard, multi-tenant MSSP support, and compliance documentation (SOC 2 roadmap, NIST CSF mapping) included. Whether you run one campaign a quarter or manage phishing programs for dozens of clients, SAT scales without additional infrastructure work on your end.

<p align="center"> <a href="https://aws.amazon.com/marketplace/search/results?searchTerms=hailbytes+sat&utm_source=github&utm_medium=repo_readme&utm_campaign=gophish-training-templates&utm_content=aws_cta_button"> <img src="https://img.shields.io/badge/Deploy%20on-AWS%20Marketplace-FF9900?style=for-the-badge&logo=amazonaws&logoColor=white" alt="Deploy on AWS Marketplace" /> </a> &nbsp;&nbsp; <a href="https://azuremarketplace.microsoft.com/en-us/marketplace/apps?search=hailbytes+sat&utm_source=github&utm_medium=repo_readme&utm_campaign=gophish-training-templates&utm_content=azure_cta_button"> <img src="https://img.shields.io/badge/Deploy%20on-Azure%20Marketplace-0078D4?style=for-the-badge&logo=microsoftazure&logoColor=white" alt="Deploy on Azure Marketplace" /> </a> </p>

Self-host vs. HailBytes SAT — At a Glance

| Capability | Self-host GoPhish (this repo) | HailBytes SAT (managed) | |---|---|---| | Templates | ✅ This repo | ✅ This repo + additional packs | | Hosting | You manage | BYOC in your AWS / Azure | | Metrics dashboard | DIY (CSV exports) | Built-in (click rate, report rate, time-to-report, repeat offenders) | | Compliance docs | DIY | Provided (SOC 2 roadmap, NIST CSF mapping) | | MSSP multi-tenant | DIY | Built-in | | Support | Community (GitHub Issues) | Enterprise SLA |

---

What's Included

<div align="center"> <img src="docs/images/email-templates.png" alt="Sample phishing email templates: Microsoft sign-in alert, DocuSign signature request, Amazon order problem, and Okta verification" width="100%" /> </div>

Email Templates (70+ Templates Across 20+ Industries)
📖 [Browse the full template catalog →](docs/CATALOG.md) — an auto-generated index of every template with its attack vector, difficulty, and estimated click rate.
  • Realistic phishing scenarios mimicking common attack vectors
  • Corporate communication themes (IT updates, HR notifications, security alerts)
  • Social engineering templates (delivery notifications, account suspensions, payment alerts)
  • Entertainment platform impersonations (Spotify, Starbucks)
  • Financial service attacks (banking, wire transfers, payment confirmations)
  • Cloud service phishing (Dropbox, Google Drive, Office 365)
  • Healthcare: HIPAA compliance, patient portals, insurance verification
  • Education: Student portals, financial aid, academic systems
  • Manufacturing: Supplier portals, vendor compliance, supply chain
  • Legal: Case management, confidential document sharing
  • HR/Payroll: Benefits enrollment, direct deposit, payroll systems
  • Technology/SaaS: API keys, developer portals, system updates
  • Retail: Loyalty programs, customer accounts, inventory systems
  • Hospitality: Hotel reservations, loyalty programs, booking systems
  • Utilities: Billing credits, service notifications, account management
  • LATAM / Portuguese: Banking alerts, IT helpdesk, HR onboarding, government (Brazil)
  • LATAM / Spanish: Microsoft 365, banking alerts, IT helpdesk, tax authority (SAT)
  • Multi-industry coverage for comprehensive training programs

<div align="center"> <img src="docs/images/education-modules.png" alt="Post-click security awareness training pages for corporate and financial phishing scenarios" width="100%" /> </div>

Educational Modules
  • Immediate learning opportunities after simulation clicks
  • Category-specific training tailored to attack types
  • Interactive quizzes to reinforce learning
  • Real-world statistics and impact data
  • Actionable protection strategies employees can implement
  • Progressive difficulty levels for ongoing education

<div align="center"> <img src="docs/images/landing-pages.png" alt="Credential-capture landing pages: Microsoft 365 sign-in, Okta sign-in, and a generic employee portal" width="100%" /> </div>

Landing Pages
  • Credential harvesting pages for testing user behavior
  • Educational notification pages for immediate training
  • Mobile-optimized responsive designs for all devices
  • Professional, realistic appearance to maximize effectiveness
  • Instant educational value rather than just "gotcha" moments

Features

Ready-to-Deploy
  • Drop-in templates requiring minimal configuration
  • Modern GoPhish syntax with proper template variables
  • Mobile-responsive design for all screen sizes

<div align="center"> <img src="best_practices.jpg" alt="Security Policy Templates" width="100%" /> </div>

Industry Best Practices
  • Based on real-world attack patterns and methodologies
  • Updated for 2024/2025 threat landscape
  • Professional design matching legitimate services
Compliance & Ethics Focused
  • Designed with privacy and legal considerations
  • Educational focus over punitive measures
  • Immediate learning opportunities for participants
Highly Customizable
  • Easy branding modifications for your organization
  • Configurable difficulty levels and scenarios
  • Modular design for mixing and matching components

Repository Structure

gophish-training-templates/
│   # Each category folder holds its email templates plus a metadata.json,
│   # a generated README.md, and (where applicable) an education/ training page.
│
├── ai-tools/            # (2)  AI tool impersonations (Copilot, ChatGPT)
├── cloud-services/      # (2)  Cloud storage & file sharing (Dropbox, Drive)
├── collaboration/       # (3)  Collaboration apps (Slack, Teams, Zoom)
├── corporate/           # (3)  Corporate news, travel, internal comms
├── delivery-shipping/   # (3)  Package delivery & shipping notices
├── e-signature/         # (2)  E-signature platforms (DocuSign, Adobe Sign)
├── education/           # (2)  Student portals, financial aid
├── entertainment/       # (2)  Entertainment & rewards (Spotify, Starbucks)
├── financial/           # (2)  Banking, wire transfers, payments
├── government/          # (4)  Government & regulatory agency lures
├── healthcare/          # (3)  HIPAA, patient portals, insurance
├── hospitality/         # (3)  Hotel & travel booking services
├── hr-payroll/          # (4)  HR & payroll (benefits, direct deposit)
├── identity/            # (3)  Identity providers & SSO (Okta, Duo)
├── it-security/         # (6)  Internal IT department communications
├── itsm/                # (3)  IT Service Management (ServiceNow, Jira)
├── latam-portuguese/    # (5)  Portuguese-language templates (Brazil)
├── latam-spanish/       # (4)  Spanish-language templates (LATAM)
├── legal/               # (3)  Legal authority & litigation pretexts
├── manufacturing/       # (3)  Supply-chain & vendor portals
├── microsoft/           # (6)  Microsoft products & services
├── quishing/            # (6)  QR-code phishing (quishing)
├── retail/              # (3)  Retail brands & loyalty programs
├── smishing/            # (5)  SMS phishing (smishing)
├── social-media/        # (3)  Social & professional networks (LinkedIn, Instagram)
├── technology/          # (3)  Developer & technical staff (API keys, cloud consoles)
├── utilities/           # (3)  Utility billing & disconnection notices
│
├── landing-pages/       # Credential-capture & post-click training pages
├── campaign-guides/     # Implementation, subject-line, best-practice & benchmarking guides
├── docs/                # Catalog, metrics guide, lure audit, showcase images
├── tools/               # Catalog/README generators, validator, preview & import scripts
└── tests/               # Tests for the tooling
📁 Every category folder has its own `README.md` listing the templates it contains, their attack vector and estimated click rate, suggested subject lines, the paired training page, and operator notes. For the complete cross-category index, see the [template catalog](docs/CATALOG.md).

Quick Start Guide

Prerequisites
  • GoPhish server installation
  • Administrative access to GoPhish interface
  • Basic understanding of phishing simulation concepts
Installation Steps
  1. Clone the Repository
   git clone https://github.com/hailbytes/gophish-training-templates.git
   cd gophish-training-templates
  1. Import Email Templates
   # Navigate to GoPhish Admin Panel
   # Go to Templates > Email Templates > New Template
   # Copy and paste HTML content from desired template
   # Configure subject line (see subject-lines.md for suggestions)
  1. Set Up Landing Pages
   # Go to Landing Pages > New Page
   # Import HTML from landing-pages/ directory
   # Configure credential capture settings if using harvest pages
  1. Create User Groups
   # Go to Users & Groups > New Group
   # Import your employee list
   # Segment by department or risk level for targeted campaigns
  1. Launch Your First Campaign
   # Go to Campaigns > New Campaign
   # Select appropriate template and landing page
   # Configure sending profile with realistic sender
   # Schedule during business hours for maximum realism

Campaign Types Supported

Baseline Testing

Establish current security awareness levels across your organization

  • Recommended Templates: IT Security, Delivery notifications
  • Frequency: Quarterly
  • Target: All employees
Department-Specific Training

Focus on risks relevant to specific roles and departments

  • IT Department: Advanced technical phishing, software updates, API security
  • Finance Team: Wire transfer scams, payment confirmations, invoice fraud
  • HR Personnel: Benefits enrollment, payroll updates, employee verification
  • Healthcare Workers: HIPAA compliance, patient portal security, insurance verification
  • Legal Teams: Case management, confidential document sharing
  • Manufacturing/Supply Chain: Vendor portals, supplier compliance
  • Customer Service: Account verification, loyalty programs
  • General Staff: Social media, entertainment, delivery scams
  • LATAM / Brazil Teams: Portuguese-language banking, tax, IT, and HR scenarios
Progressive Difficulty

Gradually increase sophistication to build resilience

  • Level 1: Obvious phishing with clear red flags
  • Level 2: Moderate sophistication with subtle indicators
  • Level 3: Ad