Operations Overview
Quick start
- Setup — add a lure domain (or use the live one).
- Phish Lures — pick a template, build the lure, copy the link.
- Send the link. When a victim signs in, they appear in Captures.
- Mailbox — open their inbox and operate as them.
Recent captures
Setup
1 · Lure domain
The public domain victims visit. Your live ngrok domain is ready, or add another.
2 · Proxy & tunnel status
3 · Infra API keys
Used to provision reserved subdomains (ngrok) and DNS records (NameSilo) without leaving the panel. Stored locally in the DB, never shown in full.
Phish Lures
Build lure
Active lures
Live sessions
Device-Code Token Links
Build token link
Victim sees a passwordless sign-in page with a code; approving it captures their token. Works on consent-open tenants.
Active token lures
OAuth app consent lure not configured
Your own app registration. Victim consents on Microsoft's real page; we capture a durable refresh token (survives password resets). Consent-open tenants only.
Captures
Accounts
Detail
Nothing is selected
B2B Bulk Sender
Send bulk email as the captured victim — bypasses external-sender banners and gateway reputation. Driven by the captured session.
SMTP AUTH blast recommended
Password-based, fast, robust — uses the legacy SMTP gap (open until Dec 2026). Pick a captured account.
Session-replay blast
Uses the captured session (OWA). Slower, but no password needed.
Reply to inbox threads
Result
Files
Intel Search
Persistence
App-registration persistence
Federation-Trust Backdoor
Seam 1 (M4): with admin rights, federate a domain to an attacker-controlled issuer for trust-layer persistence that survives password resets. Loud in Entra audit — pair with cleanup.
Federate a domain
Result / cleanup
Cleanup
Keyword Listener
Watch a captured mailbox for trigger words (wire, payment, invoice...) and record hits — BEC monitoring.