📖 What is Phishing?
Phishing is a social engineering attack where the attacker sends fraudulent messages designed to trick a person into revealing sensitive information or deploying malware. These messages often mimic trusted entities and create a sense of urgency to provoke a quick, unplanned response.
"Phishing is the most common initial access vector. Look for indicators like mismatched URLs and urgent language in exam scenarios."
📚 Certification: CompTIA PenTest+ (PT0-002)
🔑 What are the Key Concepts of Phishing?
- ▸ Spear Phishing involves highly targeted attacks using OSINT to customize messages for specific individuals, increasing the likelihood of success over generic campaigns.
- ▸ Whaling is a specialized form of spear phishing that targets high-profile executives to steal sensitive corporate data or authorize fraudulent financial transactions.
- ▸ Vishing and Smishing extend phishing to voice calls and SMS messages, bypassing traditional email security filters to reach targets on mobile devices.
- ▸ Payload delivery often utilizes malicious attachments with macros or links to credential harvesting sites to establish initial access into the target network.
- ▸ Social engineering triggers like urgency, authority, and fear are used to manipulate victims into bypassing security protocols and acting without thinking.
🎯 How does Phishing appear on the PT0-002 Exam?
You may be asked to determine the most effective phishing method after performing OSINT on a specific target, requiring you to choose spear phishing over a generic campaign.
A scenario might describe an attacker sending SMS messages to employees regarding a password reset; you will need to identify this specific technique as Smishing.
Expect questions where you must analyze a provided email or URL to identify indicators of phishing, such as typosquatting or mismatched sender addresses.
❓ Frequently Asked Questions
What is the primary difference between phishing and spear phishing in a penetration test?
Phishing is a broad, 'spray-and-pray' approach targeting a large group. Spear phishing is a precision attack using specific details about the target, making it significantly more effective for bypassing security awareness.
How do attackers typically bypass email filters during a phishing simulation?
Attackers often use URL shortening, host malicious content on trusted cloud platforms like AWS or Azure, or employ homograph attacks using visually similar characters in the domain name.