Authorised Engagements Only • 67 Simulation Sites

Adversary simulation.
At scale.

Omniprey PenTesting delivers full-spectrum phishing simulation — credential relay, email campaign automation, open tracking, and live AiTM demonstrations — for authorised red team engagements.

►  Get Access Operator Dashboard
67+
Simulation Sites
18+
AiTM Presets
14
Stage 2 Templates
5
Event Signals
Platform Capabilities

Everything a red team operator needs,
in one platform

From scenario deployment to email campaign automation to live credential relay — Omniprey PenTesting covers the full adversary simulation lifecycle.

🎯

High-fidelity simulation pages

Realistic login page replicas across 67 platforms — Microsoft, Google, Apple, banking, crypto, social and more. Engineered to replicate attacker tradecraft exactly.

💌

Email campaign engine New

Built-in phishing campaign mailer with per-operator SMTP profiles. Send personalised emails at scale using template variables — {{.FirstName}}, {{.URL}}, {{.Tracker}} and more.

📈

Per-target event timeline New

Track every signal per target: sent → opened → clicked → submitted → valid creds. Open tracking pixel fires automatically. Full timeline in the results dashboard.

🔐

AiTM credential relay New

Submitted credentials are relayed server-side to the real login endpoint. Wrong creds show an inline error. Valid creds capture the live session cookie and redirect the target to their real account dashboard.

Stage 2 social engineering

14 post-submission alert scenarios — IT Security Operations, Microsoft 365, CrowdStrike Falcon, CEO impersonation, compliance audit and more — demonstrating post-compromise escalation.

Campaign scheduling New

Schedule campaigns to send at any future date and time. The hourly cron processor handles delivery automatically — no manual trigger needed during the engagement window.

🌐

Isolated operator workspaces

Each operator gets a fully isolated workspace — campaigns, captures, SMTP profiles, config, and targets are completely private. Access via your own subdomain with your own credentials.

🏦

Bring your own domain

Point any domain at your Omniprey workspace with a single CNAME record. Participants see only your domain throughout the engagement. No extra platform cost.

📋

Live capture dashboard

Credentials, device fingerprints, IPs and user-agents captured in real time. Auto-refreshing operator view with per-campaign open, click, submit, and valid-creds rates.

💌 Email Campaign Attack Chain
1
Configure SMTP
Add sending profile with Resend API key and from address
2
Build Campaign
Write HTML body with template vars, pick sim site and subject
3
Import Targets
Add target emails — name, department, email address
4
Send / Schedule
Send immediately or pick a future date for automated delivery
5
Pixel Fires
1×1 tracking pixel records open time per recipient silently
6
Target Clicks
Unique token link records click, personalised sim page loads
Results
Full timeline per target: sent, opened, clicked, submitted, valid creds
Adversary-in-the-Middle

Live credential relay — 18+ site presets

When a target submits credentials, Omniprey relays them server-side to the real login endpoint — harvesting CSRF tokens, following redirect chains, and accumulating session cookies at every hop.

Wrong credentials: inline error on the sim page, target stays engaged. Valid credentials: live session cookie captured and stored, target silently redirected to their real account dashboard.

Presets: Amazon, Microsoft, Google, Facebook, Instagram, LinkedIn, Twitter/X, Snapchat, TikTok, Discord, GitHub, Netflix, Spotify, Steam, Twitch, PayPal, Dropbox, Adobe, Apple

1.GET real login page → harvest CSRF token + session cookies
2.POST credentials with forged headers (UA, Referer, Origin)
3.Follow redirect chain (≤6 hops), merge Set-Cookie at each hop
4.Test final URL against success pattern regex
Valid: cookie stored • target → real dashboard
Invalid: inline error on sim page • target stays
Full Attack Chain

From phishing email
to debrief

Omniprey orchestrates the complete attack chain — initial email, open tracking, credential relay, post-compromise escalation, and debrief.

▸ Simulated Attack Chain — Operator Controlled
1
Phishing Email
Personalised campaign email with pixel tracker delivered to targets
2
Email Opened
Tracking pixel fires — opened_at recorded silently per recipient
3
Link Clicked
Unique token records click, loads personalised sim login page
4
Creds Submitted
AiTM relay validates against real site — result returned instantly
5
Stage 2 Alert
Social engineering escalation page demonstrates post-compromise
Debrief
Full event timeline reviewed — IOCs, detection signals, lessons
Authorisation & Ethics

Authorised engagements only

Omniprey PenTesting is a controlled simulation platform. Every engagement requires written authorisation from the client organisation before commencement.

📝

Signed rules of engagement

Every engagement is governed by a signed Rules of Engagement document defining scope, participant roster, authorised activities, and emergency stop procedures.

👤

Enrolled participants only

Simulation links and campaign emails are distributed only to enrolled, consenting participants. Credentials submitted are synthetic — never connected to live production systems.

🏭

Isolated lab environment

Any Stage 2 payload demonstrations are conducted exclusively on isolated lab virtual machines, snapshotted before each exercise and disconnected from production networks.

Ready to run your first engagement?

Set up your workspace, import targets, and launch a full phishing campaign with email delivery, open tracking, credential relay, and live results — in under five minutes.

►  Get Access