Omniprey PenTesting delivers full-spectrum phishing simulation — credential relay, email campaign automation, open tracking, and live AiTM demonstrations — for authorised red team engagements.
From scenario deployment to email campaign automation to live credential relay — Omniprey PenTesting covers the full adversary simulation lifecycle.
Realistic login page replicas across 67 platforms — Microsoft, Google, Apple, banking, crypto, social and more. Engineered to replicate attacker tradecraft exactly.
Built-in phishing campaign mailer with per-operator SMTP profiles. Send personalised emails at scale using template variables — {{.FirstName}}, {{.URL}}, {{.Tracker}} and more.
Track every signal per target: sent → opened → clicked → submitted → valid creds. Open tracking pixel fires automatically. Full timeline in the results dashboard.
Submitted credentials are relayed server-side to the real login endpoint. Wrong creds show an inline error. Valid creds capture the live session cookie and redirect the target to their real account dashboard.
14 post-submission alert scenarios — IT Security Operations, Microsoft 365, CrowdStrike Falcon, CEO impersonation, compliance audit and more — demonstrating post-compromise escalation.
Schedule campaigns to send at any future date and time. The hourly cron processor handles delivery automatically — no manual trigger needed during the engagement window.
Each operator gets a fully isolated workspace — campaigns, captures, SMTP profiles, config, and targets are completely private. Access via your own subdomain with your own credentials.
Point any domain at your Omniprey workspace with a single CNAME record. Participants see only your domain throughout the engagement. No extra platform cost.
Credentials, device fingerprints, IPs and user-agents captured in real time. Auto-refreshing operator view with per-campaign open, click, submit, and valid-creds rates.
When a target submits credentials, Omniprey relays them server-side to the real login endpoint — harvesting CSRF tokens, following redirect chains, and accumulating session cookies at every hop.
Wrong credentials: inline error on the sim page, target stays engaged. Valid credentials: live session cookie captured and stored, target silently redirected to their real account dashboard.
Presets: Amazon, Microsoft, Google, Facebook, Instagram, LinkedIn, Twitter/X, Snapchat, TikTok, Discord, GitHub, Netflix, Spotify, Steam, Twitch, PayPal, Dropbox, Adobe, Apple
Omniprey orchestrates the complete attack chain — initial email, open tracking, credential relay, post-compromise escalation, and debrief.
Omniprey PenTesting is a controlled simulation platform. Every engagement requires written authorisation from the client organisation before commencement.
Every engagement is governed by a signed Rules of Engagement document defining scope, participant roster, authorised activities, and emergency stop procedures.
Simulation links and campaign emails are distributed only to enrolled, consenting participants. Credentials submitted are synthetic — never connected to live production systems.
Any Stage 2 payload demonstrations are conducted exclusively on isolated lab virtual machines, snapshotted before each exercise and disconnected from production networks.
Set up your workspace, import targets, and launch a full phishing campaign with email delivery, open tracking, credential relay, and live results — in under five minutes.
► Get Access