Skip to content

Professional email templates and landing pages for employee security awareness phishing simulations using GoPhish. Ready-to-deploy campaigns with realistic scenarios, educational content, and customizable branding for enterprise security training programs.

License

Notifications You must be signed in to change notification settings

HailBytes/gophish-training-templates

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

6 Commits
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

GoPhish Training Templates - Security Awareness Campaign Collection

Security Awareness GoPhish Compatible License

A comprehensive collection of professionally designed email templates and landing pages for conducting effective employee security awareness phishing simulation campaigns using the GoPhish framework.

🎯 What's Included

Security Policy Templates

πŸ“§ Email Templates (20+ Templates)

  • Realistic phishing scenarios mimicking common attack vectors
  • Corporate communication themes (IT updates, HR notifications, security alerts)
  • Social engineering templates (delivery notifications, account suspensions, payment alerts)
  • Entertainment platform impersonations (Spotify, Netflix, gaming platforms)
  • Financial service attacks (banking, wire transfers, payment confirmations)
  • Cloud service phishing (Dropbox, Google Drive, Office 365)
  • Multi-category coverage for comprehensive training programs
Security Policy Templates

πŸŽ“ Educational Modules

  • Immediate learning opportunities after simulation clicks
  • Category-specific training tailored to attack types
  • Interactive quizzes to reinforce learning
  • Real-world statistics and impact data
  • Actionable protection strategies employees can implement
  • Progressive difficulty levels for ongoing education
Security Policy Templates

🎯 Landing Pages

  • Credential harvesting pages for testing user behavior
  • Educational notification pages for immediate training
  • Mobile-optimized responsive designs for all devices
  • Professional, realistic appearance to maximize effectiveness
  • Instant educational value rather than just "gotcha" moments

πŸš€ Features

βœ… Ready-to-Deploy

  • Drop-in templates requiring minimal configuration
  • Modern GoPhish syntax with proper template variables
  • Mobile-responsive design for all screen sizes
Security Policy Templates

🎨 Industry Best Practices

  • Based on real-world attack patterns and methodologies
  • Updated for 2024 threat landscape
  • Professional design matching legitimate services

βš–οΈ Compliance & Ethics Focused

  • Designed with privacy and legal considerations
  • Educational focus over punitive measures
  • Immediate learning opportunities for participants

πŸ”§ Highly Customizable

  • Easy branding modifications for your organization
  • Configurable difficulty levels and scenarios
  • Modular design for mixing and matching components

πŸ“ Repository Structure

gophish-training-templates/
β”œβ”€β”€ πŸ“¦ delivery-shipping/
β”‚   β”œβ”€β”€ dhl_package.html
β”‚   β”œβ”€β”€ package_pickup.html
β”‚   └── education/
β”‚       └── delivery_phishing_education.html
β”œβ”€β”€ πŸ”§ it-security/
β”‚   β”œβ”€β”€ email_issues.html
β”‚   β”œβ”€β”€ mailbox_compromised.html
β”‚   β”œβ”€β”€ email_size_limit.html
β”‚   β”œβ”€β”€ system_update.html
β”‚   β”œβ”€β”€ webmail_upgrade.html
β”‚   └── education/
β”‚       └── it_security_education.html
β”œβ”€β”€ ☁️ cloud-services/
β”‚   β”œβ”€β”€ dropbox_share.html
β”‚   β”œβ”€β”€ google_drive.html
β”‚   └── education/
β”‚       └── cloud_services_education.html
β”œβ”€β”€ πŸ”— social-media/
β”‚   β”œβ”€β”€ linkedin_reminder.html
β”‚   └── education/
β”‚       └── social_media_education.html
β”œβ”€β”€ πŸ’° financial/
β”‚   β”œβ”€β”€ wire_transfer.html
β”‚   β”œβ”€β”€ skype_payment.html
β”‚   └── education/
β”‚       └── financial_education.html
β”œβ”€β”€ 🎡 entertainment/
β”‚   β”œβ”€β”€ spotify_account.html
β”‚   β”œβ”€β”€ starbucks_gift.html
β”‚   └── education/
β”‚       └── entertainment_education.html
β”œβ”€β”€ 🏒 corporate/
β”‚   β”œβ”€β”€ breaking_news.html
β”‚   β”œβ”€β”€ travel_agency.html
β”‚   └── education/
β”‚       └── corporate_education.html
β”œβ”€β”€ πŸ›οΈ government/
β”‚   β”œβ”€β”€ fdic_survey.html
β”‚   β”œβ”€β”€ crime_report.html
β”‚   β”œβ”€β”€ better_business.html
β”‚   └── education/
β”‚       └── government_education.html
β”œβ”€β”€ πŸͺŸ microsoft/
β”‚   β”œβ”€β”€ microsoft_security.html
β”‚   └── education/
β”‚       └── microsoft_education.html
β”œβ”€β”€ 🎯 landing-pages/
β”‚   β”œβ”€β”€ credential-harvest.html
β”‚   └── education-notification.html
└── πŸ“‹ campaign-guides/
    β”œβ”€β”€ implementation-guide.md
    β”œβ”€β”€ subject-lines.md
    └── best-practices.md

πŸ› οΈ Quick Start Guide

Prerequisites

  • GoPhish server installation
  • Administrative access to GoPhish interface
  • Basic understanding of phishing simulation concepts

Installation Steps

  1. Clone the Repository

    git clone https://github.com/hailbytes/gophish-training-templates.git
    cd gophish-training-templates
  2. Import Email Templates

    # Navigate to GoPhish Admin Panel
    # Go to Templates > Email Templates > New Template
    # Copy and paste HTML content from desired template
    # Configure subject line (see subject-lines.md for suggestions)
  3. Set Up Landing Pages

    # Go to Landing Pages > New Page
    # Import HTML from landing-pages/ directory
    # Configure credential capture settings if using harvest pages
  4. Create User Groups

    # Go to Users & Groups > New Group
    # Import your employee list
    # Segment by department or risk level for targeted campaigns
  5. Launch Your First Campaign

    # Go to Campaigns > New Campaign
    # Select appropriate template and landing page
    # Configure sending profile with realistic sender
    # Schedule during business hours for maximum realism

πŸ“Š Campaign Types Supported

🎯 Baseline Testing

Establish current security awareness levels across your organization

  • Recommended Templates: IT Security, Delivery notifications
  • Frequency: Quarterly
  • Target: All employees

🏒 Department-Specific Training

Focus on risks relevant to specific roles and departments

  • IT Department: Advanced technical phishing, software updates
  • Finance Team: Wire transfer scams, payment confirmations
  • HR Personnel: Resume attachments, employee-themed attacks
  • General Staff: Social media, entertainment, delivery scams

πŸ“ˆ Progressive Difficulty

Gradually increase sophistication to build resilience

  • Level 1: Obvious phishing with clear red flags
  • Level 2: Moderate sophistication with subtle indicators
  • Level 3: Advanced attacks mimicking legitimate communications
  • Level 4: Spear phishing with personalized content

πŸŽͺ Seasonal Campaigns

Leverage current events and holidays for realistic scenarios

  • Holiday Shopping: Package delivery, shopping confirmations
  • Tax Season: IRS communications, financial services
  • Back-to-School: Educational platform attacks
  • Year-End: HR benefits, company announcements

πŸŽ“ Educational Approach

🧠 Learning-Focused Design

Every template includes corresponding educational content that:

  • Explains why the attack was effective
  • Identifies specific red flags users should watch for
  • Provides real-world context and statistics
  • Offers actionable steps for future protection

πŸ“± Multi-Modal Learning

  • Visual indicators highlighting suspicious elements
  • Interactive quizzes to test comprehension
  • Scenario-based examples for practical application
  • Progressive disclosure of information to maintain engagement

πŸ“Š Measurable Outcomes

Track improvement through:

  • Click-through rate reduction over time
  • Increased reporting of suspicious emails
  • User feedback and comprehension scores
  • Behavioral change metrics

βš–οΈ Ethical Guidelines & Legal Compliance

πŸ›‘οΈ Responsible Use

These templates are designed exclusively for:

  • Authorized security awareness training within your organization
  • Educational purposes with proper consent and notification
  • Improving security posture through awareness and training

❌ Prohibited Uses

  • Unauthorized testing of external organizations
  • Malicious attacks or actual credential theft
  • Testing without proper legal authorization
  • Any activity that violates applicable laws or regulations

πŸ“‹ Best Practices

  • Obtain proper authorization before conducting simulations
  • Ensure compliance with organizational policies and applicable laws
  • Focus on education rather than punishment
  • Provide immediate learning opportunities for participants
  • Maintain confidentiality of individual results
  • Follow up with additional training for those who need it

🀝 Contributing

We welcome contributions to improve and expand this template collection!

🎯 How to Contribute

  1. Fork the repository
  2. Create a feature branch (git checkout -b feature/new-template)
  3. Add your templates following our naming conventions
  4. Include educational content for any new attack vectors
  5. Test thoroughly with GoPhish before submitting
  6. Submit a pull request with detailed description

πŸ“ Contribution Guidelines

  • Follow existing naming conventions and folder structure
  • Include both email templates and educational modules
  • Ensure mobile responsiveness for all designs
  • Test with current GoPhish version before submission
  • Provide realistic, educational content rather than obvious fake attempts
  • Include suggested subject lines and implementation notes

🌟 What We Need

  • Additional attack vectors (new platforms, services, techniques)
  • Industry-specific templates (healthcare, education, manufacturing)
  • Non-English templates for international organizations
  • Advanced persistent threat scenarios for mature security programs
  • Accessibility improvements for inclusive design

πŸ“š Additional Resources

πŸ“– Documentation

Security Policy Templates
Security Policy Templates
Security Policy Templates

πŸ”— Related Projects

🎯 Training Resources

πŸ“Š Success Metrics

πŸ“ˆ Key Performance Indicators

Track your security awareness program effectiveness:

  • Click Rate Reduction: Measure decreasing susceptibility over time
  • Reporting Increase: Monitor growth in suspicious email reports
  • Time to Report: Track how quickly users report potential threats
  • Repeat Offenders: Identify users needing additional training
  • Knowledge Retention: Test comprehension through follow-up assessments

🎯 Benchmark Goals

Industry standard targets for mature security awareness programs:

  • Click Rate: <5% for sophisticated attacks
  • Reporting Rate: >80% of suspicious emails reported
  • Response Time: <1 hour average time to report
  • Training Completion: >95% completion rate for educational modules

πŸ”„ Version History

v2.0.0 - Current Release

  • Complete template redesign with modern GoPhish syntax
  • Added educational modules for all template categories
  • Mobile-responsive design for all templates
  • Organized folder structure for better management
  • Enhanced landing pages with immediate educational value

v1.0.0 - Legacy Templates

  • Basic HTML templates with limited GoPhish integration
  • Simple phishing scenarios without educational components
  • Desktop-focused design

πŸ†˜ Support & Troubleshooting

πŸ› Common Issues

  • Template variables not rendering: Ensure proper GoPhish syntax
  • Mobile display problems: Check CSS media queries
  • Landing page capture fails: Verify form configuration in GoPhish
  • Educational modules not loading: Check file paths and permissions

πŸ’¬ Getting Help

  • Open an issue on GitHub for bugs or feature requests
  • Check existing issues before creating new ones
  • Provide detailed information including GoPhish version and error messages
  • Include screenshots for visual issues

πŸ“§ Contact

For questions about implementation or customization:

πŸ“„ License

This project is licensed under the Mozilla Public License 2.0 - see the LICENSE file for details.

πŸ”“ MPL 2.0 License Summary

  • Commercial use: βœ… Allowed
  • Modification: βœ… Allowed (with source disclosure requirements)
  • Distribution: βœ… Allowed (with license preservation)
  • Private use: βœ… Allowed
  • Patent use: βœ… Granted (with termination clause for patent litigation)
  • Trademark use: ❌ Not granted
  • Liability: ❌ Limited
  • Warranty: ❌ Limited
  • Copyleft: πŸ“„ File-level (modified files must remain open source)

πŸ” Key MPL 2.0 Requirements

  • Source Disclosure: Modified files must include source code and license notice
  • License Preservation: MPL 2.0 license must be included with distributions
  • Patent Protection: Automatic patent license grant for contributors
  • Compatibility: Can be combined with proprietary code (file-level copyleft)
  • Modifications: Changes to MPL-licensed files must remain under MPL 2.0

πŸ™ Acknowledgments

  • GoPhish Team for creating an excellent phishing simulation platform
  • Security Community for sharing knowledge and best practices
  • Contributors who help improve and expand this template collection
  • Organizations using these templates to build stronger security cultures

⚠️ Important Disclaimer

These templates are for authorized security awareness training only. Always:

  • βœ… Obtain proper authorization before conducting phishing simulations
  • βœ… Ensure legal compliance with all applicable laws and regulations
  • βœ… Focus on education rather than punishment or embarrassment
  • βœ… Respect privacy and maintain confidentiality of results
  • βœ… Follow organizational policies for security awareness training

Unauthorized use of these templates for malicious purposes is strictly prohibited and may violate local, state, and federal laws.


πŸ›‘οΈ Building Security Awareness Through Education πŸŽ“

Help us improve cybersecurity one simulation at a time

⭐ Star this repo | πŸ› Report Bug | πŸ’‘ Request Feature | 🀝 Contribute

About

Professional email templates and landing pages for employee security awareness phishing simulations using GoPhish. Ready-to-deploy campaigns with realistic scenarios, educational content, and customizable branding for enterprise security training programs.

Topics

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages