Secure Scroll

Join us as we unravel the complexities of cybersecurity, breaking down core concepts and providing fresh perspectives on industry updates. Discover how AI is reshaping threat detection and response, explore powerful free tools, stay informed about groundbreaking technologies, and gain a clear roadmap for building a successful career in cybersecurity. We also provide candid insights into various security products to empower your choices.

I’m Eswar Chand Palaparthi, a cybersecurity Specialist With over 13 years of global IT and security experience—including nearly a decade optimizing Trellix/McAfee ecosystems—I bring a complete understanding of a modern organization’s security posture to the table. I specialize in troubleshooting the issues and Implementations, and architecting comprehensive defenses using a wide range of network security products, including SIEM, XDR, IPS/IDS, Vulnerability Management, and Email Security. This blog is my space to share practical, battle-tested knowledge on network defense, threat hunting, and the evolution of the modern SOC.

Quick recap: In Part 1 we built a working phishing simulator using GoPhish and hMailServer — free tools, everything running on your own machine. In Part 2 we automate the hard parts. Target research, email writing, and stack deployment — all in a few commands.

I work in detection engineering, so while this article covers the full setup, Section 6 is where my real interest is. If you are on the blue team side, skip ahead — I will not be offended.

0. Before You Start — Prerequisites

Before anything else, make sure you have these installed on your Windows machine. Everything in this article depends on them.

ToolWhat it isDownload
Python 3.8+Required to run TheHarvester and the automation scripthttps://www.python.org/downloads
OllamaRuntime that runs Phi-3 locally on your machinehttps://ollama.com/download
Docker DesktopRequired only for Section 5 — skip if you installed GoPhish manually in Part 1https://www.docker.com/products/docker-desktop

Installing Python — one important step:

When the Python installer opens, check the box that says “Add Python to PATH” before clicking Install. If you miss this, the pip command will not work and you will get an error.

After installing, open PowerShell and verify:

python --version
pip --version
1. Why Automation Matters Here

When I was setting up Part 1, the most time-consuming part was writing the email templates. Three templates took about 45 minutes — getting the tone right, making sure the urgency felt real without being obvious.

Attackers solved this problem a long time ago. They do not sit and write emails one by one. They pull public data about targets, feed it into a language model, and generate hundreds of personalized emails in minutes.

That is what we are building here. Not to attack anyone — but to understand exactly what your organization is up against, and to run better simulations with less manual effort.

Everything in this article runs on a standard laptop. No GPU. No cloud. Phi-3 is the model we are using and it runs fine on 8GB RAM.

2. Automated OSINT with TheHarvester

Before writing a phishing email, attackers do their homework. They look up who works at the company, what their job title is, and what department they are in. The more they know, the more convincing the email sounds.

TheHarvester does this automatically. Give it a domain name and it pulls names and email addresses from Google, Bing, and LinkedIn in seconds.

Install TheHarvester:

pip install theHarvester

Run it:

theHarvester -d acmecorp.com -b google,linkedin,bing -l 50
FlagWhat it does
-dThe domain you are researching
-bWhich sources to search
-lHow many results to pull

The output gives you names and emails you can drop straight into your target list. Only run this against domains you own or have written permission to test.

3. Setting Up Phi-3 with Ollama

Ollama is a runtime for local language models. Think of it the same way you think of Docker — it manages the model for you so you do not have to deal with any setup complexity. Phi-3 is the model we are loading into it. I picked Phi-3 specifically because it does not need a GPU. Most AI tools you read about online assume you have an NVIDIA card. Phi-3 runs on CPU, which means it works on a regular office laptop. After installing Ollama from the prerequisites section, open PowerShell and pull Phi-3:

ollama pull phi3

About 2.3GB download. Once it finishes, test it:

ollama run phi3 "Write a short professional email asking someone to verify their account."

If you get a response back, you are ready. Now we connect it to your target data.

4. The Python Script That Ties It Together

This script reads your target list, sends each person’s details to Phi-3, and writes out a personalized phishing email for each one. The whole thing runs in under a minute for a list of 20 people.

Install the Ollama Python library:

pip install ollama
import csv
import ollama
INPUT_FILE = "targets/sample_target_list.csv"
OUTPUT_FILE = "targets/generated_emails.txt"
PROMPT_TEMPLATE = """
Write a professional phishing simulation email for security awareness training.
The recipient's name is {first_name} {last_name} and their job title is {position}.
The email should appear to come from the IT Helpdesk asking them to verify their account.
Keep it under 150 words. Sound natural, not robotic.
"""
def generate_email(first_name, last_name, position):
prompt = PROMPT_TEMPLATE.format(
first_name=first_name,
last_name=last_name,
position=position
)
response = ollama.chat(
model="phi3",
messages=[{"role": "user", "content": prompt}]
)
return response["message"]["content"]
with open(INPUT_FILE, newline="") as csvfile:
reader = csv.DictReader(csvfile)
with open(OUTPUT_FILE, "w") as outfile:
for row in reader:
print(f"Generating email for {row['First Name']} {row['Last Name']}...")
email = generate_email(row["First Name"], row["Last Name"], row["Position"])
outfile.write(f"--- {row['First Name']} {row['Last Name']} ---\n")
outfile.write(email + "\n\n")
print(f"Done. Emails saved to {OUTPUT_FILE}")

Run it:

python generate_lures.py

Open targets/generated_emails.txt. You will see a different email for each person on your list, written around their specific job title. Copy them into GoPhish as templates and your campaign is ready to launch.

5. Docker Setup — The Whole Stack in One Command

If you do not want to install GoPhish and Ollama separately on every machine you use, Docker handles it. One file, one command, everything runs.

Make sure Docker Desktop is installed from the prerequisites section and it is running before you continue. Save this as docker-compose.yml in your project root:

version: "3.8"
services:
gophish:
image: gophish/gophish
container_name: gophish
ports:
- "3333:3333"
- "80:80"
volumes:
- ./part1/config/gophish_config.json:/opt/gophish/config.json
restart: unless-stopped
ollama:
image: ollama/ollama
container_name: ollama
ports:
- "11434:11434"
volumes:
- ollama_data:/root/.ollama
restart: unless-stopped
volumes:
ollama_data:

Start everything:

docker-compose up -d

Pull Phi-3 into the running container:

docker exec -it ollama ollama pull phi3

GoPhish is now at https://localhost:3333. Ollama is running at http://localhost:11434. Everything is local, nothing goes to the cloud.

6. How to Detect This on the Defensive Side

Building this taught me something useful — AI-generated phishing is much harder to catch with traditional filters because it does not repeat itself. This is the section I actually enjoyed writing. Building this taught me something useful — AI-generated phishing is much harder to catch with traditional filters because it does not repeat itself. Every email is slightly different, so keyword matching and signature-based detection largely miss it.

Here is what actually works:

Traditional PhishingAI-Generated Phishing
Same email body sent to everyoneUnique email per recipient
Generic greetingsCorrect name, job title, department
Obvious grammar mistakesClean, natural language
Caught by keyword filtersBypasses most content filters

Sigma rules to catch the activity:

# Rule 1 - High volume of unique outbound emails
title: Possible AI Phishing - High Volume Unique Emails
detection:
selection:
EventID: 4625
Source: SMTP
condition: selection | count() > 50 within 1h
# Legitimate senders rarely send 50+ unique emails in one hour
# Rule 2 - OSINT tool running on a corporate machine
title: OSINT Tool Execution - TheHarvester
detection:
selection:
EventID: 1
CommandLine|contains:
- 'theHarvester'
- 'harvester.py'
condition: selection
# TheHarvester on a corporate endpoint is a red flag
# Rule 3 - Ollama API traffic on the network
title: Local LLM API - Ollama Port Activity
detection:
selection:
EventID: 3
DestinationPort: 11434
condition: selection
# Port 11434 is Ollama's default port — unusual in corporate environments
7. Closing Thought

What took me 45 minutes to do manually in Part 1 now takes about 2 minutes with this setup. That is the reality of where phishing is heading — not because attackers are smarter, but because the tools got easier.

The same tools work for defenders though. You can now run monthly simulations with rotating AI-generated templates, test different departments with different lures, and do it all without a vendor platform or a budget approval.

The best phishing awareness programs are the ones that feel real. This setup gets you there.


GitHub: All files from both parts — https://github.com/chandpeshwar/phishsim-from-scratch


Sources:

Disclaimer: This article is intended for educational and defensive security purposes only. All tools, techniques, and scripts covered here are for authorized security testing within your own organization. Never run phishing simulations or OSINT tools against systems, domains, or individuals without explicit written permission. The author takes no responsibility for any misuse of the information provided.

Posted in

Leave a Reply

Discover more from Secure Scroll

Subscribe now to keep reading and get access to the full archive.

Continue reading