Quick recap: In Part 1 we built a working phishing simulator using GoPhish and hMailServer — free tools, everything running on your own machine. In Part 2 we automate the hard parts. Target research, email writing, and stack deployment — all in a few commands.
I work in detection engineering, so while this article covers the full setup, Section 6 is where my real interest is. If you are on the blue team side, skip ahead — I will not be offended.
0. Before You Start — Prerequisites
Before anything else, make sure you have these installed on your Windows machine. Everything in this article depends on them.
| Tool | What it is | Download |
|---|---|---|
| Python 3.8+ | Required to run TheHarvester and the automation script | https://www.python.org/downloads |
| Ollama | Runtime that runs Phi-3 locally on your machine | https://ollama.com/download |
| Docker Desktop | Required only for Section 5 — skip if you installed GoPhish manually in Part 1 | https://www.docker.com/products/docker-desktop |
Installing Python — one important step:
When the Python installer opens, check the box that says “Add Python to PATH” before clicking Install. If you miss this, the pip command will not work and you will get an error.
After installing, open PowerShell and verify:
python --versionpip --version

1. Why Automation Matters Here
When I was setting up Part 1, the most time-consuming part was writing the email templates. Three templates took about 45 minutes — getting the tone right, making sure the urgency felt real without being obvious.
Attackers solved this problem a long time ago. They do not sit and write emails one by one. They pull public data about targets, feed it into a language model, and generate hundreds of personalized emails in minutes.
That is what we are building here. Not to attack anyone — but to understand exactly what your organization is up against, and to run better simulations with less manual effort.
Everything in this article runs on a standard laptop. No GPU. No cloud. Phi-3 is the model we are using and it runs fine on 8GB RAM.
2. Automated OSINT with TheHarvester
Before writing a phishing email, attackers do their homework. They look up who works at the company, what their job title is, and what department they are in. The more they know, the more convincing the email sounds.
TheHarvester does this automatically. Give it a domain name and it pulls names and email addresses from Google, Bing, and LinkedIn in seconds.
Install TheHarvester:
pip install theHarvester
Run it:
theHarvester -d acmecorp.com -b google,linkedin,bing -l 50
| Flag | What it does |
|---|---|
-d | The domain you are researching |
-b | Which sources to search |
-l | How many results to pull |
The output gives you names and emails you can drop straight into your target list. Only run this against domains you own or have written permission to test.
3. Setting Up Phi-3 with Ollama
Ollama is a runtime for local language models. Think of it the same way you think of Docker — it manages the model for you so you do not have to deal with any setup complexity. Phi-3 is the model we are loading into it. I picked Phi-3 specifically because it does not need a GPU. Most AI tools you read about online assume you have an NVIDIA card. Phi-3 runs on CPU, which means it works on a regular office laptop. After installing Ollama from the prerequisites section, open PowerShell and pull Phi-3:
ollama pull phi3
About 2.3GB download. Once it finishes, test it:
ollama run phi3 "Write a short professional email asking someone to verify their account."
If you get a response back, you are ready. Now we connect it to your target data.
4. The Python Script That Ties It Together
This script reads your target list, sends each person’s details to Phi-3, and writes out a personalized phishing email for each one. The whole thing runs in under a minute for a list of 20 people.
Install the Ollama Python library:
pip install ollama
import csvimport ollamaINPUT_FILE = "targets/sample_target_list.csv"OUTPUT_FILE = "targets/generated_emails.txt"PROMPT_TEMPLATE = """Write a professional phishing simulation email for security awareness training.The recipient's name is {first_name} {last_name} and their job title is {position}.The email should appear to come from the IT Helpdesk asking them to verify their account.Keep it under 150 words. Sound natural, not robotic."""def generate_email(first_name, last_name, position): prompt = PROMPT_TEMPLATE.format( first_name=first_name, last_name=last_name, position=position ) response = ollama.chat( model="phi3", messages=[{"role": "user", "content": prompt}] ) return response["message"]["content"]with open(INPUT_FILE, newline="") as csvfile: reader = csv.DictReader(csvfile) with open(OUTPUT_FILE, "w") as outfile: for row in reader: print(f"Generating email for {row['First Name']} {row['Last Name']}...") email = generate_email(row["First Name"], row["Last Name"], row["Position"]) outfile.write(f"--- {row['First Name']} {row['Last Name']} ---\n") outfile.write(email + "\n\n")print(f"Done. Emails saved to {OUTPUT_FILE}")
Run it:
python generate_lures.py
Open targets/generated_emails.txt. You will see a different email for each person on your list, written around their specific job title. Copy them into GoPhish as templates and your campaign is ready to launch.
5. Docker Setup — The Whole Stack in One Command
If you do not want to install GoPhish and Ollama separately on every machine you use, Docker handles it. One file, one command, everything runs.
Make sure Docker Desktop is installed from the prerequisites section and it is running before you continue. Save this as docker-compose.yml in your project root:
version: "3.8"services: gophish: image: gophish/gophish container_name: gophish ports: - "3333:3333" - "80:80" volumes: - ./part1/config/gophish_config.json:/opt/gophish/config.json restart: unless-stopped ollama: image: ollama/ollama container_name: ollama ports: - "11434:11434" volumes: - ollama_data:/root/.ollama restart: unless-stoppedvolumes: ollama_data:
Start everything:
docker-compose up -d
Pull Phi-3 into the running container:
docker exec -it ollama ollama pull phi3
GoPhish is now at https://localhost:3333. Ollama is running at http://localhost:11434. Everything is local, nothing goes to the cloud.
6. How to Detect This on the Defensive Side
Building this taught me something useful — AI-generated phishing is much harder to catch with traditional filters because it does not repeat itself. This is the section I actually enjoyed writing. Building this taught me something useful — AI-generated phishing is much harder to catch with traditional filters because it does not repeat itself. Every email is slightly different, so keyword matching and signature-based detection largely miss it.
Here is what actually works:
| Traditional Phishing | AI-Generated Phishing |
|---|---|
| Same email body sent to everyone | Unique email per recipient |
| Generic greetings | Correct name, job title, department |
| Obvious grammar mistakes | Clean, natural language |
| Caught by keyword filters | Bypasses most content filters |
Sigma rules to catch the activity:
# Rule 1 - High volume of unique outbound emailstitle: Possible AI Phishing - High Volume Unique Emailsdetection: selection: EventID: 4625 Source: SMTP condition: selection | count() > 50 within 1h# Legitimate senders rarely send 50+ unique emails in one hour# Rule 2 - OSINT tool running on a corporate machinetitle: OSINT Tool Execution - TheHarvesterdetection: selection: EventID: 1 CommandLine|contains: - 'theHarvester' - 'harvester.py' condition: selection# TheHarvester on a corporate endpoint is a red flag# Rule 3 - Ollama API traffic on the networktitle: Local LLM API - Ollama Port Activitydetection: selection: EventID: 3 DestinationPort: 11434 condition: selection# Port 11434 is Ollama's default port — unusual in corporate environments
7. Closing Thought
What took me 45 minutes to do manually in Part 1 now takes about 2 minutes with this setup. That is the reality of where phishing is heading — not because attackers are smarter, but because the tools got easier.
The same tools work for defenders though. You can now run monthly simulations with rotating AI-generated templates, test different departments with different lures, and do it all without a vendor platform or a budget approval.
The best phishing awareness programs are the ones that feel real. This setup gets you there.
GitHub: All files from both parts — https://github.com/chandpeshwar/phishsim-from-scratch
Sources:
- GoPhish — https://getgophish.com
- Ollama — https://ollama.com
- Microsoft Phi-3 — https://azure.microsoft.com/en-us/products/phi-3
- TheHarvester — https://github.com/laramies/theHarvester
- Docker Desktop — https://www.docker.com/products/docker-desktop
- MITRE ATT&CK T1566 (Phishing) — https://attack.mitre.org/techniques/T1566
Disclaimer: This article is intended for educational and defensive security purposes only. All tools, techniques, and scripts covered here are for authorized security testing within your own organization. Never run phishing simulations or OSINT tools against systems, domains, or individuals without explicit written permission. The author takes no responsibility for any misuse of the information provided.
Leave a Reply