Loading Events

Hook, Line & Pretext Workshop: Crafting Effective Phish

Please Note: Lab experiences do not require registration and are available on a first-come, first-served basis. The room will be cleared after each session to accommodate the next group.

Every effective phishing email is really a marketing email with a hostile goal. It wins attention, builds desire, and drives a single click. This hands-on introductory workshop pulls back the curtain on that craft. In 90 minutes you’ll learn the persuasion techniques that make a lure irresistible, borrowed straight from the sales and marketing playbook: the handful of influence levers that actually move people, the copywriting structure behind a high-converting message, and the emotional triggers that turn a glance into a click. Then you’ll add the ingredient that separates a generic blast from a believable one, which is context, using open-source intelligence (OSINT) to tie a lure to a real department, location, or current event so it feels timely and true.

You won’t just watch. After we run the full method end to end against a familiar fictional target, the Scranton branch of Dunder Mifflin, you’ll roll up your sleeves and build your own department or location wide pretext against a real organization you know. You’ll walk out able to reason about why people click, not just that they do, with a repeatable process and a finished lure you can take straight back to your own awareness program.
This is a content-creation and analysis workshop. No live phishing is conducted and no email is ever sent.

Who it’s for: Aspiring and early-career security practitioners, security-awareness and blue-team staff who want to think like an attacker, IT professionals moving toward security, and students or career-changers exploring offensive security. Anyone who builds or improves a phishing-awareness program will get direct, practical value.

Level and prerequisites: Introductory. No prior phishing, red-team, or OSINT experience required. You should be comfortable using a web browser and reading professional email. Nothing to install, no coding, no command line.

What to bring:

  • A laptop with a web browser, for light open-source research during the lab
  • A real organization you know: your employer, your school or university, a nonprofit or club you belong to, or a former workplace, etc.
  • Something to write with. All worksheets are provided
  • Curiosity and a willingness to share your draft for friendly peer feedbac

What you’ll leave with:

  • The three-gates test (legality, then ethics, then morality) for vetting any campaign before it runs
  • A working command of the four influence levers that drive clicks and the “one hook, one ask, one button” rule for writing them
  • A repeatable OSINT-to-pretext method for making lures timely and relevant to a department or location
  • A completed Pretext Canvas and a draft, awareness-grade phishing email you can optionally submit to your own organization’s security-awareness program

Format and duration: A hands-on 90 minutes: about 30 minutes of instruction, a 10-minute guided case study against Dunder Mifflin, and roughly 50 minutes of lab with peer review and debrief.

What this workshop is not: It’s not a tooling or infrastructure course. There are no phishing frameworks, payloads, landing pages, or email spoofing. It’s not spear-phishing of named individuals; the focus is wide-net, department and location-level pretexts. And nothing is ever sent.

 

Jenn

Jenn (@_nextjenn) is a Senior Offensive Security Consultant and a DEF CON Black Badge holder, earned by winning the vishing competition. With over a decade of cybersecurity experience, she specializes in social engineering, physical security testing, and network penetration testing. Leveraging her background in psychology and experience as a licensed Private Investigator and Locksmith, she has led sophisticated red team engagements across physical penetration testing, phishing, vishing, and deepfake-driven operations. An active mentor and coach in the social engineering community, Jenn has judged DEF CON’s 2024 “Humans vs AI” and 2025 Vishing competitions and shares insights through podcasts and conference talks, including Wild West Hackin’ Fest and San Diego Comic-Con.

JC

“JC is a U.S. Marine Corps veteran, President of Snowfensive, and co-founder of the Social Engineering Community Village at DEF CON. With more than a decade of experience spanning information technology, digital forensics, incident response, penetration testing, and social engineering, he specializes in turning complex security concepts into practical skills people can immediately apply.

At Snowfensive, JC oversees the company’s offensive security services, including phishing, vishing, physical social engineering, covert entry assessments, and technical penetration testing across networks, wireless environments, and applications. He has designed and led human-focused security engagements for organizations across a wide range of industries, combining technical tradecraft with a practical understanding of how people, processes, and technology intersect.”

Event Information

  • Start Time: August 8, 2026 1:30 pm
  • End Time: August 8, 2026 3:00 pm
  • Venue: SEC Labs Room W320

Details

  • Date: August 8
  • Time:
    1:30 pm - 3:00 pm

Venue

  • SEC Labs Room W320