Social engineering assessment platform

SIPHON

Targets in. Evidence out.

Run an authorized phishing assessment end to end — scenario, lure, landing page, launch, and evidence — with scope enforced by the engine itself.

SIPHON — CAMPAIGN DASHBOARD
Scenarios
12 built-in · 7 categories
Pages
Multi-stage, branching
Guardrails
Domain · window · kill switch
Output
Live timeline + XLSX

Assessment pipeline

  1. Scope

    Set allowed domains and a time window.

  2. Build

    Pick a scenario, adapt lure and pages.

  3. Launch

    Deliver through a dedicated agent.

  4. Track

    Watch events land in real time.

  5. Debrief

    Export evidence for the report.

Product tour

Follow an assessment from hardened operator access and the scenario library through lure authoring, staged pages, launch controls, and the evidence you hand back.

SIPHON // Access

Secure operator access

A single hardened entry point for the assessment team, with local credentials only.

Features

Professional social engineering assessment with a terminal-noir aesthetic.

Scenario library

Start from a proven scenario instead of a blank campaign. Clone it, fill its branding slots, and adapt the chain to the engagement.

SCENARIOS — LIBRARY SIPHON scenario library showing built-in scenarios tagged by category and difficulty

Reusable assessment chains

Built-in scenario catalogue

Twelve ready scenarios spanning credential harvest, MFA phishing, document lures, IT helpdesk, and HR themes — from a single-page sign-in to a three-stage push-fatigue chain. Each one carries its email, its staged pages, and a qualification preset, with branding slots left open for the engagement.

Categories

  • Credential harvest
  • MFA phishing
  • Document lure
  • IT helpdesk
  • HR corporate
  • Training
  • Custom

Difficulty

  1. Advanced
  2. Moderate
  3. Basic

Modules

SIPHON modules are regular Django apps, discovered by the same plugin system the agent uses. Qualification modules ship in the box; everything else is an extension point.

Extension points

API endpoint
Add routes under /api/plugins/
Qualification
Add a module to the request pipeline
Importer
Turn any file format into a target group
Signals
React to campaign and result events
Frontend
Embed a page in the SIPHON sidebar
MODULE // Bundled / 16 modules

Traffic qualification suite

The chain that decides who is in scope. Each module returns a verdict; anything that is not the authorized recipient — a scanner, a sandbox, a replayed link, a request from outside the agreed geography or window — receives the benign response you configured instead of the exercise.

  • AuthzGate
  • GeoScope
  • NetScope
  • DeviceLock
  • TemporalGuard
  • ReplayGuard
  • BotFilter
  • BehaviorGate
  • BrowserPrint
  • TLSProfile
  • NetworkIntel
  • Classifier
  • Interstitial
  • ProgressiveReveal
  • Polymorph
  • WebObf

Get in touch

See SIPHON on a real engagement.

SIPHON is not public and is supplied for authorized assessments only. Reach out for a walkthrough or to hear when it becomes available.