GitHub RadarRed team tool
Professional email templates and landing pages for employee security awareness phishing simulations using GoPhish. Ready-to-deploy campaigns with realistic scenarios, educational content, and customizable branding for enterprise security training programs. Primary language: HTML. 48 stars.
Project links:Open GitHub projectBack to radar
   
A comprehensive collection of professionally designed email templates and landing pages for conducting effective employee security awareness phishing simulation campaigns using the GoPhish framework.
---
<p align="center"> <img src="docs/sat-ui-preview.png" alt="HailBytes SAT dashboard — template library, campaign analytics, and repeat-offender tracking" width="100%" /> </p>
Running GoPhish yourself means managing infrastructure, maintaining sending profiles, exporting CSVs to track metrics, and stitching together your own reporting. HailBytes SAT gives you all of these templates pre-loaded in a fully managed security awareness training environment — deployed inside your own AWS or Azure account (BYOC) so your data never leaves your cloud.
HailBytes SAT is built for teams that need results without the ops overhead: a hardened enterprise platform, a live metrics dashboard, multi-tenant MSSP support, and compliance documentation (SOC 2 roadmap, NIST CSF mapping) included. Whether you run one campaign a quarter or manage phishing programs for dozens of clients, SAT scales without additional infrastructure work on your end.
<p align="center"> <a href="https://aws.amazon.com/marketplace/search/results?searchTerms=hailbytes+sat&utm_source=github&utm_medium=repo_readme&utm_campaign=gophish-training-templates&utm_content=aws_cta_button"> <img src="https://img.shields.io/badge/Deploy%20on-AWS%20Marketplace-FF9900?style=for-the-badge&logo=amazonaws&logoColor=white" alt="Deploy on AWS Marketplace" /> </a> <a href="https://azuremarketplace.microsoft.com/en-us/marketplace/apps?search=hailbytes+sat&utm_source=github&utm_medium=repo_readme&utm_campaign=gophish-training-templates&utm_content=azure_cta_button"> <img src="https://img.shields.io/badge/Deploy%20on-Azure%20Marketplace-0078D4?style=for-the-badge&logo=microsoftazure&logoColor=white" alt="Deploy on Azure Marketplace" /> </a> </p>
| Capability | Self-host GoPhish (this repo) | HailBytes SAT (managed) | |---|---|---| | Templates | ✅ This repo | ✅ This repo + additional packs | | Hosting | You manage | BYOC in your AWS / Azure | | Metrics dashboard | DIY (CSV exports) | Built-in (click rate, report rate, time-to-report, repeat offenders) | | Compliance docs | DIY | Provided (SOC 2 roadmap, NIST CSF mapping) | | MSSP multi-tenant | DIY | Built-in | | Support | Community (GitHub Issues) | Enterprise SLA |
---
<div align="center"> <img src="docs/images/email-templates.png" alt="Sample phishing email templates: Microsoft sign-in alert, DocuSign signature request, Amazon order problem, and Okta verification" width="100%" /> </div>
📖 [Browse the full template catalog →](docs/CATALOG.md) — an auto-generated index of every template with its attack vector, difficulty, and estimated click rate.
<div align="center"> <img src="docs/images/education-modules.png" alt="Post-click security awareness training pages for corporate and financial phishing scenarios" width="100%" /> </div>
<div align="center"> <img src="docs/images/landing-pages.png" alt="Credential-capture landing pages: Microsoft 365 sign-in, Okta sign-in, and a generic employee portal" width="100%" /> </div>
<div align="center"> <img src="best_practices.jpg" alt="Security Policy Templates" width="100%" /> </div>
gophish-training-templates/
│ # Each category folder holds its email templates plus a metadata.json,
│ # a generated README.md, and (where applicable) an education/ training page.
│
├── ai-tools/ # (2) AI tool impersonations (Copilot, ChatGPT)
├── cloud-services/ # (2) Cloud storage & file sharing (Dropbox, Drive)
├── collaboration/ # (3) Collaboration apps (Slack, Teams, Zoom)
├── corporate/ # (3) Corporate news, travel, internal comms
├── delivery-shipping/ # (3) Package delivery & shipping notices
├── e-signature/ # (2) E-signature platforms (DocuSign, Adobe Sign)
├── education/ # (2) Student portals, financial aid
├── entertainment/ # (2) Entertainment & rewards (Spotify, Starbucks)
├── financial/ # (2) Banking, wire transfers, payments
├── government/ # (4) Government & regulatory agency lures
├── healthcare/ # (3) HIPAA, patient portals, insurance
├── hospitality/ # (3) Hotel & travel booking services
├── hr-payroll/ # (4) HR & payroll (benefits, direct deposit)
├── identity/ # (3) Identity providers & SSO (Okta, Duo)
├── it-security/ # (6) Internal IT department communications
├── itsm/ # (3) IT Service Management (ServiceNow, Jira)
├── latam-portuguese/ # (5) Portuguese-language templates (Brazil)
├── latam-spanish/ # (4) Spanish-language templates (LATAM)
├── legal/ # (3) Legal authority & litigation pretexts
├── manufacturing/ # (3) Supply-chain & vendor portals
├── microsoft/ # (6) Microsoft products & services
├── quishing/ # (6) QR-code phishing (quishing)
├── retail/ # (3) Retail brands & loyalty programs
├── smishing/ # (5) SMS phishing (smishing)
├── social-media/ # (3) Social & professional networks (LinkedIn, Instagram)
├── technology/ # (3) Developer & technical staff (API keys, cloud consoles)
├── utilities/ # (3) Utility billing & disconnection notices
│
├── landing-pages/ # Credential-capture & post-click training pages
├── campaign-guides/ # Implementation, subject-line, best-practice & benchmarking guides
├── docs/ # Catalog, metrics guide, lure audit, showcase images
├── tools/ # Catalog/README generators, validator, preview & import scripts
└── tests/ # Tests for the tooling📁 Every category folder has its own `README.md` listing the templates it contains, their attack vector and estimated click rate, suggested subject lines, the paired training page, and operator notes. For the complete cross-category index, see the [template catalog](docs/CATALOG.md).
git clone https://github.com/hailbytes/gophish-training-templates.git
cd gophish-training-templates # Navigate to GoPhish Admin Panel
# Go to Templates > Email Templates > New Template
# Copy and paste HTML content from desired template
# Configure subject line (see subject-lines.md for suggestions) # Go to Landing Pages > New Page
# Import HTML from landing-pages/ directory
# Configure credential capture settings if using harvest pages # Go to Users & Groups > New Group
# Import your employee list
# Segment by department or risk level for targeted campaigns # Go to Campaigns > New Campaign
# Select appropriate template and landing page
# Configure sending profile with realistic sender
# Schedule during business hours for maximum realismEstablish current security awareness levels across your organization
Focus on risks relevant to specific roles and departments
Gradually increase sophistication to build resilience