Week 07 · overview
Week 7: Phishing and OSINT
This week combines two ideas from the Garden State Cyber human-factor unit:
- how phishing messages create believable pressure
- how public information can make those messages more convincing
This week
Lesson 1: Phishing: Read the Message Before You Trust the Story
Analyze sender information, requests, URLs, attachments, pressure tactics, and verification paths. Practice classifying synthetic messages as likely legitimate, suspicious, or unresolved.
Lesson 2: OSINT: What Can Public Information Reveal?
Use a teacher-provided fictional Tony Stark-style dataset to practice focused OSINT analysis, source correlation, confidence ratings, and privacy-aware mitigation.
Lesson 3: Phish Myself: Design the Attack, Then Defeat It
Create a fictional personalized phishing artifact, annotate the persuasion choices, build the defensive mirror, and peer-review it without sending or deploying anything.
What you will produce
- phishing evidence ledger
- message decision flowchart
- fictional OSINT source table and correlation graph
- OSINT risk brief
- synthetic phishing artifact
- attack/defense mirror
- phishing-resistant workflow
The key idea is:
Personal context can make deception stronger, so verification has to be stronger than familiarity.