Week 07 · overview

Week 7: Phishing and OSINT

This week combines two ideas from the Garden State Cyber human-factor unit:

  • how phishing messages create believable pressure
  • how public information can make those messages more convincing

This week

Lesson 1: Phishing: Read the Message Before You Trust the Story

Analyze sender information, requests, URLs, attachments, pressure tactics, and verification paths. Practice classifying synthetic messages as likely legitimate, suspicious, or unresolved.

Lesson 2: OSINT: What Can Public Information Reveal?

Use a teacher-provided fictional Tony Stark-style dataset to practice focused OSINT analysis, source correlation, confidence ratings, and privacy-aware mitigation.

Lesson 3: Phish Myself: Design the Attack, Then Defeat It

Create a fictional personalized phishing artifact, annotate the persuasion choices, build the defensive mirror, and peer-review it without sending or deploying anything.

What you will produce

  • phishing evidence ledger
  • message decision flowchart
  • fictional OSINT source table and correlation graph
  • OSINT risk brief
  • synthetic phishing artifact
  • attack/defense mirror
  • phishing-resistant workflow

The key idea is:

Personal context can make deception stronger, so verification has to be stronger than familiarity.