The Phishing Heist: A Live Attack Simulation Demo
Modern phishing attacks are fast, convincing, and increasingly powered by AI. In this session, we demonstrate how security teams can realistically simulate these attacks using Microsoft Attack Simulation Training (MAST) enabling organizations to proactively test, measure, and improve their human security layer.
Participants are taken through a complete end-to-end phishing simulation, covering campaign design, lure creation, delivery, tracking, and result analysis. We show how AI tooling like what real attackers use can be leveraged responsibly to craft highly convincing phishing scenarios within minutes. By combining urgency, time pressure, and perceived gain, we demonstrate how realistic attack paths can be created, closely mimicking real-world threat behavior.
This session focuses on practical execution, proven best practices, and common pitfalls, providing concrete insights into how phishing simulations can become a structural and measurable component of a modern security strategy. Expect a hands-on walkthrough that moves beyond theory and delivers directly applicable techniques for both internal security programs and customer-facing security services.
The session is delivered by Tristan van Onselen (Microsoft Certified Trainer & Product Owner MDR Services) and Ferry Braeken (Cyber Security Architect), combining deep technical expertise with extensive real-world implementation experience.