Test your people the way real attackers do. Safely.

Anglerfish emulates modern social-engineering attacks — AI phone calls, deepfake video, and phishing email — against your own organization, under strict, auditable control.

Request a Demo

Phishing is how real breaches start. Most teams can only test it by hand.

Anglerfish brings the automation and realism attackers now use — and wraps it in the governance a defensible program requires.

Anglerfish

Adversary emulation for the human layer.

A security-testing platform that lets authorized red teams run realistic campaigns — then prove the testing itself stayed inside the lines.

Red & purple teams

Run realistic, repeatable campaigns at scale without standing up bespoke tooling for every engagement.

Security leaders

Quantify human-layer risk and show measurable improvement over time to the board.

MSSPs & consultancies

Deliver consistent, well-governed social-engineering assessments across many clients.

Capabilities

Three attack channels, one orchestration layer.

Anglerfish runs the channels real attackers combine — through campaign, monitoring, and reporting surface. It captures the engagement. It never hosts your sensitive infrastructure.

Key Features

Voice — AI vishing calls

Real-time AI agents place outbound calls with natural, low-latency speech. Each call follows an approved persona and script, adapts to whoever answers, and is fully transcribed and recorded. Per-call safety classification runs inline.

Video — consented avatar

A photorealistic avatar of a consented executive joins a meeting and delivers an approved message. Built on a three-party consent floor — subject, sponsoring org, and avatar vendor — before any avatar can be used.

Email — targeted phishing

Operator-run, bring-your-own-infrastructure campaigns with funnel capture across opens, clicks, and submissions. The platform references your phishing infrastructure rather than hosting it.

OSINT — target intelligence

Structured reconnaissance to inform realistic pretexts and prioritize targets. On the roadmap.

Campaigns tie it together

Define reusable engagements — persona, script, channel, configuration — and run them against managed target groups on a schedule, within an authorized window, against an explicit allow-list. Every dispatch, call, and outcome lands in one place with live monitoring and cost telemetry.

Safety & governance

Built to stay inside the lines.

The hard part of offensive testing isn't the attack. It's keeping it authorized, scoped, and accountable. Governance is the core of Anglerfish, not an afterthought.

Realism without recklessness.

Recordings and rendered clips are stored encrypted and access-controlled, with playback via short-lived signed links and every access logged. Sensitive infrastructure and biometric liability stay with you and your vendors — Anglerfish captures configuration and outcomes, not the attack infrastructure itself.

Rules of engagement
Every campaign is bound to a signed, hash-referenced RoE document. No dispatch happens outside an authorized engagement.
Consent gates
The video channel cannot activate without a complete three-party consent record. Only verified, consented avatars can be used.
Allow-lists & test pools
Targets must be on an explicit allow-list. A verified test pool lets operators dry-run safely before touching real recipients.
Live kill switch
An operator halt instantly stops an in-progress engagement — verified end-to-end as a hard stop.
Inline safety classification
A content-safety gate evaluates the conversation in real time and ends any interaction that drifts outside policy.
Tamper-evident audit chain
Authorizations, dispatches, and access events are recorded in a hash-linked audit trail for defensible reporting.
How It Works

From authorization to outcome.

An operator configures an engagement in the console. A policy core validates every action against the rules of engagement and current state, then dispatches the right channel worker to drive the underlying provider. Results stream back live.

Operator: Console, Web, API
Policy Core: RoE, State, Audit
Agents: Voice + Video + Email