Tooling (GoPhish, SET)
This card covers the toolset to run and measure social engineering campaigns in an authorized engagement: from the phishing framework to credential/session capture and page cloning, always within a scope with written consent.
GoPhish (managed phishing campaigns)
Section titled “GoPhish (managed phishing campaigns)”What it does platform to launch campaigns, with tracking and metrics (open/click/credential)Pieces Sending Profile (SMTP) · Email Template · Landing Page · Users&Groups · CampaignMetrics dashboard with per-user/group rates -> basis of the awareness reportTypical use awareness simulation: measure clicks and reports, not to compromise machinesFlow: configure the sending profile (authenticated domain) → email template → landing (clone) → authorized target group → launch and observe metrics.
SET — Social-Engineer Toolkit
Section titled “SET — Social-Engineer Toolkit”What it does classic framework (Python) with several social engineering vectorsModules Credential Harvester (clones a login and captures), Website Attack, spear-phishing, payload generation, QR, etc.Use tests and demos in a lab/engagement; very didacticSession phishing / AiTM (MFA theft)
Section titled “Session phishing / AiTM (MFA theft)”Evilginx a "man-in-the-middle" proxy that relays the real login and captures the SESSION cookie -> evades MFA because it steals the already-authenticated session, not just the passwordEvilProxy an "as-a-service" offering of the same concept (used by real actors)# ONLY in an authorized engagement; shows why non-phishing-resistant MFA isn't enoughPage cloning and lures
Section titled “Page cloning and lures”- clone of the target login (SET/manual/httrack) served on own infrastructure with TLS- HTML attachments that build the landing client-side; QR for "quishing"- shorteners/redirectors for the link (within authorized scope)Supporting infrastructure
Section titled “Supporting infrastructure”- look-alike domain + categorization + SPF/DKIM/DMARC of the attacker domain (deliverability)- TLS certificate (Let's Encrypt) on the landing- secure logging and custody of captured credentials (personal data -> GDPR, destroy after report)Defense (blue team) — recognizing these tools
Section titled “Defense (blue team) — recognizing these tools”- Detection of look-alike domains and phishing kits (SET/GoPhish/Evilginx landing signatures).
- Phishing-resistant MFA (FIDO2): nullifies Evilginx/EvilProxy session theft.
- URL rewriting/detonation, mail analysis, and hunting for stolen session cookies (anomalous geo/UA).
- Threat intel on kits and domains (see IOCs & TTPs) for proactive blocking.
Real-world cases
Section titled “Real-world cases”- EvilProxy / Evilginx: mass MFA-session-theft campaigns against M365/Google documented by multiple vendors.
- SET has been a reference tool in training and pentest reports for over a decade.
- Phishing-as-a-service (PhaaS) kits lower the barrier to entry and fuel BEC at scale.
Testing checklist
Section titled “Testing checklist”- Written authorization and scope (domains, targets, exclusions)
- Chosen framework (GoPhish for metrics, SET for demo, Evilginx for AiTM)
- Domain + mail authentication + landing TLS ready
- Template and landing consistent with the pretext
- Metrics tracking configured (open/click/credential/report)
- GDPR custody and destruction of what’s captured
- Demonstrate the impact of non-phishing-resistant MFA (if in scope)