Skip to content

Tooling (GoPhish, SET)

This card covers the toolset to run and measure social engineering campaigns in an authorized engagement: from the phishing framework to credential/session capture and page cloning, always within a scope with written consent.

What it does platform to launch campaigns, with tracking and metrics (open/click/credential)
Pieces Sending Profile (SMTP) · Email Template · Landing Page · Users&Groups · Campaign
Metrics dashboard with per-user/group rates -> basis of the awareness report
Typical use awareness simulation: measure clicks and reports, not to compromise machines

Flow: configure the sending profile (authenticated domain) → email template → landing (clone) → authorized target group → launch and observe metrics.

What it does classic framework (Python) with several social engineering vectors
Modules Credential Harvester (clones a login and captures), Website Attack,
spear-phishing, payload generation, QR, etc.
Use tests and demos in a lab/engagement; very didactic
Evilginx a "man-in-the-middle" proxy that relays the real login and captures the SESSION
cookie -> evades MFA because it steals the already-authenticated session, not just the password
EvilProxy an "as-a-service" offering of the same concept (used by real actors)
# ONLY in an authorized engagement; shows why non-phishing-resistant MFA isn't enough
- clone of the target login (SET/manual/httrack) served on own infrastructure with TLS
- HTML attachments that build the landing client-side; QR for "quishing"
- shorteners/redirectors for the link (within authorized scope)
- look-alike domain + categorization + SPF/DKIM/DMARC of the attacker domain (deliverability)
- TLS certificate (Let's Encrypt) on the landing
- secure logging and custody of captured credentials (personal data -> GDPR, destroy after report)

Defense (blue team) — recognizing these tools

Section titled “Defense (blue team) — recognizing these tools”
  • Detection of look-alike domains and phishing kits (SET/GoPhish/Evilginx landing signatures).
  • Phishing-resistant MFA (FIDO2): nullifies Evilginx/EvilProxy session theft.
  • URL rewriting/detonation, mail analysis, and hunting for stolen session cookies (anomalous geo/UA).
  • Threat intel on kits and domains (see IOCs & TTPs) for proactive blocking.
  • EvilProxy / Evilginx: mass MFA-session-theft campaigns against M365/Google documented by multiple vendors.
  • SET has been a reference tool in training and pentest reports for over a decade.
  • Phishing-as-a-service (PhaaS) kits lower the barrier to entry and fuel BEC at scale.
  • Written authorization and scope (domains, targets, exclusions)
  • Chosen framework (GoPhish for metrics, SET for demo, Evilginx for AiTM)
  • Domain + mail authentication + landing TLS ready
  • Template and landing consistent with the pretext
  • Metrics tracking configured (open/click/credential/report)
  • GDPR custody and destruction of what’s captured
  • Demonstrate the impact of non-phishing-resistant MFA (if in scope)