Social Engineering Tools
gophish
gophish is phishing done as a proper campaign platform. Where SET is quick
one-off attacks, Gophish is built to run a full, measurable phishing assessment: you
design email templates and landing pages in a web dashboard, define the target
groups, schedule the send, and then watch a live results view as recipients open
the mail, click the link, and submit credentials — every step tracked and
timestamped. At the end it produces the numbers a phishing engagement is really
about: open rates, click rates, and submission rates, per target.
Installed from the AUR; Security → Social Engineering Tools → gophish. It runs as a server with a web admin interface — running it is the action — so Oniomarchy launches it directly.
Using it
- Start Gophish; it prints an admin URL (default
https://localhost:3333) and, on first run, a generated admin password in its console output. - Set up a sending profile — the SMTP server the campaign mails through.
- Build a template and landing page — import a real email’s HTML, and clone the page you want to capture credentials on.
- Define target groups and launch a campaign.
- Watch the results dashboard — opens, clicks, and submitted data update live, and the report at the end gives you the per-target and aggregate rates.
Gophish is the tool when the deliverable is metrics on human susceptibility, run as an authorized, scoped assessment.