Social Engineering Tools

gophish

gophish is phishing done as a proper campaign platform. Where SET is quick one-off attacks, Gophish is built to run a full, measurable phishing assessment: you design email templates and landing pages in a web dashboard, define the target groups, schedule the send, and then watch a live results view as recipients open the mail, click the link, and submit credentials — every step tracked and timestamped. At the end it produces the numbers a phishing engagement is really about: open rates, click rates, and submission rates, per target.

Installed from the AUR; Security → Social Engineering Tools → gophish. It runs as a server with a web admin interface — running it is the action — so Oniomarchy launches it directly.

Using it

  1. Start Gophish; it prints an admin URL (default https://localhost:3333) and, on first run, a generated admin password in its console output.
  2. Set up a sending profile — the SMTP server the campaign mails through.
  3. Build a template and landing page — import a real email’s HTML, and clone the page you want to capture credentials on.
  4. Define target groups and launch a campaign.
  5. Watch the results dashboard — opens, clicks, and submitted data update live, and the report at the end gives you the per-target and aggregate rates.

Gophish is the tool when the deliverable is metrics on human susceptibility, run as an authorized, scoped assessment.