Social Engineering Tools

setoolkit

setoolkit — the Social-Engineer Toolkit (SET) — is the reference framework for human-layer attacks. From one menu-driven console it launches a whole catalog of techniques: cloning a real website to harvest credentials, generating malicious payloads and attachments, mass-mailing a phishing campaign, spoofing SMS, creating malicious QR codes, and more. It’s the classic tool for spear-phishing and credential-harvesting engagements, and it’s built to make sophisticated attacks quick to stand up so you can focus on the pretext.

Installed from the AUR (as social-engineer-toolkit); Security → Social Engineering Tools → setoolkit. SET is a menu-driven framework — running it is the action — so Oniomarchy launches you straight into its console.

Using it

SET is entirely menu-driven; you navigate by number:

setoolkit
 1) Social-Engineering Attacks
     2) Website Attack Vectors
         3) Credential Harvester Attack Method
             2) Site Cloner
   [ enter the URL to clone and the IP to POST captured creds to ]

The top-level menu covers spear-phishing, website attacks (the credential harvester and site cloner above are the most-used), infectious media, payload generation, and mass mailer. The credential harvester clones a target’s real login page and captures anything typed into it — the bread-and-butter SE demonstration.

Host the cloned page and captured results using the web servers in Running Services, and consider hooking visitors’ browsers with BeEF.