Social Engineering Tools
setoolkit
setoolkit — the Social-Engineer Toolkit (SET) — is the reference framework for
human-layer attacks. From one menu-driven console it launches a whole catalog of
techniques: cloning a real website to harvest credentials, generating malicious
payloads and attachments, mass-mailing a phishing campaign, spoofing SMS, creating
malicious QR codes, and more. It’s the classic tool for spear-phishing and
credential-harvesting engagements, and it’s built to make sophisticated attacks
quick to stand up so you can focus on the pretext.
Installed from the AUR (as social-engineer-toolkit); Security → Social
Engineering Tools → setoolkit. SET is a menu-driven framework — running it is
the action — so Oniomarchy launches you straight into its console.
Using it
SET is entirely menu-driven; you navigate by number:
setoolkit
1) Social-Engineering Attacks
2) Website Attack Vectors
3) Credential Harvester Attack Method
2) Site Cloner
[ enter the URL to clone and the IP to POST captured creds to ]
The top-level menu covers spear-phishing, website attacks (the credential harvester and site cloner above are the most-used), infectious media, payload generation, and mass mailer. The credential harvester clones a target’s real login page and captures anything typed into it — the bread-and-butter SE demonstration.
Host the cloned page and captured results using the web servers in Running Services, and consider hooking visitors’ browsers with BeEF.