1. Social-Engineer Toolkit (SET)
Description:
The Social-Engineer Toolkit (SET) is a collection of tools designed specifically for social engineering attacks. It can perform phishing attacks, credential harvesting, website cloning, and spear-phishing. SET is widely used by penetration testers to simulate social engineering scenarios.
Examples:
- Launch SET:
- setoolkit
- Launch SET:
Explanation: Starts the Social-Engineer Toolkit in interactive mode, providing a menu-driven interface to choose various attack options.
- Website Attack Vector:
- Choose the “Social-Engineering Attacks” > “Website Attack Vectors” > “Credential Harvester Attack Method.”
- Set the URL for the cloned site. Explanation: Clones a website to harvest credentials when users try to log in. This method is useful for phishing attacks.
- Spear-Phishing Attack:
- Choose “Social-Engineering Attacks” > “Spear-Phishing Attack Vectors.”
- Provide a crafted email and payload to be sent to the target. Explanation: Generates a malicious document that can be attached to an email. The email is crafted to appear convincing, tricking the target into opening the attachment.
- Website Attack Vector: