Phishing Assessment
Phishing Penetration Testing Checklist
-
Reconnaissance and Information Gathering:
- Tools:
- OSINT Framework
- Shodan
- WHOIS lookup.
- Commands:
- WHOIS Lookup:
whois target.com
- WHOIS Lookup:
- Tools:
-
Phishing Payload Creation:
- Tools:
- Commands:
- Start GoPhish:
gophish - Launch SET:
setoolkit
- Start GoPhish:
-
Email Spoofing and Crafting:
- Tools: Email spoofing tools, email client.
- Commands:
- Use your preferred email client to craft and send phishing emails.
-
Domain Spoofing:
- Tools: Domain registration services.
- Commands:
- Register domains similar to the target organization's domain.
-
Sending Phishing Emails:
-
Credential Harvesting:
- Tools:
- GoPhish
- Custom phishing pages.
- Commands:
- Create and host phishing landing pages.
- Tools:
-
Reporting and Analysis:
-
Advanced Techniques:
- Tools and Frameworks:
- Evilginx2: Advanced phishing with 2FA bypass.
- King Phisher: Phishing campaign toolkit.
- Phishery: URL-based phishing toolkit.
- Commands:
- Launch Evilginx2:
evilginx2 - Use King Phisher:
king-phisher
- Launch Evilginx2:
- Tools and Frameworks:
-
Password Cracking:
- Tools:
- Hashcat: Password cracking tool.
- Commands:
- Use Hashcat:
hashcat
- Use Hashcat:
- Tools:
-
Post-Exploitation:
- Tools and Frameworks:
- Empire: Post-exploitation framework.
- Metasploit: Penetration testing framework.
- Commands:
- Launch Empire:
empire - Use Metasploit:
msfconsole
- Launch Empire:
- Tools and Frameworks: