Skip to main content
1 min read Intermediate Social Eng.

Phishing Assessment

Phishing Penetration Testing Checklist

  • Reconnaissance and Information Gathering:

  • Phishing Payload Creation:

  • Email Spoofing and Crafting:

    • Tools: Email spoofing tools, email client.
    • Commands:
      • Use your preferred email client to craft and send phishing emails.
  • Domain Spoofing:

    • Tools: Domain registration services.
    • Commands:
      • Register domains similar to the target organization's domain.
  • Sending Phishing Emails:

    • Tools:
    • Commands:
      • Use GoPhish for campaign management: gophish
  • Credential Harvesting:

    • Tools:
    • Commands:
      • Create and host phishing landing pages.
  • Reporting and Analysis:

    • Tools:
    • Commands:
      • Monitor campaigns with GoPhish: gophish
      • Analyze captured data with Wireshark: wireshark
  • Advanced Techniques:

    • Tools and Frameworks:
    • Commands:
      • Launch Evilginx2: evilginx2
      • Use King Phisher: king-phisher
  • Password Cracking:

    • Tools:
    • Commands:
      • Use Hashcat: hashcat
  • Post-Exploitation:

    • Tools and Frameworks:
      • Empire: Post-exploitation framework.
      • Metasploit: Penetration testing framework.
    • Commands:
      • Launch Empire: empire
      • Use Metasploit: msfconsole