GO KALI FREE

Social Engineering Toolkit (SET)

Social Engineering

Intermediatehigh risk

The Social Engineering Toolkit (SET) is an open-source Python-driven framework designed to facilitate advanced social engineering attacks. It provides a menu-driven interface to generate spear-phishing campaigns, credential harvesting web pages, and infectious media for authorized penetration testing.

Installation

sudo apt install set

Basic Syntax

sudo setoolkit

Quick Facts

Full Name
Social Engineering Toolkit
License
GPL
Language
Python
Interface
Menu-driven CLI
Category
Social Engineering
Author
TrustedSec

Tool Overview

The Social Engineering Toolkit (SET) is an open-source Python-driven framework designed for advanced social engineering attacks. It provides a menu-driven interface for phishing, credential harvesting, and infectious media generation.

SET includes modules for spear-phishing, website attacks, credential harvesting, mass mailing, and infectious media creation. It integrates with Metasploit for payload delivery.

SET is widely used by penetration testers and red teams for social engineering assessments. It provides realistic attack simulations to test employee security awareness.

Common Commands

sudo setoolkitLaunch the Social-Engineer Toolkit with root privileges
setoolkitStart the interactive SET menu
seautomate answers.txtReplay a saved sequence of SET menu answers non-interactively
nano /etc/setoolkit/set.configEdit the global SET configuration file
1Main menu: select Social-Engineering Attacks
2Main menu: select Penetration Testing (Fast-Track)
4Main menu: Update the Social-Engineer Toolkit
5Main menu: Update the SET configuration
1 > 1Open Spear-Phishing Attack Vectors
1 > 2Open Website Attack Vectors
1 > 2 > 1Website: Java Applet Attack Method
1 > 2 > 2Website: Metasploit Browser Exploit Method
1 > 2 > 3Website: Credential Harvester Attack Method
1 > 2 > 3 > 1Credential Harvester using built-in Web Templates
1 > 2 > 3 > 2Credential Harvester using Site Cloner

Step-by-Step Guide

  1. 1Start the application using root privileges
  2. 2Navigate the menu to select your desired attack category
  3. 3Input the requested variables (like server IP and target URL)
  4. 4Execute the campaign module
  5. 5Wait for the framework to intercept and display stolen data
  6. 6Save the extracted credentials for your final report

Use Cases

Phishing Campaigns

Conduct spear-phishing and mass phishing attacks.

Credential Harvesting

Clone websites to capture credentials.

Infectious Media

Create USB payloads for physical attacks.

Website Attacks

Clone sites for credential capture.

Key Features

Related Tools

GoPhish

Social Engineering

Phishing simulation framework.

Frequently Asked Questions

What is SET used for?

SET is used for conducting social engineering attacks including phishing, credential harvesting, and infectious media generation. It provides a menu-driven interface for attack selection.

Is SET legal to use?

SET is legal for authorized penetration testing and security assessments. Always obtain explicit written permission before using it.

How does credential harvesting work?

SET clones a target website and hosts it on a local server. When victims enter credentials, they are captured while being redirected to the legitimate site.

Does SET work with Metasploit?

Yes, SET integrates with Metasploit for payload delivery and post-exploitation activities.

Tags

#social-engineering#phishing#credential-harvesting#framework

Ethical Usage Notice

This tool is designed for authorized security testing, educational purposes, and legitimate network administration only. Unauthorized access to computer systems is illegal.