> For the complete documentation index, see [llms.txt](https://dmcxblue.gitbook.io/red-team-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://dmcxblue.gitbook.io/red-team-notes/initial-acces/spear-phishing-links/set-social-engineering-toolkit.md).

# SET(Social-Engineering Toolkit)

A social engineering framework frequently used for the gather of credentials or user execution access. I am using this Framework to automate most of the job to setup a Phishing Page

The Social-Engineering Toolkit is an open-source testing framework designed for social engineering. SET has a number of custom attack vectors that allow you to make believable attacks quickly. SET is a product of Trusted-Sec. This tool is great for Phishing will automate a lot of the process and will provide us a link to send to the user.

The setup of SET is very straight forward we will runs this on our Linux box.

![](https://244509215-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Lx2b2zLkTKHrsGfxMoR%2F-Lx3TA_oY2d2OYHhZrOO%2F-Lx3UWWsrzcMdmE0j8iw%2Fimage.png?alt=media\&token=60439afb-b2d2-4630-812e-f0d99ae13cb7)

We will gather credentials in this demonstration, continue onto the first option.

![](https://244509215-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Lx2b2zLkTKHrsGfxMoR%2F-Lx3TA_oY2d2OYHhZrOO%2F-Lx3UgBq_AVttyLmHFkZ%2Fimage.png?alt=media\&token=89b85928-0ee1-44ef-bf0e-c4e6789d8eff)

We want to choose the Website Attack Vectors, you are very welcomed to explore the other options to learn more on this.

![](https://244509215-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Lx2b2zLkTKHrsGfxMoR%2F-Lx3TA_oY2d2OYHhZrOO%2F-Lx3UuHsIL3mhwugxqXV%2Fimage.png?alt=media\&token=e15d86b5-a1c7-474d-9638-98cdea5c05a9)

We will move forward and select the Credential Harvester Attack Method self-explanatory on what this will do, it will create an attack to harvest credentials by the use of Social-Engineering.

![](https://244509215-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Lx2b2zLkTKHrsGfxMoR%2F-Lx3TA_oY2d2OYHhZrOO%2F-Lx3V95q684Uurl4gCWd%2Fimage.png?alt=media\&token=59722076-4dd5-4f87-ad54-d01fed0b4cb8)

This is optional but I will use the Web Templates option as it is a quick and dirty DEMO. The explanations on what every options does will be on SET

![](https://244509215-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Lx2b2zLkTKHrsGfxMoR%2F-Lx3TA_oY2d2OYHhZrOO%2F-Lx3VRh5ZwCw-eb56_ls%2Fimage.png?alt=media\&token=ba993f77-9e52-4b54-9000-568d59347e28)

In the next field we will add an IP internal or External. \[In external we will need Port Forwarding Enabled]

![](https://244509215-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Lx2b2zLkTKHrsGfxMoR%2F-Lx3TA_oY2d2OYHhZrOO%2F-Lx3VekXNsiCZoO8ePmA%2Fimage.png?alt=media\&token=4a2d6798-8602-4e0e-b591-f0baf36ca09f)

Google as my selected Template

![](https://244509215-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Lx2b2zLkTKHrsGfxMoR%2F-Lx3TA_oY2d2OYHhZrOO%2F-Lx3Vl9i_SC3XJYKW93u%2Fimage.png?alt=media\&token=e11d10b0-5c63-4053-82dd-08cbe910cb94)

Again creativity will help here on how your victim will enter it's credentials

![As you can see the Logo is missing](https://244509215-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Lx2b2zLkTKHrsGfxMoR%2F-Lx3TA_oY2d2OYHhZrOO%2F-Lx3W91WSx7adhRoQUqS%2Fimage.png?alt=media\&token=22c54833-37a6-4f27-a37c-d00431f68dd8)

Once they log in there credentials they will be redirected to the real Google page and on your terminal you will receive the output for the inserted Credentials.

![](https://244509215-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Lx2b2zLkTKHrsGfxMoR%2F-Lx3TA_oY2d2OYHhZrOO%2F-Lx3WYTnA60alFZUlauf%2Fimage.png?alt=media\&token=f0a360c1-809c-4b96-a5aa-8b74a672f3d8)

Many other tools exist out there that will use other websites and different languages no need to use SET but this is a sample on what SET can do, as this is open-source editing is welcome to adapt to newer websites and security measures that are used by them. This can and will be detected by a well aware Analyst.

You can explore the many other options available from SET.
