GoPhish

GoPhish is an open-source phishing toolkit that allows users to quickly and easily set up and execute phishing engagements. The GitHub page above provides installation instructions, and I'll briefly cover setting up a phishing campaign.

Setup

Users & Groups

Users & Groups is where you create the group of email addresses you want to send phishing emails to. Users can be added individually or bulk-imported from a CSV file.

The template for the CSV file can be found after clicking New Group.

Launching a Campaign

The Campaign tab is where you combine everything you created from above and launch the phishing campaign. The New Campaign menu is pretty straightforward, so the only thing I'll mention is the URL field. The URL in that field will be where your landing page will be hosted, so ensure your phishing targets can reach the URL.

If you want to use a custom domain to host the landing page, create a DNS A record for your domain that points to your GoPhish server.

Here's an example URL:

Last updated