This project documents a hands-on social engineering laboratory focused on phishing simulation, website cloning, and credential harvesting techniques within a controlled cybersecurity training environment.
The exercise was performed using Gophish, Mailtrap, and the Social-Engineer Toolkit (SET) to understand how phishing campaigns are designed, deployed, monitored, and analyzed from an ethical hacking perspective.
- Deploy and configure Gophish
- Configure SMTP delivery using Mailtrap
- Create phishing email templates
- Build phishing landing pages
- Launch and monitor phishing campaigns
- Clone websites using SET
- Capture and analyze submitted credentials in a controlled environment
- Understand phishing attack workflows and defensive considerations
- Kali Linux
- Gophish
- Mailtrap
- Social-Engineer Toolkit (SET)
- HTML
- SMTP
- Windows Defender Firewall
- Gophish installation and configuration
- HTTPS administration interface setup
- Firewall rule configuration
- SMTP integration with Mailtrap
- Email template creation
- Landing page creation
- Target group management
- Phishing campaign deployment
- Campaign tracking and analytics
- Website Attack Vectors configuration
- Credential Harvester setup
- Site Cloner implementation
- Local web server configuration
- HTML form analysis and troubleshooting
- Credential capture validation
- Result analysis and verification
- Social Engineering
- Phishing Simulation
- Security Awareness
- Credential Harvesting
- Website Cloning
- SMTP Infrastructure
- Email Security
- User Interaction Tracking
- Ethical Hacking
The laboratory successfully demonstrated the complete lifecycle of a phishing campaign, including email delivery, landing page interaction, user activity monitoring, website cloning, and credential harvesting in an authorized testing environment.
Nouman J Nizami