3.1 Social Engineer's Toolkit (SET)
Join over 3 million cybersecurity professionals advancing their career
Sign up with
Required fields are marked with an *
Already have an account? Sign In »
welcome to Module three, and Cyber is crafting the perfect email course. Now that we've done our recount and composed our phishing e mail,
let's go ahead and you set or the Social Engineers Tool kit to finish the attack.
In this video, we're going to go over the Social Engineers tool kit and learn to navigate through the menus.
So, first off, what is set or again? Social engineering tool kit.
So the social engineers toolkit is everything you need to perform a variety of social engineering attacks. You can perform everything from spearfishing, copying websites, mass mailers and even power shell attacks. There's a couple ways to launch it. You can launch it from the gooey or the graphical user interface
by clicking application,
social engineering tools, social engineers, tool kit or from the command line with the command s E T 00 l k i t.
So, the first time you launch
set, you'll see a disclaimer and I'll go ahead, read it here. I've got a screenshot below, but the social engineer of tool kit is designed purely for good and not evil. If you plan on using this tool for malicious purposes that are not authorized by the company you're performing the assessments for you are violating the terms of service and license of the tool set by hitting. Yes,
you agree the terms of service and the only use a stool for lawful purposes only.
So you type. Yes. Um, it will go away. You'll never see it again.
If you'd like to learn more about the Social Engineers tool kit, you can visit the developers and trusted sec dot com slash social engineer Tool kit Dash set.
And for now, we're gonna go ahead and hop right in.
So it's really easy to navigate this. Just a quick screen shot. Before we hop in. You can see the menu, and then you just press any of the corresponding numbers to what you're trying to do and that will go through the menu.
So let's pop into our lab.
All right, We've got our Callie machine. We will log in with roots and tour,
And so again, there were two ways to launch it. You can go to your applications
social engineering tools right down here and sat tubes.
You'll see. Right? There s e t in click that that will launch it, or I like to do most things from the terminal just a little bit easier. So we'll launch our terminal,
make this a little bit bigger here.
And the command was S e T O l k I t
let it alone.
Let's try that one more time.
There we go. We've got a cursor.
All right. S e T o l k I t
You've got your social engineers Tool kit here does tell you the current version that you're on the version available. And if you are having any issues, they always ask that you update it before you submit those issues to their get.
So as you can see here, we've got our menu. We've got social engineering attacks, penetration, testing, which is their new module. Third party modules. You can update it from here If you're not using Callie, all the updates through Callie are done through the regular app. Get update
and I get upgraded,
but we're gonna go into the social engineering attack. So you type one
and press enter.
And here you can see the menu we saw in the slide. So these are the different types of attacks. You can perform. So we've got spear phishing attacks, website attacks. That's where you can clone your websites. Infectious media generators. You can also create payloads and listeners. The mass mailer, Arduino based attacks,
wireless attacks, Q R code generator
and power shell on an SMS spoofing, which is your text message spoofing and third party modules.
Any time you are in any of the menus you can type in 99 that will return you back to the main menu.
So we'll go back to social engineering and let's say, wanna clone website So you take two
and this will give you the different types of website attacks they've got available. Um,
say actually clicked the wrong one. What we're gonna do 99
back to that main menu, So it is very easy to navigate.
What I would recommend is kind of just going through all the men you've seen, what types of things are available, and you can also check the third party modules as well.
All right, we're gonna end. This video was just a quick quist.
So one what is one way to launch the Social Engineers tool kit?
And we went over two ways to do this
so you can launch it from the gooey by going application. Social engineering tools and the social engineers tool kit is just the S e T i con,
or you can launch it from the command line
with the command s e T 00 l k i t.
So, what is the normal menu option to go back to the main menu?
Yep. And that is just 99. So for many men you that you're in, you just type 99. That'll take you back to the main menu. If it locks up or you just want to start all over, you can also type in exit or control. See? And then we'll get you back to just the regular terminal window and you can start new.
So coming up now that we're familiar with the navigation and use of set, we're going to use it to send our phishing e mail
Course Assessment - Phishing