awesome-repositories.com
Blog
MCP
awesome-repositories.com

Découvrez les meilleurs dépôts open-source grâce à notre recherche par IA.

ExplorerRecherches sélectionnéesAlternatives open sourceLogiciels auto-hébergésBlogPlan du site
ProjetÀ proposNotre méthodologiePresseServeur MCP
Mentions légalesConfidentialitéConditions d'utilisation
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
trustedsec avatar

trustedsec/social-engineer-toolkit

0
View on GitHub↗
14,984 stars·3,369 forks·Python·8 vues

Social Engineer Toolkit

The Social-Engineer Toolkit is a social engineering framework and penetration testing suite designed to simulate human-centric security attacks. It serves as a phishing simulation tool and credential harvesting utility to evaluate personnel awareness and organizational resilience.

The toolkit provides specialized tooling for phishing campaign testing and credential theft simulation. It enables the creation of deceptive emails and landing pages to identify vulnerabilities in how users handle sensitive account information.

The system includes capabilities for security awareness training and broader penetration testing, utilizing site cloning, DNS spoofing, and payload generation to execute various attack vectors.

Features

  • Phishing Campaign Orchestrators - Orchestrates phishing campaigns by deploying fake emails and landing pages to track user interactions.
  • Credential Harvesting Simulations - Simulates credential theft by mimicking login portals to test how easily users reveal sensitive account information.
  • Phishing Capturers - Mimics legitimate login pages to capture usernames and passwords during authorized security assessments.
  • Penetration Testing Suites - Offers a specialized suite of tools for security professionals to execute human-centric attack vectors.
  • Phishing Attack Tools - Ships a system for creating and deploying deceptive emails and landing pages to evaluate user susceptibility.
  • Social Engineering Simulations - Simulates common deception techniques to evaluate organizational resilience against social engineering.
  • Security Training - Generates realistic attack scenarios used as educational resources for security awareness training.
  • Security Listener Profiles - Spawns a local web server to capture credentials and session data in real time during security testing.
  • DNS Spoofing Tools - Includes tools for intercepting and modifying DNS query responses to redirect target traffic.
  • Evasive Payload Generators - Generates malicious documents and websites by injecting payloads into predefined templates.
  • Reverse Shells - Establishes socket-based reverse shells for remote command execution on target machines.
  • Website Cloning Tools - Provides automated site cloning to create convincing replicas of web pages for credential harvesting.
  • Exploitation and Payloads - Framework for social engineering and phishing attacks.
  • Offensive Security - Advanced framework for simulating social engineering and phishing attacks.
  • Penetration Testing - Automates social engineering attack simulations.
  • Security Tools - Framework for social engineering and penetration testing
  • Social Engineering Tools - Comprehensive framework for simulating various social engineering attack vectors.

Historique des stars

Graphique de l'historique des stars pour trustedsec/social-engineer-toolkitGraphique de l'historique des stars pour trustedsec/social-engineer-toolkit

Recherche par IA

Explorez plus de dépôts awesome

Décrivez vos besoins en langage naturel — l'IA classe des milliers de projets open source sélectionnés par pertinence.

Start searching with AI

Questions fréquentes

Que fait trustedsec/social-engineer-toolkit ?

The Social-Engineer Toolkit is a social engineering framework and penetration testing suite designed to simulate human-centric security attacks. It serves as a phishing simulation tool and credential harvesting utility to evaluate personnel awareness and organizational resilience.

Quelles sont les fonctionnalités principales de trustedsec/social-engineer-toolkit ?

Les fonctionnalités principales de trustedsec/social-engineer-toolkit sont : Phishing Campaign Orchestrators, Credential Harvesting Simulations, Phishing Capturers, Penetration Testing Suites, Phishing Attack Tools, Social Engineering Simulations, Security Training, Security Listener Profiles.

Quelles sont les alternatives open-source à trustedsec/social-engineer-toolkit ?

Les alternatives open-source à trustedsec/social-engineer-toolkit incluent : jaykali/maskphish — Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network… kgretzky/evilginx2 — Evilginx2 is a man-in-the-middle phishing framework designed to proxy authentication traffic between a user and a… screetsec/thefatrat — TheFatRat is a security exploitation framework designed to automate the creation, obfuscation, and deployment of… beefproject/beef — BeEF is a modular security testing environment designed for browser exploitation and web application auditing. It… gophish/gophish — Gophish is an open-source phishing toolkit and simulation framework designed to test organizational security awareness… ignitetch/advphishing — AdvPhishing is a tool for social engineering simulations and credential harvesting testing. It generates deceptive web…

Alternatives open source à Social Engineer Toolkit

Projets open source similaires, classés selon le nombre de fonctionnalités partagées avec Social Engineer Toolkit.
  • jaykali/maskphishAvatar de jaykali

    jaykali/maskphish

    3,020Voir sur GitHub↗

    Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network vulnerability scanning, open-source intelligence, penetration testing, and social engineering. It functions as a multi-purpose framework for automating reconnaissance and executing security audits across diverse network environments. The project features a specialized phishing and social engineering toolkit used for cloning websites, masking URLs, and deploying deceptive pages to capture user credentials. It also includes a remote access Trojan builder for generating platform-specific exe

    Shellhackhackinghacking-tool
    Voir sur GitHub↗3,020
  • kgretzky/evilginx2Avatar de kgretzky

    kgretzky/evilginx2

    14,627Voir sur GitHub↗

    Evilginx2 is a man-in-the-middle phishing framework designed to proxy authentication traffic between a user and a target web service. By acting as a reverse proxy, the tool intercepts and relays web requests to capture credentials and session tokens in real time, enabling the bypass of multi-factor authentication mechanisms through session cookie hijacking. The platform distinguishes itself by integrating infrastructure orchestration with modular template-driven content injection. It automates the deployment of proxy servers, manages the lifecycle of encryption certificates, and applies conte

    Go
    Voir sur GitHub↗14,627
  • screetsec/thefatratAvatar de screetsec

    screetsec/TheFatRat

    11,038Voir sur GitHub↗

    TheFatRat is a security exploitation framework designed to automate the creation, obfuscation, and deployment of payloads for penetration testing. It functions as a comprehensive toolkit that streamlines the exploitation lifecycle, enabling users to generate malicious executables, manage network listeners, and execute post-exploitation tasks through a unified command-line interface. The framework distinguishes itself by integrating various third-party exploitation utilities into a single, orchestrated workflow. It provides specialized capabilities for embedding code into legitimate binaries a

    Caccessibilityantivirusautorun
    Voir sur GitHub↗11,038
  • beefproject/beefAvatar de beefproject

    beefproject/beef

    10,728Voir sur GitHub↗

    BeEF is a modular security testing environment designed for browser exploitation and web application auditing. It functions as a platform for security professionals to evaluate client-side defenses by injecting persistent scripts into web browsers, establishing a bidirectional communication channel for remote command execution and data exfiltration. The framework distinguishes itself through its ability to use compromised browser sessions as proxies to conduct internal network reconnaissance, effectively bypassing perimeter security controls. It utilizes an event-driven control interface and

    JavaScript
    Voir sur GitHub↗10,728
Voir les 30 alternatives à Social Engineer Toolkit→