10.4. Social Engineering

10.4.1. OSINT

10.4.2. Social Tools

  • SlackPirate Slack Enumeration and Extraction Tool - extract sensitive information from a Slack Workspace

  • twint An advanced Twitter scraping & OSINT tool

10.4.4. Hacking database

10.4.5. Fishing

  • spoofcheck

  • gophish

  • SocialFish

  • HFish A Most Convenient Honeypot Platform

  • blackeye complete Phishing Tool, with 32 templates +1 customizable

  • king phisher Phishing Campaign Toolkit

  • espoofer An email spoofing testing tool that aims to bypass SPF/DKIM/DMARC and forge DKIM signatures

  • ditto A tool for IDN homograph attacks and detection

  • SiteCopy sitecopy is a tool that facilitates personal website backup and network data collection

  • goblin is a simulation fishing system suitable for red and blue confrontation

10.4.6. squatting

  • dnstwist Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation

10.4.8. Password guessing

  • OMEN Ordered Markov ENumerator - Password Guesser

  • genpAss

10.4.9. Forgery

10.4.10. Integrated Framework