Skip to main content

Social Engineering & Phishing Simulation

Social engineering and phishing simulation tools let authorized teams launch controlled phishing campaigns and credential harvesting exercises to measure employee awareness and test email security controls.

5 Tools Cataloged
ToolLicensePlatformsPricingAction
EvilginxBSD-3-ClauseLinux, WindowsFree / CommercialProfile
GophishMITWindows, macOS, LinuxOpen SourceProfile
King PhisherBSD-3-ClauseLinux, WindowsOpen SourceProfile
ModlishkaModlishka Public Source License (custom, source-available)Windows, macOS, Linux, BSDFree / CommercialProfile
The Social-Engineer Toolkit (SET)BSD-3-ClauseLinux, macOSOpen SourceProfile

Tools in Social Engineering & Phishing Simulation

Evilginx

Free / Commercial

Reverse-proxy framework that tests MFA and session resilience by proxying legitimate websites, with an open-source core and commercial Pro edition.

LicenseBSD-3-Clause
PlatformLinux, Windows

Gophish

Open Source

Open-source phishing simulation framework with a web UI and JSON API for building, sending, and tracking campaigns with detailed analytics.

LicenseMIT
PlatformWindows, macOS, Linux

King Phisher

Open Source

Open-source phishing campaign toolkit with client-server architecture, supporting multiple concurrent campaigns, plugins, and SPF checks.

LicenseBSD-3-Clause
PlatformLinux, Windows

Modlishka

Free / Commercial

HTTP reverse proxy written in Go that tests two-factor authentication and session handling weaknesses by proxying arbitrary web domains.

LicenseModlishka Public Source License (custom, source-available)
PlatformWindows, macOS, Linux, BSD

Open-source Python framework from TrustedSec for authorized social-engineering assessments with guided attack vectors and Metasploit integration.

LicenseBSD-3-Clause
PlatformLinux, macOS

Frequently Asked Questions

What is Social Engineering & Phishing Simulation?

Social engineering and phishing simulation tools let authorized teams launch controlled phishing campaigns and credential harvesting exercises to measure employee awareness and test email security controls.

What topics does the Social Engineering & Phishing Simulation category cover?

Phishing Campaign Simulation, Adversary-in-the-Middle (AiTM) Testing, Credential Harvesting Simulation, Security Awareness Measurement, Payload Delivery Scenarios

About Social Engineering & Phishing Simulation

Social engineering and phishing simulation tools let authorized teams test employee awareness and email security controls through controlled campaigns. The category includes phishing campaign platforms like Gophish and King Phisher that send simulated phishing emails to employees, track who opens them, and measure credential submission rates. Evilginx and Modlishka are adversary-in-the-middle proxies that bypass two-factor authentication by proxying login pages and capturing session tokens, used to test whether MFA implementations resist phishing attacks. The Social-Engineer Toolkit (SET) provides a framework for crafting social engineering payloads including phishing pages, USB drop attacks, and PowerShell-based delivery. Security awareness teams use these tools to measure how many employees click phishing links, submit credentials, or open attachments, then target training at the identified weak points. Email security teams use phishing simulations to test whether mail filters, DMARC policies, and endpoint protections catch phishing payloads before they reach users. The category overlaps with red team tools, since social engineering is often the initial access vector in red team campaigns. All tools in this category are for authorized use only, typically run by internal security teams or contracted assessors against their own organization.

Covered Topics & Disciplines

Phishing Campaign SimulationAdversary-in-the-Middle (AiTM) TestingCredential Harvesting SimulationSecurity Awareness MeasurementPayload Delivery Scenarios