Social Engineering & Phishing Simulation
Social engineering and phishing simulation tools let authorized teams launch controlled phishing campaigns and credential harvesting exercises to measure employee awareness and test email security controls.
| Tool | License | Platforms | Pricing | Action |
|---|---|---|---|---|
| Evilginx | BSD-3-Clause | Linux, Windows | Free / Commercial | Profile→ |
| Gophish | MIT | Windows, macOS, Linux | Open Source | Profile→ |
| King Phisher | BSD-3-Clause | Linux, Windows | Open Source | Profile→ |
| Modlishka | Modlishka Public Source License (custom, source-available) | Windows, macOS, Linux, BSD | Free / Commercial | Profile→ |
| The Social-Engineer Toolkit (SET) | BSD-3-Clause | Linux, macOS | Open Source | Profile→ |
Tools in Social Engineering & Phishing Simulation
Evilginx
Free / CommercialReverse-proxy framework that tests MFA and session resilience by proxying legitimate websites, with an open-source core and commercial Pro edition.
Gophish
Open SourceOpen-source phishing simulation framework with a web UI and JSON API for building, sending, and tracking campaigns with detailed analytics.
King Phisher
Open SourceOpen-source phishing campaign toolkit with client-server architecture, supporting multiple concurrent campaigns, plugins, and SPF checks.
Modlishka
Free / CommercialHTTP reverse proxy written in Go that tests two-factor authentication and session handling weaknesses by proxying arbitrary web domains.
The Social-Engineer Toolkit (SET)
Open SourceOpen-source Python framework from TrustedSec for authorized social-engineering assessments with guided attack vectors and Metasploit integration.
Frequently Asked Questions
What is Social Engineering & Phishing Simulation?→
Social engineering and phishing simulation tools let authorized teams launch controlled phishing campaigns and credential harvesting exercises to measure employee awareness and test email security controls.
What topics does the Social Engineering & Phishing Simulation category cover?→
Phishing Campaign Simulation, Adversary-in-the-Middle (AiTM) Testing, Credential Harvesting Simulation, Security Awareness Measurement, Payload Delivery Scenarios
About Social Engineering & Phishing Simulation
Social engineering and phishing simulation tools let authorized teams test employee awareness and email security controls through controlled campaigns. The category includes phishing campaign platforms like Gophish and King Phisher that send simulated phishing emails to employees, track who opens them, and measure credential submission rates. Evilginx and Modlishka are adversary-in-the-middle proxies that bypass two-factor authentication by proxying login pages and capturing session tokens, used to test whether MFA implementations resist phishing attacks. The Social-Engineer Toolkit (SET) provides a framework for crafting social engineering payloads including phishing pages, USB drop attacks, and PowerShell-based delivery. Security awareness teams use these tools to measure how many employees click phishing links, submit credentials, or open attachments, then target training at the identified weak points. Email security teams use phishing simulations to test whether mail filters, DMARC policies, and endpoint protections catch phishing payloads before they reach users. The category overlaps with red team tools, since social engineering is often the initial access vector in red team campaigns. All tools in this category are for authorized use only, typically run by internal security teams or contracted assessors against their own organization.
Covered Topics & Disciplines
Related Security Categories
Reconnaissance frameworks, attack-surface discovery engines, and public-data enrichment platforms.
Intercepting HTTP proxies, security assessment toolkits, and network exploitation frameworks.
Adversary emulation platforms, C2 frameworks, and atomic test libraries for authorized red team operations.