Attack Tool(s): Modlishka, evilginx, GoPhish, Social-Engineer-Toolkit (SET)
- Modlishka: https://github.com/drk1wi/Modlishka
- evilginx: https://github.com/kgretzky/evilginx2
- GoPhish: https://getgophish.com
- SET: https://github.com/trustedsec/social-engineer-toolkit
Detection Link(s):
- Security Information and Event Management (SIEM) Log Analysis
- Server Analysis
- Cloud Event Log Analysis
- User and Entity Behavior Analytics (UEBA)
Helpful Blogs (BHIS):
- “How to Phish for Geniuses” – https://www.blackhillsinfosec.com/how-to-phish-for-geniuses – Covers phishing tactics and tools like Modlishka.
- “Gone Phishing: Installing GoPhish and Creating a Campaign – https://www.blackhillsinfosec.com/installing-gophish-and-creating-a-campaign – GoPhish setup and use.
