← All cheat sheets

GOPHISH

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

GoPhish is an open-source phishing SIMULATION framework for security
awareness programs and authorized social-engineering assessments. It
manages campaigns end to end: sending profiles, email templates, landing
pages, target groups, and results tracking. Authorized awareness testing
only.

SETUP#

./gophish                                        # Start server
# Admin UI:  https://127.0.0.1:3333  (creds printed on first run)
# Phishing server (serves landing pages): http://0.0.0.0:80
# Config in config.json (admin/phish listen addresses, TLS)

CORE OBJECTS (UI OR API)#

# Sending Profile  - SMTP relay used to send simulation mail
# Email Template    - the phishing email (supports {{.Variables}})
# Landing Page       - captured page + optional credential form
# Users & Groups     - target recipients (CSV import)
# Campaign           - ties the above together + schedules the send

TEMPLATE VARIABLES#

# {{.FirstName}} {{.LastName}} {{.Email}} {{.Position}}
# {{.URL}}      - the tracked phishing link
# {{.Tracker}}  - open-tracking pixel
# {{.RId}}      - per-recipient result id
# Personalisation improves realism for awareness metrics

LANDING PAGES#

# - Import a site by URL, then edit
# - "Capture Submitted Data" to record form posts
# - "Capture Passwords" (use judiciously; awareness programs often
#    capture only the click/submit event, not the actual password)
# - Redirect to a training/awareness page after submit

CAMPAIGN RESULTS (METRICS)#

# Tracked states: Email Sent -> Email Opened -> Clicked Link ->
#                 Submitted Data -> Reported
# Export CSV for reporting; feed click/report rates into the awareness
# program's KPIs

API USAGE#

curl -k -H "Authorization: Bearer <API_KEY>" \
  https://127.0.0.1:3333/api/campaigns/
curl -k -H "Authorization: Bearer <API_KEY>" \
  https://127.0.0.1:3333/api/groups/
# Full REST API for automating campaigns, groups, and result pulls
# (Authorization header carries the API key from UI > Settings)

EVILGINX INTEGRATION#

# GoPhish can hand off clicks to an Evilginx lure to demonstrate
# session/MFA-bypass impact in a red-team context (see EVILGINX2.txt)
# Awareness-only programs usually stop at the click/report metric

EXAMPLES#

# Typical awareness campaign flow (UI)
# 1. Sending Profile -> SMTP relay
# 2. Email Template  -> lure with {{.URL}} + {{.Tracker}}
# 3. Landing Page    -> cloned portal, redirect to training page
# 4. Users & Groups  -> CSV import of the target population
# 5. Campaign        -> schedule, launch, watch results

# Pull campaign results via API for reporting
curl -k -H "Authorization: Bearer $KEY" \
  https://127.0.0.1:3333/api/campaigns/1/results

NOTES#

- GoPhish is built for SIMULATION/awareness - favour capturing the
  click + report metric over harvesting real passwords
- Always run under signed authorization; brief leadership, define the
  target population, and provide just-in-time training on click
- Key KPI is the REPORT rate (did users report the phish?), not just
  the click rate - report that to the client
- For red-team engagements, chain to EVILGINX2 to show real MFA-session
  bypass; for pure awareness, do not
- Ties to your phishing-detection consultancy angle (OpenClaw) and
  SOCIAL-ENGINEERING / PhishingAnalysis sheets you already have
- LU FS context: awareness testing supports DORA/NIS2 human-risk and
  security-training requirements