GOPHISH
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
GoPhish is an open-source phishing SIMULATION framework for security awareness programs and authorized social-engineering assessments. It manages campaigns end to end: sending profiles, email templates, landing pages, target groups, and results tracking. Authorized awareness testing only.
SETUP#
./gophish # Start server # Admin UI: https://127.0.0.1:3333 (creds printed on first run) # Phishing server (serves landing pages): http://0.0.0.0:80 # Config in config.json (admin/phish listen addresses, TLS)
CORE OBJECTS (UI OR API)#
# Sending Profile - SMTP relay used to send simulation mail
# Email Template - the phishing email (supports {{.Variables}})
# Landing Page - captured page + optional credential form
# Users & Groups - target recipients (CSV import)
# Campaign - ties the above together + schedules the send
TEMPLATE VARIABLES#
# {{.FirstName}} {{.LastName}} {{.Email}} {{.Position}}
# {{.URL}} - the tracked phishing link
# {{.Tracker}} - open-tracking pixel
# {{.RId}} - per-recipient result id
# Personalisation improves realism for awareness metrics
LANDING PAGES#
# - Import a site by URL, then edit # - "Capture Submitted Data" to record form posts # - "Capture Passwords" (use judiciously; awareness programs often # capture only the click/submit event, not the actual password) # - Redirect to a training/awareness page after submit
CAMPAIGN RESULTS (METRICS)#
# Tracked states: Email Sent -> Email Opened -> Clicked Link -> # Submitted Data -> Reported # Export CSV for reporting; feed click/report rates into the awareness # program's KPIs
API USAGE#
curl -k -H "Authorization: Bearer <API_KEY>" \ https://127.0.0.1:3333/api/campaigns/ curl -k -H "Authorization: Bearer <API_KEY>" \ https://127.0.0.1:3333/api/groups/ # Full REST API for automating campaigns, groups, and result pulls # (Authorization header carries the API key from UI > Settings)
EVILGINX INTEGRATION#
# GoPhish can hand off clicks to an Evilginx lure to demonstrate # session/MFA-bypass impact in a red-team context (see EVILGINX2.txt) # Awareness-only programs usually stop at the click/report metric
EXAMPLES#
# Typical awareness campaign flow (UI)
# 1. Sending Profile -> SMTP relay
# 2. Email Template -> lure with {{.URL}} + {{.Tracker}}
# 3. Landing Page -> cloned portal, redirect to training page
# 4. Users & Groups -> CSV import of the target population
# 5. Campaign -> schedule, launch, watch results
# Pull campaign results via API for reporting
curl -k -H "Authorization: Bearer $KEY" \
https://127.0.0.1:3333/api/campaigns/1/results
NOTES#
- GoPhish is built for SIMULATION/awareness - favour capturing the click + report metric over harvesting real passwords - Always run under signed authorization; brief leadership, define the target population, and provide just-in-time training on click - Key KPI is the REPORT rate (did users report the phish?), not just the click rate - report that to the client - For red-team engagements, chain to EVILGINX2 to show real MFA-session bypass; for pure awareness, do not - Ties to your phishing-detection consultancy angle (OpenClaw) and SOCIAL-ENGINEERING / PhishingAnalysis sheets you already have - LU FS context: awareness testing supports DORA/NIS2 human-risk and security-training requirements