SET
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
SET is an open-source penetration testing framework focused on social engineering attacks. It integrates with Metasploit and provides automated attack vectors for phishing, credential harvesting, and payload delivery.
LAUNCHING#
setoolkit # Launch SET (requires root) sudo setoolkit # Launch with root privileges
MAIN MENU OPTIONS#
# 1) Social-Engineering Attacks # 2) Penetration Testing (Fast-Track) # 3) Third Party Modules # 4) Update the Social-Engineer Toolkit # 5) Update SET configuration # 99) Exit
SOCIAL ENGINEERING ATTACKS#
# 1) Spear-Phishing Attack Vectors # 2) Website Attack Vectors # 3) Infectious Media Generator # 4) Create a Payload and Listener # 5) Mass Mailer Attack # 6) Arduino-Based Attack Vector # 7) Wireless Access Point Attack # 8) QRCode Generator Attack # 9) Powershell Attack Vectors # 10) Third Party Modules
SPEAR PHISHING#
# Spear-Phishing Attack submenu: # 1) Perform Mass Email Attack # 2) Create a FileFormat Payload # 3) Create a Social-Engineering Template # Steps: # 1. Select payload type # 2. Choose exploit format (PDF, Office, etc.) # 3. Configure email settings # 4. Set target email(s) # 5. Launch attack
WEBSITE ATTACK VECTORS#
# 1) Java Applet Attack Method # 2) Metasploit Browser Exploit Method # 3) Credential Harvester Attack Method # 4) Tabnabbing Attack Method # 5) Web Jacking Attack Method # 6) Multi-Attack Web Method # 7) HTA Attack Method
CREDENTIAL HARVESTER#
# Website Attack Vectors → Credential Harvester # Options: # 1) Web Templates - Use built-in templates # 2) Site Cloner - Clone a target website # 3) Custom Import - Use your own HTML # Steps for Site Cloner: # 1. Select "Site Cloner" # 2. Enter attacker IP (for listener) # 3. Enter URL to clone # 4. SET clones the site and starts listener # 5. Credentials posted to attacker on submission
INFECTIOUS MEDIA#
# Creates autorun payloads for USB/CD/DVD # 1) File-Format Exploits # 2) Standard Metasploit Executable # Generates files to place on removable media
PAYLOAD & LISTENER#
# Creates standalone payloads with built-in listener # Payload types: # - Windows Reverse TCP Meterpreter # - Windows Reverse TCP Shell # - Windows Reverse TCP VNC DLL # - Linux/Mac payloads
MASS MAILER#
# Options: # 1) E-Mail Attack Single Email Address # 2) E-Mail Attack Mass Mailer # # Configure: # - SMTP server settings # - From address (spoofed) # - Subject and body # - Attachment (optional)
POWERSHELL ATTACKS#
# 1) Powershell Alphanumeric Shellcode Injector # 2) Powershell Reverse Shell # 3) Powershell Bind Shell # 4) Powershell Dump SAMFile # Generates encoded PowerShell commands
QR CODE ATTACK#
# Generates QR code pointing to malicious URL # Steps: # 1. Enter target URL # 2. SET generates QR code image # 3. Distribute QR code to targets
CONFIGURATION#
# Config file: /etc/setoolkit/set.config # Key settings: METASPLOIT_PATH=/opt/metasploit APACHE_SERVER=ON SELF_SIGNED_APPLET=ON WEBATTACK_EMAIL=ON EMAIL_PROVIDER=GMAIL
EXAMPLES#
# Quick credential harvest of a login page: # 1. Launch setoolkit # 2. Select 1 (Social-Engineering Attacks) # 3. Select 2 (Website Attack Vectors) # 4. Select 3 (Credential Harvester) # 5. Select 2 (Site Cloner) # 6. Enter your IP address # 7. Enter target URL to clone # 8. Wait for victims to submit credentials
NOTES#
- Requires root privileges - Integrates with Metasploit Framework - Built-in templates for common sites - Custom templates can be imported - Logs stored in /root/.set/ - Only for authorized penetration testing - Updates via menu option or git pull - Python-based framework