King Phisher - Phishing Campaign Toolkit
King Phisher is a tool for testing and promoting user awareness by simulating
real world phishing attacks. It features an easy to use, yet very flexible
architecture allowing full control over both emails and server content.
King Phisher can be used to run campaigns ranging from simple awareness
training to more complicated scenarios in which user aware content is served
for harvesting credentials.
King Phisher is only to be used for legal applications when the explicit
permission of the targeted organization has been obtained.
Why Use King Phisher
Fully Featured And Flexible
King Phisher was created out of a need for an application that would facilitate
running multiple separate campaigns with different goals ranging from education,
credential harvesting and so called "Drive By" attacks. King Phisher has been
used to run campaigns ranging from hundreds of targets to tens of thousands
of targets with ease. It also supports sending messages with embedded images
and determining when emails are opened with a tracking image.
Integrated Web Server
King Phisher uses the packaged web server that comes standard with Python making
configuring a separate instance unnecessary.
Open Source
The Python programming language makes it possible to modify the King Phisher
source code to suite the specific needs of the user. Alternatively end users
not interested in modifying the source code are welcome to
open an issue and request
a feature. Users are able to run campaigns as large as they like, as often as
they like.
No Web Interface
No web interface makes it more difficult for prying eyes to identify that the
King Phisher server is being used for social engineering. Additionally the
lack of a web interface reduces the exposure of the King Phisher operator to
web related vulnerabilities such as XSS.
King Phisher - Phishing Campaign Toolkit
Reviewed by Zion3R
on
5:02 PM
Rating: