Gophish - Email Phishing
WHAT IS GOPHISH?
Gophish is a powerful, open-source phishing simulation tool that allows security professionals and organizations to create, manage, and track phishing campaigns. It provides a user-friendly interface for designing phishing emails and landing pages, making it accessible even for those with limited technical expertise. Gophish is primarily used for:
Security Awareness Training: Educating employees about the dangers of phishing and how to recognize suspicious emails.
Penetration Testing: Assessing an organization’s vulnerability to phishing attacks by simulating real-world scenarios.
Data Collection: Gathering metrics on how many users clicked on links or submitted sensitive information.
HOW GOPHISH WORKS
- Set up
- Go to Railway, sign up using
Githuband clickDeploy. - View log to get credential.

- Using that info to log in

- Go to Railway, sign up using
- Configuration
- Users and Groups

- Landing pages: we can import legit website

- Email template: we can import email by this action

- Sending profile:
- We are using Gmail SMTP service so
smtp.gmail.com:587 - Note: We have to use legit
Username(Email) and generatePasswordApp Password.
- We are using Gmail SMTP service so
- Users and Groups
After we have configured the above settings, it’s time to create and launch a campaign.
We can track the results in near real-time from the respective campaign dashboard. 
Happy hacking!
