Sign inSign up

cisagov/gophish-tools

By cisagov

•Updated 3 months ago

Image
1

10K+

cisagov/gophish-tools repository overview

⁠gophish-tools

GitHub Build Status License CodeQL Coverage Status Code Style

⁠Docker Image

MicroBadger Layers Docker Image Size

This repository contains a set of scripts that can be used by phishing campaign assessors to simplify the process of managing Gophish campaigns.

⁠Scripts

  • gophish-cleaner - Removes an assessment or elements of an assessment in Gophish.
  • gophish-complete - Completes a campaign in Gophish and/or outputs a Gophish campaign summary.
  • gophish-export - Exports all the data from an assessment within Gophish into a single JSON file. In addition, user report JSONs for each campaign in an assessment will also be generated.
  • gophish-import - Imports an assessment JSON file into Gophish.
  • gophish-test - Sends a duplicate assessment from Gophish to custom targets as a test.
  • pca-wizard - Creates an assessment JSON file via an interactive "wizard".
  • pca-wizard-templates - Generates templates for files needed when creating an assessment JSON with pca-wizard.

⁠Usage

The scripts in this project can be executed either in a local Python environment or in a Docker container.

⁠Install and run via local Python

We strongly encourage the use of virtual Python environments. Please see this section⁠ in our "Contributing" document⁠ for information on how to set up and use a virtual Python environment.

To install the scripts in your local Python environment:

git clone https://github.com/cisagov/gophish-tools.git
cd gophish-tools
pip install --requirement requirements.txt

After the scripts have been installed, they can be run like any other script:

gophish-import
⁠Pull or build Docker image

Pull cisagov/gophish-tools from the Docker repository:

docker pull cisagov/gophish-tools

Or build cisagov/gophish-tools from source:

git clone https://github.com/cisagov/gophish-tools.git
cd gophish-tools
docker build --tag cisagov/gophish-tools .
⁠Run scripts via Docker

The easiest way to use the containerized scripts is to alias them in your local shell:

eval "$(docker run cisagov/gophish-tools)"

That will add aliases to your current shell for all of the scripts⁠ mentioned above, plus an additional one for gophish-tools-bash, which can be used to start up a bash shell inside a gophish-tools container.

⁠Assessment JSON Field Dictionary

The following items are included in the assessment JSON as produced by pca-wizard. An example assessment JSON⁠ can be found in this project.

NameDescriptionTypeDefaultRequired
idAssessment identifier. (e.g. RV0000)stringyes
timezoneTimezone name based on pytz⁠ timezones. (e.g. US/Eastern)stringyes
domainAssessment domain for Gophish public interface. (e.g. domain.tld)stringyes
target_domainApproved target domains where all email recipients must reside. (e.g. [target1.tld, target2.tld])list(string)yes
start_dateAssessment start date in 24-hr ISO format with offset. (e.g. 2020-01-01T14:00:00-04:00)stringyes
end_dateAssessment end date in 24-hr ISO format with offset. (e.g. 2020-01-06T15:30:00-04:00)stringyes
rescheduleIndicates if the assessment json is a rescheduled assessment.booleanyes
start_campaignThe campaign that the assessment should start at.integer1no
groupsConsolidated list of email recipients grouped to receive campaigns, example⁠.list(dict)yes
pagesGophish landing pages, example⁠.list(dict)yes
campaignsAssessment campaigns, example⁠.list(dict)yes
⁠Group Dictionary

Groups are imported from a templated csv file that can be generated with the command pca-wizard-templates --targets.

NameDescriptionTypeDefaultRequired
nameGroup name in the format of {assessment identifier}-G{integer} (e.g. RV0000-G1).stringyes
targetsList of email recipients, example⁠.list(dict)yes
⁠Target Dictionary
NameDescriptionTypeDefaultRequired
first_nameRecipient's first name.stringyes
last_nameRecipient's last name.stringyes
emailRecipient's email address. (e.g. [email protected])stringyes
positionPosition name for use in creating sub-groups of recipients within the organization such as "HR", "IT", etc.stringno
⁠Page Dictionary
NameDescriptionTypeDefaultRequired
namePage name in the format of {assessment identifier}-{integer}-{descriptor} (e.g. RV0000-1-AutoForward).stringyes
capture_credentialsCapture all non-password input with Gophish. Supports forwarding after submit action.booleanyes
capture_passwordsCapture password input by the user, but note that captured input is stored in plain text as of Gophish version 0.9.0.booleanFalseno
htmlContent of the landing page in HTML format.stringyes
⁠Campaign Dictionary
NameDescriptionTypeDefaultRequired
nameCampaign name in the format of {assessment identifier}-C{integer} (e.g. RV0000-C1).stringyes
launch_dateCampaign launch date in 24-hr ISO format with offset. (e.g. 2020-01-01T14:00:00-04:00)stringyes
completed_dateCampaign completion date in 24-hr ISO format with offset. (e.g. 2020-01-01T15:30:00-04:00)stringyes
urlFull URL for the campaign's landing page. (e.g. http://domain.tld/camp/1)stringyes
page_nameLanding page name as defined in the assessment json.stringyes
group_nameGroup name as defined in the assessment json.stringyes
templateEmail template for the campaign, example⁠.dictyes
smtpGophish sending profile, example⁠.dictyes
⁠Email Template Dictionary

Email templates can be imported from a templated json file that can be be generated with the command pca-wizard-templates --emails.

NameDescriptionTypeDefaultRequired
nameTemplate name in the format of {assessment identifier}-T{integer}-{template identifier} (e.g. RV0000-T1-1A2B3D).stringyes
subjectEmail subject as seen by recipients.stringyes
htmlHTML representation of the email.stringyes
textPlain text representation of the email.stringyes
⁠SMTP Dictionary
NameDescriptionTypeDefaultRequired
nameSending profile name in the format of {assessment identifier}-SP-{integer} (e.g. RV0000-SP-1).stringyes
from_addressFrom email address with display name, required format: {display name}<{sending email address}>. (e.g. John Doe<[email protected]>)stringyes
hostEmail server for Gophish to send email through.stringpostfix:587no
interface_typeType of interface Gophish will use with mail server.stringSMTPno
ignore_certIndicate if Gophish should ignore certs with mail server.booleanTrueno

⁠User Report Field Dictionary

User report JSONs are also exported by gophish-export. User reports summarize data from targeted user clicks on phishing emails generated by a campaign.

NameDescriptionType
assessmentAssessment ID that this user report is associated with.string
campaignCampaign ID that this user report is associated with.string
customerCustomer ID that this user report document is associated with. Note that Gophish does not contain this information, so gophish-export will always export it as an empty string.string
first_reportFirst report (click) generated by a targeted user. Format: YYYY-MM-DDThh:mm.ssdatetime
total_num_reportsTotal number of user reports received during a campaign.integer

⁠Campaign Summary Field Dictionary

The following JSON data is exported by gophish-export. Campaign summaries for all assessments in a campaign is reported in the following format.

NameDescriptionType
subjectThe subject line for a Gophish-generated email.string
senderThe from address of a Gophish-generated email.string
start_dateThe start date of a campaign.datetime
end_dateThe end date of a campaign.datetime
redirectThe URL the Gophish-generated email will redirect to.string
clicksThe total number of clicks reported by a campaign.integer
unique_clicksThe total number of clicks generated by unique users.integer
percent_clicksThe percentage of emails sent versus how many were clicks by a targeted user.float

⁠Contributing

We welcome contributions! Please see CONTRIBUTING.md⁠ for details.

⁠License

This project is in the worldwide public domain⁠.

This project is in the public domain within the United States, and copyright and related rights in the work worldwide are waived through the CC0 1.0 Universal public domain dedication⁠.

All contributions to this project will be released under the CC0 dedication. By submitting a pull request, you are agreeing to comply with this waiver of copyright interest.

Tag summary

Content type

Image

Digest

sha256:0b2aa4c13…

Size

48.7 MB

Last updated

3 months ago

docker pull cisagov/gophish-tools