Featured resource
2026 Tech Forecast
2026 Tech Forecast

1,500+ tech insiders, business leaders, and Pluralsight Authors share their predictions on what’s shifting fastest and how to stay ahead.

Download the forecast
  • Lab
    • Libraries: If you want this lab, consider one of these libraries.
    • Security
Google Cloud Platform icon
Labs

Execute Phishing Campaign with SET

Globomantics' IT Security team is concerned about ongoing phishing campaigns targeting its employees and wants to assess their awareness of social engineering attacks. In this lab, you will take on the role of a security analyst conducting an internal phishing campaign for Globomantics. Using the Social-Engineer Toolkit (SET), you will clone the organization's internal login portal, configure a Credential Harvester, and simulate credential harvesting through a phishing attack. By the end of the lab, you will have hands-on experience executing a simulated phishing campaign, evaluating its results, and identifying vulnerable user accounts, providing practical insight into how attackers spoof login pages and harvest credentials.

Google Cloud Platform icon
Lab platform
Lab Info
Level
Beginner
Last updated
Jul 22, 2026
Duration
1h 30m

Contact sales

By clicking submit, you agree to our Privacy Policy and Terms of Use, and consent to receive marketing emails from Pluralsight.
Table of Contents
  1. Challenge

    Utilize the site cloner to create a convincing spoofed login page

    In this objective, you will prepare the infrastructure for a simulated phishing campaign by using the Social-Engineer Toolkit (SET) to clone the internal Globomantics login portal and configure a Credential Harvester.

  2. Challenge

    Configure the credential harvester to capture user submissions

    With your phishing infrastructure fully set up, you will test the phishing infrastructure by interacting with the spoofed Globomantics login portal as a simulated victim. By submitting test credentials and observing the site's behavior, you will demonstrate how a credential harvesting attack captures user submissions while maintaining the appearance of a legitimate login experience.

  3. Challenge

    Review the campaign results to identify the most vulnerable user groups

    Now that you have simulated the victim interactions, you will return to the attacker's perspective to evaluate the success of the phishing campaign. By reviewing the credentials captured by the Social-Engineer Toolkit (SET), you will identify compromised user accounts and gain insight into how phishing campaign results can be used to assess organizational risk and guide targeted security awareness training.

About the author

Pluralsight Skills gives leaders confidence they have the skills needed to execute technology strategy. Technology teams can benchmark expertise across roles, speed up release cycles and build reliable, secure products. By leveraging our expert content, skill assessments and one-of-a-kind analytics, keep up with the pace of change, put the right people on the right projects and boost productivity. It's the most effective path to developing tech skills at scale.

Real skill practice before real-world application

Hands-on Labs are real environments created by industry experts to help you learn. These environments help you gain knowledge and experience, practice without compromising your system, test without risk, destroy without fear, and let you learn from your mistakes. Hands-on Labs: practice your skills before delivering in the real world.

Learn by doing

Engage hands-on with the tools and technologies you’re learning. You pick the skill, we provide the credentials and environment.

Follow your guide

All labs have detailed instructions and objectives, guiding you through the learning process and ensuring you understand every step.

Turn time into mastery

On average, you retain 75% more of your learning if you take time to practice. Hands-on labs set you up for success to make those skills stick.

Get started with Pluralsight