Modlishka is a man-in-the-middle reverse proxy framework designed for automated phishing campaigns. It dynamically generates valid TLS certificates for target domains, aggregates traffic from multiple domains through a single proxy, and injects custom scripts into proxied responses. The framework operates transparently without requiring client-side certificate installation and relays two-factor authentication steps to capture secondary verification tokens. What sets Modlishka apart is its ability to automate the entire credential theft process. It logs all form submissions, headers, and cooki
AdvPhishing is a tool for social engineering simulations and credential harvesting testing. It generates deceptive web interfaces, including cloned service provider pages and pre-made layouts that mimic payment and social media platforms, to capture user login details. The tool manages the end-to-end deployment of phishing campaigns by routing captured credentials to a specified email address via an integrated SMTP mail delivery mechanism. It includes utilities for exposing a local development server to the public internet through secure tunneling and redirects users to legitimate third-party
AllHackingTools is a security tool orchestrator and suite designed to install, update, and manage a wide array of third-party hacking and security utilities from a single command interface. It functions as a centralized hub for network analysis, open source intelligence, penetration testing, and social engineering tools. The project provides specialized frameworks for gathering open source intelligence and searching for user profiles across social platforms. It includes toolkits for network reconnaissance, vulnerability scanning, and the execution of security exploits, as well as a social eng
The Social-Engineer Toolkit is a social engineering framework and penetration testing suite designed to simulate human-centric security attacks. It serves as a phishing simulation tool and credential harvesting utility to evaluate personnel awareness and organizational resilience. The toolkit provides specialized tooling for phishing campaign testing and credential theft simulation. It enables the creation of deceptive emails and landing pages to identify vulnerabilities in how users handle sensitive account information. The system includes capabilities for security awareness training and br
SocialFish ist ein Tool zum Credential-Harvesting und ein Phishing-Framework, das darauf ausgelegt ist, Benutzernamen, Passwörter und Zwei-Faktor-Authentifizierungscodes über täuschende Webseiten abzufangen. Es fungiert als Social-Engineering-Plattform und Informationsbeschaffungstool, das für Sicherheitsforschung und Penetrationstests verwendet wird.
Die Hauptfunktionen von undeadsec/socialfish sind: MITM Phishing Frameworks, Credential Interception, Credential Collection, Page Cloning, Reverse Proxy Tunneling Tools, Traffic Proxying, Phishing Proxies, Credential Harvesting Simulations.
Open-Source-Alternativen zu undeadsec/socialfish sind unter anderem: drk1wi/modlishka — Modlishka is a man-in-the-middle reverse proxy framework designed for automated phishing campaigns. It dynamically… ignitetch/advphishing — AdvPhishing is a tool for social engineering simulations and credential harvesting testing. It generates deceptive web… mishakorzik/allhackingtools — AllHackingTools is a security tool orchestrator and suite designed to install, update, and manage a wide array of… trustedsec/social-engineer-toolkit — The Social-Engineer Toolkit is a social engineering framework and penetration testing suite designed to simulate… kgretzky/evilginx2 — Evilginx2 is a man-in-the-middle phishing framework designed to proxy authentication traffic between a user and a… htr-tech/nexphisher — Nexphisher is a command-line security utility and social engineering simulation framework designed for capturing…