awesome-repositories.com
Blog
awesome-repositories.com

Entdecke die besten Open-Source-Repositories mit KI-gestützter Suche.

EntdeckenKuratierte SuchenOpen-Source-AlternativenSelf-hosted SoftwareBlogSitemap
ProjektÜber unsRanking-MethodikPresseMCP-Server
RechtlichesDatenschutzAGB
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
UndeadSec avatar

UndeadSec/SocialFish

0
View on GitHub↗
4,764 Stars·1,429 Forks·CSS·BSD-3-Clause·5 Aufrufe

SocialFish

SocialFish ist ein Tool zum Credential-Harvesting und ein Phishing-Framework, das darauf ausgelegt ist, Benutzernamen, Passwörter und Zwei-Faktor-Authentifizierungscodes über täuschende Webseiten abzufangen. Es fungiert als Social-Engineering-Plattform und Informationsbeschaffungstool, das für Sicherheitsforschung und Penetrationstests verwendet wird.

Das System nutzt einen Reverse-Proxy, um Netzwerkverkehr zu tunneln und HTTP-Anfragen sowie Sitzungscookies in Echtzeit zu erfassen. Es verfügt über ein Live-Operator-Panel zum Abfangen von Einmalpasswörtern und nutzt browserbasiertes Klonen, um Authentifizierungsseiten zu replizieren.

Die Plattform bietet Funktionen zur Überwachung von Phishing-Kampagnen, einschließlich der Verfolgung von IP-Adressen der Opfer, Geolokalisierung und Geräte-Fingerprints. Sie enthält zudem Tools zur Verwaltung von Klon-Vorlagen und zum Senden von Echtzeit-Webhook-Benachrichtigungen, wenn Anmeldedaten erfasst werden.

Features

  • MITM Phishing Frameworks - Implements a complete phishing framework combining reverse proxying with real-time credential capture and 2FA bypass.
  • Credential Interception - Intercepts usernames, passwords, and session cookies from submitted forms and browser storage.
  • Credential Collection - Deploys deceptive social engineering pages to gather sensitive login information and personal data.
  • Page Cloning - Implements automated browser sessions to scrape and replicate target authentication pages for social engineering lures.
  • Reverse Proxy Tunneling Tools - Uses a reverse proxy to tunnel network traffic, allowing the interception and modification of data between the victim and the target site.
  • Traffic Proxying - Tunnels remote traffic through a reverse proxy to intercept and analyze HTTP requests and responses.
  • Phishing Proxies - Utilizes a transparent reverse proxy to tunnel network traffic and intercept HTTP requests and session cookies.
  • Credential Harvesting Simulations - Provides a framework for mimicking login portals to capture usernames, passwords, and 2FA codes.
  • MITM Credential Harvesters - Employs a reverse proxy to intercept and log credentials from proxied traffic in real-time.
  • Multi-Factor Authentication Bypass Testing - Intercepts one-time passwords and session cookies in real time to overcome two-factor security measures.
  • Session Hijacking - Intercepts and logs HTTP cookies and form inputs to steal active authentication tokens from client browsers.
  • Social Engineering Simulations - Creates deceptive login pages to simulate phishing attacks and test human vulnerabilities in security.
  • MFA Interception - Captures one-time passwords in real-time via a live operator panel to bypass multi-factor authentication.
  • Deceptive Pages - Duplicates modern authentication pages to create deceptive lures designed to trick users into revealing credentials.
  • Simulation Platforms - Offers a comprehensive platform to deploy deceptive lures and track victim activity, including geolocation and device fingerprints.
  • Proxy-Based Phishing Campaign Deployers - Manages pre-configured page layouts and capture settings in a database for rapid deployment of proxy-based phishing campaigns.
  • UI Cloning Templates - Allows storing and reusing specific cloning configurations as templates for subsequent targeted campaigns.
  • Operator Panels - Provides a live operator panel to manually intercept two-factor authentication codes as they are submitted by victims.
  • Traffic Interception - Uses a reverse proxy to monitor and analyze HTTP requests and responses from targeted remote users.
  • Information Gathering Tools - Harvests data from targets through simulated attacks to support security research and penetration testing.
  • User Activity Monitoring - Logs IP addresses, geolocation, and device fingerprints to monitor how users interact with phishing lures.
  • Phishing Session Monitors - Tracks victim metadata, including IP addresses and geolocation, to analyze the success of social engineering lures.
  • Offensive Security Tools - Phishing and information collection framework.
  • Social Engineering - Tool for capturing credentials via social engineering.
  • Social Engineering Tools - Phishing framework for social media credential harvesting.

Star-Verlauf

Star-Verlauf für undeadsec/socialfishStar-Verlauf für undeadsec/socialfish

KI-Suche

Entdecke weitere awesome Repositories

Beschreibe in einfachen Worten, was du brauchst — die KI bewertet tausende kuratierte Open-Source-Projekte nach Relevanz.

Start searching with AI

Open-Source-Alternativen zu SocialFish

Ähnliche Open-Source-Projekte, sortiert nach der Anzahl der gemeinsamen Funktionen mit SocialFish.
  • drk1wi/modlishkaAvatar von drk1wi

    drk1wi/Modlishka

    5,273Auf GitHub ansehen↗

    Modlishka is a man-in-the-middle reverse proxy framework designed for automated phishing campaigns. It dynamically generates valid TLS certificates for target domains, aggregates traffic from multiple domains through a single proxy, and injects custom scripts into proxied responses. The framework operates transparently without requiring client-side certificate installation and relays two-factor authentication steps to capture secondary verification tokens. What sets Modlishka apart is its ability to automate the entire credential theft process. It logs all form submissions, headers, and cooki

    Goeducationalmitmpenetration-testing-tools
    Auf GitHub ansehen↗5,273
  • ignitetch/advphishingAvatar von Ignitetch

    Ignitetch/AdvPhishing

    3,112Auf GitHub ansehen↗

    AdvPhishing is a tool for social engineering simulations and credential harvesting testing. It generates deceptive web interfaces, including cloned service provider pages and pre-made layouts that mimic payment and social media platforms, to capture user login details. The tool manages the end-to-end deployment of phishing campaigns by routing captured credentials to a specified email address via an integrated SMTP mail delivery mechanism. It includes utilities for exposing a local development server to the public internet through secure tunneling and redirects users to legitimate third-party

    Hackadvancephishingamazone-tfofacebook-otp
    Auf GitHub ansehen↗3,112
  • mishakorzik/allhackingtoolsAvatar von mishakorzik

    mishakorzik/AllHackingTools

    5,186Auf GitHub ansehen↗

    AllHackingTools is a security tool orchestrator and suite designed to install, update, and manage a wide array of third-party hacking and security utilities from a single command interface. It functions as a centralized hub for network analysis, open source intelligence, penetration testing, and social engineering tools. The project provides specialized frameworks for gathering open source intelligence and searching for user profiles across social platforms. It includes toolkits for network reconnaissance, vulnerability scanning, and the execution of security exploits, as well as a social eng

    Shellall-in-onebruteforcecibersecurity
    Auf GitHub ansehen↗5,186
  • trustedsec/social-engineer-toolkitAvatar von trustedsec

    trustedsec/social-engineer-toolkit

    14,984Auf GitHub ansehen↗

    The Social-Engineer Toolkit is a social engineering framework and penetration testing suite designed to simulate human-centric security attacks. It serves as a phishing simulation tool and credential harvesting utility to evaluate personnel awareness and organizational resilience. The toolkit provides specialized tooling for phishing campaign testing and credential theft simulation. It enables the creation of deceptive emails and landing pages to identify vulnerabilities in how users handle sensitive account information. The system includes capabilities for security awareness training and br

    Python
    Auf GitHub ansehen↗14,984
Alle 30 Alternativen zu SocialFish anzeigen→

Häufig gestellte Fragen

Was macht undeadsec/socialfish?

SocialFish ist ein Tool zum Credential-Harvesting und ein Phishing-Framework, das darauf ausgelegt ist, Benutzernamen, Passwörter und Zwei-Faktor-Authentifizierungscodes über täuschende Webseiten abzufangen. Es fungiert als Social-Engineering-Plattform und Informationsbeschaffungstool, das für Sicherheitsforschung und Penetrationstests verwendet wird.

Was sind die Hauptfunktionen von undeadsec/socialfish?

Die Hauptfunktionen von undeadsec/socialfish sind: MITM Phishing Frameworks, Credential Interception, Credential Collection, Page Cloning, Reverse Proxy Tunneling Tools, Traffic Proxying, Phishing Proxies, Credential Harvesting Simulations.

Welche Open-Source-Alternativen gibt es zu undeadsec/socialfish?

Open-Source-Alternativen zu undeadsec/socialfish sind unter anderem: drk1wi/modlishka — Modlishka is a man-in-the-middle reverse proxy framework designed for automated phishing campaigns. It dynamically… ignitetch/advphishing — AdvPhishing is a tool for social engineering simulations and credential harvesting testing. It generates deceptive web… mishakorzik/allhackingtools — AllHackingTools is a security tool orchestrator and suite designed to install, update, and manage a wide array of… trustedsec/social-engineer-toolkit — The Social-Engineer Toolkit is a social engineering framework and penetration testing suite designed to simulate… kgretzky/evilginx2 — Evilginx2 is a man-in-the-middle phishing framework designed to proxy authentication traffic between a user and a… htr-tech/nexphisher — Nexphisher is a command-line security utility and social engineering simulation framework designed for capturing…