For a phishing simulation platform, the strongest matches are gophish/gophish (Gophish is a self-hostable phishing simulation framework that lets), ignitetch/advphishing (AdvPhishing is a self-hostable phishing simulation tool that lets) and trustedsec/social-engineer-toolkit (The Social-Engineer Toolkit is a well-known penetration testing suite). securestate/king-phisher and kgretzky/evilginx2 round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.
Open-source tools for conducting simulated phishing attacks to improve organizational security awareness and employee training.
Gophish is an open-source phishing toolkit and simulation framework designed to test organizational security awareness and evaluate vulnerability to social engineering attacks. It provides a core engine for sending deceptive emails to targets and tracking their interactions to identify gaps in security training. The platform functions as a comprehensive campaign manager for deploying lures and monitoring email delivery and click-through rates. It allows for the design and execution of simulated email threats to track how targets interact with malicious-looking content or provide credentials i
Gophish is a self-hostable phishing simulation framework that lets you create, run, and manage email‑based campaigns with tracking and reporting—exactly the kind of tool needed for security awareness training, though it lacks SMS and integrated training content.
AdvPhishing is a tool for social engineering simulations and credential harvesting testing. It generates deceptive web interfaces, including cloned service provider pages and pre-made layouts that mimic payment and social media platforms, to capture user login details. The tool manages the end-to-end deployment of phishing campaigns by routing captured credentials to a specified email address via an integrated SMTP mail delivery mechanism. It includes utilities for exposing a local development server to the public internet through secure tunneling and redirects users to legitimate third-party
AdvPhishing is a self-hostable phishing simulation tool that lets you deploy credential-harvesting campaigns with pre-built cloned pages and automatic data exfiltration, fitting the core purpose—though it lacks integrated training content and multi-channel support.
The Social-Engineer Toolkit is a social engineering framework and penetration testing suite designed to simulate human-centric security attacks. It serves as a phishing simulation tool and credential harvesting utility to evaluate personnel awareness and organizational resilience. The toolkit provides specialized tooling for phishing campaign testing and credential theft simulation. It enables the creation of deceptive emails and landing pages to identify vulnerabilities in how users handle sensitive account information. The system includes capabilities for security awareness training and br
The Social-Engineer Toolkit is a well-known penetration testing suite that includes phishing simulation, campaign management, and customizable templates, making it a solid fit for running security awareness phishing tests, though it may not offer the full reporting and LDAP sync features of a dedicated platform.
Phishing Campaign Toolkit
King-Phisher is a dedicated phishing campaign toolkit built for simulating attacks and security awareness training, directly matching the core purpose of creating and managing phishing simulations even if its full feature set isn’t detailed.
Evilginx2 is a man-in-the-middle phishing framework designed to proxy authentication traffic between a user and a target web service. By acting as a reverse proxy, the tool intercepts and relays web requests to capture credentials and session tokens in real time, enabling the bypass of multi-factor authentication mechanisms through session cookie hijacking. The platform distinguishes itself by integrating infrastructure orchestration with modular template-driven content injection. It automates the deployment of proxy servers, manages the lifecycle of encryption certificates, and applies conte
Evilginx2 is a man-in-the-middle phishing framework for credential and session token capture during offensive red-team operations, not a full campaign-management simulation platform with reporting, user management, or integrated training content.
Zphisher is a security testing framework designed for conducting authorized social engineering assessments and penetration testing. It functions as a credential harvesting simulator that enables security professionals to evaluate organizational defenses and user awareness by deploying deceptive login interfaces. The platform automates the creation of realistic web pages through dynamic template rendering and provides tools to mask destination addresses. It integrates reverse proxy tunneling to expose local testing services to the public internet, allowing for remote access during security aud
Zphisher generates realistic phishing pages and provides reverse tunneling for security testing, but it is a credential-harvesting page generator rather than a full campaign-management platform with reporting, user management, or multi-channel support.
Seeker is a social engineering location tool and browser geolocation capture system. It provides a framework for capturing precise GPS coordinates and device metadata by hosting deceptive webpages that prompt users for location permissions. The project includes an HTML phishing template engine for deploying custom or predefined website clones designed to trick users into granting sensitive permissions. It further utilizes a device fingerprinting tool to collect hardware specifications, operating system details, and screen resolution from visiting clients. The system incorporates network reco
Seeker is a geolocation-focused social engineering tool that lets you create deceptive webpages, not a full phishing simulation platform with campaign management, reporting, user management, and multi-channel support.
Wifiphisher is a modular security framework designed for wireless penetration testing and social engineering auditing. It functions as a platform for security professionals to assess the resilience of Wi-Fi networks by simulating unauthorized access, performing man-in-the-middle interceptions, and executing credential-harvesting scenarios. The tool distinguishes itself through its ability to combine rogue access point deployment with dynamic phishing interfaces. By forcing wireless clients to associate with deceptive infrastructure, the framework can capture network metadata and inject it int
Wifiphisher is a wireless penetration testing tool that uses rogue access points for credential harvesting, not a dedicated phishing simulation platform for running and managing security awareness training campaigns with features like campaign management, user directories, or multi-channel support.