awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
drk1wi avatar

drk1wi/Modlishka

0
View on GitHub↗
5,273 stars·942 forks·Go·other·23 views

Modlishka

Modlishka is a man-in-the-middle reverse proxy framework designed for automated phishing campaigns. It dynamically generates valid TLS certificates for target domains, aggregates traffic from multiple domains through a single proxy, and injects custom scripts into proxied responses. The framework operates transparently without requiring client-side certificate installation and relays two-factor authentication steps to capture secondary verification tokens.

What sets Modlishka apart is its ability to automate the entire credential theft process. It logs all form submissions, headers, and cookies to capture plaintext credentials and session tokens, and provides a web-based panel for viewing captured sessions and impersonating authenticated users. Pre-configured phishing templates allow rapid deployment of phishing proxies, while pattern-based content injection enables granular control over payload delivery.

The framework also supports arbitrary domain proxying, meaning it can intercept traffic to any website without the target user installing certificates. It handles most common two-factor authentication schemes automatically, and the captured session management panel allows attackers to hijack active sessions for impersonation.

Features

  • MITM Phishing Frameworks - A reverse proxy that intercepts HTTPS traffic to capture credentials, session tokens, and bypass two-factor authentication for targeted phishing attacks.
  • Proxied Payload Injections - Injects custom JavaScript payloads into proxied web pages using pattern-based matching rules.
  • Reverse Proxy Interceptors - Acts as a reverse proxy between user and target site to intercept all transmitted data.
  • Multi-Domain Proxies - Aggregates traffic from multiple domains through a single proxy without client certificate installation.
  • Phishing Proxies - Sets up a transparent reverse proxy that intercepts traffic between a target user and a real website to capture credentials.
  • MITM Credential Harvesters - Intercepts login credentials, session tokens, and URL parameters from proxied traffic via form submission logging.
  • Active 2FA Bypass Proxies - Automatically handles common 2FA schemes during proxied sessions to capture credentials despite extra verification steps.
  • MITM - Operates as a man-in-the-middle reverse proxy that proxies arbitrary domains without requiring client certificate installation.
  • Proxy-Based Phishing Campaign Deployers - Quickly deploys phishing proxies with pre-built configuration templates and pattern-based script injection rules.
  • Transparent 2FA Relayers - Relays two-factor authentication steps transparently through the proxy to capture secondary verification tokens.
  • Automatic HTTPS Proxies - Automatically generates TLS certificates for HTTPS man-in-the-middle interception.
  • Proxy Templates - Provides pre-configured proxy templates for rapid phishing campaign deployment.
  • Dynamic MITM Certificate Generators - Generates valid TLS certificates on the fly for target domains using a configurable internal certificate authority.
  • Session Impersonators - Uses captured session tokens from a web panel to impersonate authenticated users on the target site.
  • Captured Session Managers - Manages captured sessions by viewing harvested credentials and impersonating authenticated users from a web panel.
  • Session Management Panels - Provides a web panel for viewing captured sessions, impersonating authenticated users, and managing harvested credential data.
  • Pattern-Matched Injections - Injects custom scripts into proxied responses based on configurable URL or content pattern matching rules.
  • Phishing - Reverse proxy for advanced phishing campaigns.
  • Social Engineering - Reverse proxy framework for phishing operations.
  • Social Engineering Tools - Reverse proxy for real-time 2FA phishing attacks.

Star history

Star history chart for drk1wi/modlishkaStar history chart for drk1wi/modlishka

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Projects sharing features with Modlishka

These projects share indexed features with Modlishka. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • undeadsec/socialfishUndeadSec avatar

    UndeadSec/SocialFish

    4,764View on GitHub↗

    SocialFish is a credential harvesting tool and phishing framework designed to intercept usernames, passwords, and two-factor authentication codes through deceptive web pages. It functions as a social engineering platform and information gathering tool used to collect target data and system information for security research and penetration testing. The system utilizes a reverse proxy to tunnel network traffic and capture real-time HTTP requests and session cookies. It features a live operator panel for intercepting one-time passwords and employs browser-based cloning to replicate authenticatio

    CSS
    View on GitHub↗4,764
  • kgretzky/evilginx2kgretzky avatar

    kgretzky/evilginx2

    14,627View on GitHub↗

    Evilginx2 is a man-in-the-middle phishing framework designed to proxy authentication traffic between a user and a target web service. By acting as a reverse proxy, the tool intercepts and relays web requests to capture credentials and session tokens in real time, enabling the bypass of multi-factor authentication mechanisms through session cookie hijacking. The platform distinguishes itself by integrating infrastructure orchestration with modular template-driven content injection. It automates the deployment of proxy servers, manages the lifecycle of encryption certificates, and applies conte

    Go
    View on GitHub↗14,627
  • mantvydasb/redteaming-tactics-and-techniquesmantvydasb avatar

    mantvydasb/RedTeaming-Tactics-and-Techniques

    4,620View on GitHub↗

    This project is a red teaming knowledge base and offensive security playbook designed to simulate adversary behavior. It serves as a comprehensive collection of technical guides and tactics for executing red team operations. The repository provides detailed instructions for Active Directory exploitation, including Kerberos abuse and domain privilege escalation. It covers defense evasion through API unhooking and payload obfuscation, as well as Windows internals research involving the manipulation of kernel objects and system memory. The capability surface extends to network penetration testi

    PowerShelloffensive-securityoscppentesting
    View on GitHub↗4,620
  • specterops/bloodhoundSpecterOps avatar

    SpecterOps/BloodHound

    2,789View on GitHub↗

    BloodHound is an identity risk management platform and graph-based attack path analyzer used to map identity relationships and permissions in Active Directory. It functions as a security tool for auditing directory services, uncovering unintended privilege relationships, and visualizing sequences of permissions that can lead to domain compromise. The project differentiates itself as a comprehensive adversary emulation framework that coordinates remote agents and executes post-exploitation commands. It includes a reverse proxy for bypassing multi-factor authentication via real-time session hij

    Go
    View on GitHub↗2,789
Compare all 30 related projects→

Frequently asked questions

What does drk1wi/modlishka do?

Modlishka is a man-in-the-middle reverse proxy framework designed for automated phishing campaigns. It dynamically generates valid TLS certificates for target domains, aggregates traffic from multiple domains through a single proxy, and injects custom scripts into proxied responses. The framework operates transparently without requiring client-side certificate installation and relays two-factor authentication steps to capture secondary verification tokens.

What are the main features of drk1wi/modlishka?

The main features of drk1wi/modlishka are: MITM Phishing Frameworks, Proxied Payload Injections, Reverse Proxy Interceptors, Multi-Domain Proxies, Phishing Proxies, MITM Credential Harvesters, Active 2FA Bypass Proxies, MITM.

Which projects share features with drk1wi/modlishka?

Projects with overlapping indexed features include: undeadsec/socialfish — SocialFish is a credential harvesting tool and phishing framework designed to intercept usernames, passwords, and… kgretzky/evilginx2 — Evilginx2 is a man-in-the-middle phishing framework designed to proxy authentication traffic between a user and a… mantvydasb/redteaming-tactics-and-techniques — This project is a red teaming knowledge base and offensive security playbook designed to simulate adversary behavior.… specterops/bloodhound — BloodHound is an identity risk management platform and graph-based attack path analyzer used to map identity… mdsecactivebreach/o365-attack-toolkit — o365-attack-toolkit allows operators to perform oauth phishing attacks. ring0lab/catphish — CATPHISH project - For phishing and corporate espionage. Perfect for RED TEAM.