awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectAboutHow we rankPressMCP server
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to fkasler/phishmonger

Open-source alternatives to Phishmonger

30 open-source projects similar to fkasler/phishmonger, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Phishmonger alternative.

  • v2-dev/awesome-social-engineeringv2-dev avatar

    v2-dev/awesome-social-engineering

    4,029View on GitHub↗

    This project is a curated collection of frameworks, libraries, and toolsets designed for social engineering and public data gathering. It aggregates specialized software and educational materials used to perform human-centric attacks during professional security engagements. The directory provides resources for gathering and visualizing open source intelligence to identify sensitive information leaks. It also includes a collection of methods and software for executing phishing campaigns to harvest credentials and session cookies. The repository further covers educational materials focused on

    View on GitHub↗4,029
  • bitsadmin/fakelogonscreenbitsadmin avatar

    bitsadmin/fakelogonscreen

    1,375View on GitHub↗

    Fake Windows logon screen to steal passwords

    C#cobaltstrikefakelogon
    View on GitHub↗1,375
  • bizken/phishmailerBiZken avatar

    BiZken/PhishMailer

    1,368View on GitHub↗
    Pythonhackingphishingphishing-attacks
    View on GitHub↗1,368
  • boxug/trapeB

    boxug/trape

    0View on GitHub↗
    View on GitHub↗0
  • certsocietegenerale/swordphish-awarenessC

    certsocietegenerale/swordphish-awareness

    0View on GitHub↗
    View on GitHub↗0

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • curtbraz/phishing-apiC

    curtbraz/Phishing-API

    0View on GitHub↗
    View on GitHub↗0
  • dafthack/mailsniperdafthack avatar

    dafthack/MailSniper

    3,246View on GitHub↗

    MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, insider intel, network architecture information, etc.). It can be used as a non-administrative user to search their own email, or by an administrator to search the mailboxes of every user in a domain.

    PowerShell
    View on GitHub↗3,246
  • drk1wi/modlishkadrk1wi avatar

    drk1wi/Modlishka

    5,273View on GitHub↗

    Modlishka is a man-in-the-middle reverse proxy framework designed for automated phishing campaigns. It dynamically generates valid TLS certificates for target domains, aggregates traffic from multiple domains through a single proxy, and injects custom scripts into proxied responses. The framework operates transparently without requiring client-side certificate installation and relays two-factor authentication steps to capture secondary verification tokens. What sets Modlishka apart is its ability to automate the entire credential theft process. It logs all form submissions, headers, and cooki

    Goeducationalmitmpenetration-testing-tools
    View on GitHub↗5,273
  • elceef/dnstwistelceef avatar

    elceef/dnstwist

    5,595View on GitHub↗

    dnstwist is a Python-based tool designed to detect domain name variants and typo-squatting attempts. It generates a comprehensive list of potential domain permutations—such as misspellings, homoglyphs, and character substitutions—that could be used for phishing, brand impersonation, or other malicious activities. The project serves as a security research utility for identifying lookalike domains that might be registered by adversaries to exploit user confusion or trust. The tool systematically probes each generated domain variant to determine its registration status, DNS resolution, and other

    Pythondnsdomainsfuzzing
    View on GitHub↗5,595
  • fireeye/reelphishfireeye avatar

    fireeye/ReelPhish

    524View on GitHub↗

    This tool has been released along with a FireEye blog post. The blog post can be found at the following link: https://www.fireeye.com/blog/threat-research/2018/02/reelphish-real-time-two-factor-phishing-tool.html

    Python
    View on GitHub↗524
  • gemgeorge/sniperphishG

    GemGeorge/SniperPhish

    0View on GitHub↗
    View on GitHub↗0
  • gophish/gophishgophish avatar

    gophish/gophish

    13,938View on GitHub↗

    Gophish is an open-source phishing toolkit and simulation framework designed to test organizational security awareness and evaluate vulnerability to social engineering attacks. It provides a core engine for sending deceptive emails to targets and tracking their interactions to identify gaps in security training. The platform functions as a comprehensive campaign manager for deploying lures and monitoring email delivery and click-through rates. It allows for the design and execution of simulated email threats to track how targets interact with malicious-looking content or provide credentials i

    Go
    View on GitHub↗13,938
  • htr-tech/zphisherhtr-tech avatar

    htr-tech/zphisher

    15,416View on GitHub↗

    Zphisher is a security testing framework designed for conducting authorized social engineering assessments and penetration testing. It functions as a credential harvesting simulator that enables security professionals to evaluate organizational defenses and user awareness by deploying deceptive login interfaces. The platform automates the creation of realistic web pages through dynamic template rendering and provides tools to mask destination addresses. It integrates reverse proxy tunneling to expose local testing services to the public internet, allowing for remote access during security aud

    HTMLhtr-techphisherphishing
    View on GitHub↗15,416
  • kgretzky/evilginxkgretzky avatar

    kgretzky/evilginx

    1,230View on GitHub↗

    PLEASE USE NEW VERSION: https://github.com/kgretzky/evilginx2

    Python
    View on GitHub↗1,230
  • kgretzky/evilginx2kgretzky avatar

    kgretzky/evilginx2

    14,627View on GitHub↗

    Evilginx2 is a man-in-the-middle phishing framework designed to proxy authentication traffic between a user and a target web service. By acting as a reverse proxy, the tool intercepts and relays web requests to capture credentials and session tokens in real time, enabling the bypass of multi-factor authentication mechanisms through session cookie hijacking. The platform distinguishes itself by integrating infrastructure orchestration with modular template-driven content injection. It automates the deployment of proxy servers, manages the lifecycle of encryption certificates, and applies conte

    Go
    View on GitHub↗14,627
  • mdsecactivebreach/o365-attack-toolkitmdsecactivebreach avatar

    mdsecactivebreach/o365-attack-toolkit

    1,124View on GitHub↗

    o365-attack-toolkit allows operators to perform oauth phishing attacks.

    Go
    View on GitHub↗1,124
  • alteredsecurity/365-stealerA

    AlteredSecurity/365-Stealer

    0View on GitHub↗
    View on GitHub↗0
  • mrd0x/bitbmrd0x avatar

    mrd0x/BITB

    2,890View on GitHub↗

    Browser In The Browser (BITB) Templates

    JavaScript
    View on GitHub↗2,890
  • muraenateam/muraenamuraenateam avatar

    muraenateam/muraena

    1,062View on GitHub↗

    Muraena is an almost-transparent reverse proxy aimed at automating phishing and post-phishing activities.

    Go
    View on GitHub↗1,062
  • netevert/dnsmorphN

    netevert/dnsmorph

    0View on GitHub↗
    View on GitHub↗0
  • quickbreach/smbetrayQ

    quickbreach/SMBetray

    0View on GitHub↗
    View on GitHub↗0
  • raikia/uhoh365R

    Raikia/UhOh365

    0View on GitHub↗
    View on GitHub↗0
  • rices/phishiousR

    Rices/Phishious

    0View on GitHub↗
    View on GitHub↗0
  • ring0lab/catphishring0lab avatar

    ring0lab/catphish

    632View on GitHub↗

    CATPHISH project - For phishing and corporate espionage. Perfect for RED TEAM.

    Ruby
    View on GitHub↗632
  • ryhanson/phisheryryhanson avatar

    ryhanson/phishery

    1,019View on GitHub↗

    An SSL Enabled Basic Auth Credential Harvester with a Word Document Template URL Injector

    Go
    View on GitHub↗1,019
  • securestate/king-phishersecurestate avatar

    securestate/king-phisher

    2,551View on GitHub↗

    Phishing Campaign Toolkit

    Python
    View on GitHub↗2,551
  • secureworks/phishinsuitssecureworks avatar

    secureworks/PhishInSuits

    122View on GitHub↗

    The OAuth Device Authorization flow is documented via: Device Authorization Flow via Auth0 v2 OAuth2 Device Code via Microsoft

    Python
    View on GitHub↗122
  • steveltn/https-portalSteveLTN avatar

    SteveLTN/https-portal

    4,694View on GitHub↗

    This project is a Docker-based Nginx reverse proxy manager designed to automate the deployment of HTTPS for web applications. It functions as a gateway that acquires and renews security certificates via Let's Encrypt and proxies incoming traffic to backend services. The system distinguishes itself by automatically discovering web services running in Docker containers to eliminate manual domain configuration. It manages security certificates through an automated process and can expose these certificates to other applications via shared volumes. The tool covers traffic management through load

    Ruby
    View on GitHub↗4,694
  • threatexpress/domainhunterthreatexpress avatar

    threatexpress/domainhunter

    1,664View on GitHub↗

    Authors Joe Vest (@joevest) & Andrew Chiles (@andrewchiles)

    Python
    View on GitHub↗1,664
  • undeadsec/evilurlUndeadSec avatar

    UndeadSec/EvilURL

    1,265View on GitHub↗

    Generate unicode domains for IDN Homograph Attack and detect them.

    Pythonattackidnidn-homograph-attack
    View on GitHub↗1,265