awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
htr-tech avatar

htr-tech/nexphisherArchived

0
View on GitHub↗
3,829 stars·625 forks·Shell·GPL-3.0·13 viewsgithub.com/htr-tech/zphisher↗

Nexphisher

Nexphisher is a command-line security utility and social engineering simulation framework designed for capturing credentials during authorized security audits. It functions as a tool for credential harvesting and penetration testing to evaluate organizational resilience against phishing attacks.

The system orchestrates the deployment of realistic login pages and integrates network tunneling to expose local web servers to the public internet. This allows for remote security testing and the execution of controlled social engineering simulations.

The framework provides capabilities for template-based page generation, centralized data logging of intercepted form submissions, and the orchestration of concurrent processes to manage web servers and network tunnels. It is used to conduct security awareness training by simulating the tactics used in credential theft.

Features

  • Credential Harvesting Simulations - Simulates credential harvesting attacks to evaluate organizational resilience against phishing.
  • Awareness Training - Runs controlled phishing exercises to educate staff on recognizing social engineering tactics.
  • Social Engineering Frameworks - Provides an integrated toolset for designing and executing social engineering simulations to harvest user data.
  • Social Engineering Simulations - Mimics deception techniques using realistic login pages and network tunneling to test human vulnerabilities.
  • Penetration Testing Frameworks - Provides a framework for conducting authorized security audits by deploying temporary deceptive web interfaces.
  • Credential Capture Logs - Implements centralized logging to intercept and record credentials from simulated form submissions.
  • Command Line Utilities - Provides a terminal-based interface for managing phishing templates, network tunnels, and data logs.
  • Reverse Tunnels - Exposes local security testing servers to the public internet via automated reverse tunnels.
  • Network Tunneling - Provides automated network tunneling to expose local security testing servers to the public internet.
  • Credential Harvesting Pages - Uses templates to generate realistic credential harvesting pages that mimic legitimate login interfaces.
  • Local Development Hosting - Hosts simulated login pages on a local server to capture user input during security audits.

Star history

Star history chart for htr-tech/nexphisherStar history chart for htr-tech/nexphisher

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Projects sharing features with Nexphisher

These projects share indexed features with Nexphisher. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • ignitetch/advphishingIgnitetch avatar

    Ignitetch/AdvPhishing

    3,112View on GitHub↗

    AdvPhishing is a tool for social engineering simulations and credential harvesting testing. It generates deceptive web interfaces, including cloned service provider pages and pre-made layouts that mimic payment and social media platforms, to capture user login details. The tool manages the end-to-end deployment of phishing campaigns by routing captured credentials to a specified email address via an integrated SMTP mail delivery mechanism. It includes utilities for exposing a local development server to the public internet through secure tunneling and redirects users to legitimate third-party

    Hackadvancephishingamazone-tfofacebook-otp
    View on GitHub↗3,112
  • xjp-git/antizhapianXJP-GIT avatar

    XJP-GIT/AntiZhaPian

    3,177View on GitHub↗

    AntiZhaPian is a social engineering framework and fraud simulation application. It generates fake security center dashboards and anti-fraud interfaces designed to deceive users into believing that official security software is installed. The project functions as a simulation tool that mimics the visual appearance and behavior of anti-fraud applications. It uses template-based rendering and state-driven UI simulation to create synthetic dashboards with dynamic dates and fake status indicators. The application includes a user profile management interface for viewing and updating personal accou

    View on GitHub↗3,177
  • undeadsec/socialfishUndeadSec avatar

    UndeadSec/SocialFish

    4,764View on GitHub↗

    SocialFish is a credential harvesting tool and phishing framework designed to intercept usernames, passwords, and two-factor authentication codes through deceptive web pages. It functions as a social engineering platform and information gathering tool used to collect target data and system information for security research and penetration testing. The system utilizes a reverse proxy to tunnel network traffic and capture real-time HTTP requests and session cookies. It features a live operator panel for intercepting one-time passwords and employs browser-based cloning to replicate authenticatio

    CSS
    View on GitHub↗4,764
  • trustedsec/social-engineer-toolkittrustedsec avatar

    trustedsec/social-engineer-toolkit

    14,984View on GitHub↗

    The Social-Engineer Toolkit is a social engineering framework and penetration testing suite designed to simulate human-centric security attacks. It serves as a phishing simulation tool and credential harvesting utility to evaluate personnel awareness and organizational resilience. The toolkit provides specialized tooling for phishing campaign testing and credential theft simulation. It enables the creation of deceptive emails and landing pages to identify vulnerabilities in how users handle sensitive account information. The system includes capabilities for security awareness training and br

    Python
    View on GitHub↗14,984
Compare all 30 related projects→

Frequently asked questions

What does htr-tech/nexphisher do?

Nexphisher is a command-line security utility and social engineering simulation framework designed for capturing credentials during authorized security audits. It functions as a tool for credential harvesting and penetration testing to evaluate organizational resilience against phishing attacks.

What are the main features of htr-tech/nexphisher?

The main features of htr-tech/nexphisher are: Credential Harvesting Simulations, Awareness Training, Social Engineering Frameworks, Social Engineering Simulations, Penetration Testing Frameworks, Credential Capture Logs, Command Line Utilities, Reverse Tunnels.

Which projects share features with htr-tech/nexphisher?

Projects with overlapping indexed features include: ignitetch/advphishing — AdvPhishing is a tool for social engineering simulations and credential harvesting testing. It generates deceptive web… xjp-git/antizhapian — AntiZhaPian is a social engineering framework and fraud simulation application. It generates fake security center… undeadsec/socialfish — SocialFish is a credential harvesting tool and phishing framework designed to intercept usernames, passwords, and… trustedsec/social-engineer-toolkit — The Social-Engineer Toolkit is a social engineering framework and penetration testing suite designed to simulate… specterops/bloodhound — BloodHound is an identity risk management platform and graph-based attack path analyzer used to map identity… jarun/nnn — This project is a keyboard-driven terminal file manager designed for efficient navigation and manipulation of local…