# htr-tech/nexphisher

**Attribution required: if you use, quote, or summarise this content, you must credit and link back to [awesome-repositories.com](https://awesome-repositories.com/repository/htr-tech-nexphisher).**

_How this analysis was created: the description and tags below were written by an AI model that read this project's README and public documentation pages; stars, license and language come straight from the GitHub API. The model does not read the source code._

3,829 stars · 625 forks · Shell · GPL-3.0 · archived

## Links

- GitHub: https://github.com/htr-tech/nexphisher
- Homepage: https://github.com/htr-tech/zphisher
- awesome-repositories: https://awesome-repositories.com/repository/htr-tech-nexphisher.md

## Topics

`htr-tech` `linux` `phisher` `phishing` `phishing-attacks` `phishing-servers` `shellphish` `terminal` `termux` `tool` `zphisher`

## Description

Nexphisher is a command-line security utility and social engineering simulation framework designed for capturing credentials during authorized security audits. It functions as a tool for credential harvesting and penetration testing to evaluate organizational resilience against phishing attacks.

The system orchestrates the deployment of realistic login pages and integrates network tunneling to expose local web servers to the public internet. This allows for remote security testing and the execution of controlled social engineering simulations.

The framework provides capabilities for template-based page generation, centralized data logging of intercepted form submissions, and the orchestration of concurrent processes to manage web servers and network tunnels. It is used to conduct security awareness training by simulating the tactics used in credential theft.

## Tags

### Security & Cryptography

- [Credential Harvesting Simulations](https://awesome-repositories.com/f/security-cryptography/credential-harvesting-simulations.md) — Simulates credential harvesting attacks to evaluate organizational resilience against phishing.
- [Awareness Training](https://awesome-repositories.com/f/security-cryptography/phishing-detections/awareness-training.md) — Runs controlled phishing exercises to educate staff on recognizing social engineering tactics.
- [Social Engineering Frameworks](https://awesome-repositories.com/f/security-cryptography/social-engineering-frameworks.md) — Provides an integrated toolset for designing and executing social engineering simulations to harvest user data.
- [Social Engineering Simulations](https://awesome-repositories.com/f/security-cryptography/social-engineering-simulations.md) — Mimics deception techniques using realistic login pages and network tunneling to test human vulnerabilities. ([source](https://github.com/htr-tech/nexphisher#readme))
- [Penetration Testing Frameworks](https://awesome-repositories.com/f/security-cryptography/vulnerability-assessment-testing/penetration-testing-frameworks.md) — Provides a framework for conducting authorized security audits by deploying temporary deceptive web interfaces.

### System Administration & Monitoring

- [Credential Capture Logs](https://awesome-repositories.com/f/system-administration-monitoring/centralized-logging-systems/credential-capture-logs.md) — Implements centralized logging to intercept and record credentials from simulated form submissions.

### Development Tools & Productivity

- [Command Line Utilities](https://awesome-repositories.com/f/development-tools-productivity/terminal-shell-cli/terminal-cli-enhancements/shell-terminal-utilities/general-enhancements-tooling/terminal-productivity/command-line-utilities.md) — Provides a terminal-based interface for managing phishing templates, network tunnels, and data logs.

### Networking & Communication

- [Reverse Tunnels](https://awesome-repositories.com/f/networking-communication/local-server-tunnels/reverse-tunnels.md) — Exposes local security testing servers to the public internet via automated reverse tunnels.
- [Network Tunneling](https://awesome-repositories.com/f/networking-communication/network-tunneling.md) — Provides automated network tunneling to expose local security testing servers to the public internet.

### User Interface & Experience

- [Credential Harvesting Pages](https://awesome-repositories.com/f/user-interface-experience/page-layout-templates/deceptive-pages/credential-harvesting-pages.md) — Uses templates to generate realistic credential harvesting pages that mimic legitimate login interfaces.

### Web Development

- [Local Development Hosting](https://awesome-repositories.com/f/web-development/web-application-hosting/local-development-hosting.md) — Hosts simulated login pages on a local server to capture user input during security audits.
