awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
htr-tech avatar

htr-tech/zphisher

0
View on GitHub↗
15,416 stars·5,809 forks·HTML·gpl-3.0·16 views

Zphisher

Zphisher is a security testing framework designed for conducting authorized social engineering assessments and penetration testing. It functions as a credential harvesting simulator that enables security professionals to evaluate organizational defenses and user awareness by deploying deceptive login interfaces.

The platform automates the creation of realistic web pages through dynamic template rendering and provides tools to mask destination addresses. It integrates reverse proxy tunneling to expose local testing services to the public internet, allowing for remote access during security audits without requiring modifications to network firewall configurations.

The tool supports the simulation of credential harvesting attacks to measure vulnerability within authentication workflows. It is packaged to ensure consistent execution across different host environments, facilitating the deployment of controlled testing infrastructure for security awareness training.

Features

  • Attack Simulations - Tests organizational defenses against social engineering through automated link generation and traffic redirection.
  • Penetration Testing Platforms - Evaluates user awareness by creating realistic login interfaces and tunneling local services to the internet.
  • Phishing Attack Tools - Provides a platform for conducting authorized social engineering assessments via deceptive login pages and URL masking.
  • Phishing Page Generators - Creates realistic web interfaces designed to capture user credentials for authorized security assessments.
  • Penetration Testing Frameworks - Automates the deployment of deceptive web interfaces and link redirection tools for security control evaluation.
  • Security Testing and Auditing - Conducts controlled social engineering exercises to identify weaknesses in authentication workflows and user awareness.
  • Social Engineering - Automated phishing tool with multiple templates.
  • Local Tunneling Services - Routes traffic from the public internet to local development environments using secure tunneling services.
  • Remote Access Proxies - Routes traffic from public internet endpoints to local services via secure reverse proxy tunnels.
  • Service Exposure - Exposes local web services to the public internet through secure tunnels for remote testing.
  • Request Interception Middleware - Intercepts and logs incoming HTTP form submissions to record user input within a controlled testing environment.

Star history

Star history chart for htr-tech/zphisherStar history chart for htr-tech/zphisher

How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Open-source alternatives to Zphisher

Similar open-source projects, ranked by how many features they share with Zphisher.
  • jaykali/maskphishjaykali avatar

    jaykali/maskphish

    3,020View on GitHub↗

    Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network vulnerability scanning, open-source intelligence, penetration testing, and social engineering. It functions as a multi-purpose framework for automating reconnaissance and executing security audits across diverse network environments. The project features a specialized phishing and social engineering toolkit used for cloning websites, masking URLs, and deploying deceptive pages to capture user credentials. It also includes a remote access Trojan builder for generating platform-specific exe

    Shellhackhackinghacking-tool
    View on GitHub↗3,020
  • wifiphisher/wifiphisherwifiphisher avatar

    wifiphisher/wifiphisher

    14,631View on GitHub↗

    Wifiphisher is a modular security framework designed for wireless penetration testing and social engineering auditing. It functions as a platform for security professionals to assess the resilience of Wi-Fi networks by simulating unauthorized access, performing man-in-the-middle interceptions, and executing credential-harvesting scenarios. The tool distinguishes itself through its ability to combine rogue access point deployment with dynamic phishing interfaces. By forcing wireless clients to associate with deceptive infrastructure, the framework can capture network metadata and inject it int

    Pythonaccess-pointattackmalware
    View on GitHub↗14,631
  • 1n3/sn1per1N3 avatar

    1N3/Sn1per

    10,049View on GitHub↗

    Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate reconnaissance, vulnerability scanning, and exploit verification. It functions as a dockerized security toolkit that coordinates multiple tools into a unified automated pipeline to identify security flaws across network and web assets. The platform features an attack surface manager for discovering internet-facing assets through OSINT, DNS enumeration, and certificate transparency. It distinguishes itself with an AI-powered security analyzer that uses large language models to summarize scan

    Shellattack-surfaceattack-surface-managementattacksurface
    View on GitHub↗10,049
  • greydgl/pentestgptGreyDGL avatar

    GreyDGL/PentestGPT

    11,697View on GitHub↗

    PentestGPT is an autonomous security testing framework that leverages large language models to plan, execute, and coordinate end-to-end penetration testing engagements. By functioning as an autonomous agent, the system automates the entire testing lifecycle, from initial reconnaissance and vulnerability analysis to the generation of custom exploits and the execution of post-exploitation tasks. The platform distinguishes itself through a multi-agent orchestration system that coordinates specialized AI agents to collaborate on complex, multi-stage attack chains. It integrates multimodal context

    Pythonlarge-language-modelsllmpenetration-testing
    View on GitHub↗11,697
See all 30 alternatives to Zphisher→

Frequently asked questions

What does htr-tech/zphisher do?

Zphisher is a security testing framework designed for conducting authorized social engineering assessments and penetration testing. It functions as a credential harvesting simulator that enables security professionals to evaluate organizational defenses and user awareness by deploying deceptive login interfaces.

What are the main features of htr-tech/zphisher?

The main features of htr-tech/zphisher are: Attack Simulations, Penetration Testing Platforms, Phishing Attack Tools, Phishing Page Generators, Penetration Testing Frameworks, Security Testing and Auditing, Social Engineering, Local Tunneling Services.

What are some open-source alternatives to htr-tech/zphisher?

Open-source alternatives to htr-tech/zphisher include: jaykali/maskphish — Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network… wifiphisher/wifiphisher — Wifiphisher is a modular security framework designed for wireless penetration testing and social engineering auditing.… 1n3/sn1per — Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate… greydgl/pentestgpt — PentestGPT is an autonomous security testing framework that leverages large language models to plan, execute, and… andresriancho/w3af — w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities… v2-dev/awesome-social-engineering — This project is a curated collection of frameworks, libraries, and toolsets designed for social engineering and public…