awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
UndeadSec avatar

UndeadSec/SocialFish

0
View on GitHub↗

SocialFish

SocialFish is a credential harvesting tool and phishing framework designed to intercept usernames, passwords, and two-factor authentication codes through deceptive web pages. It functions as a social engineering platform and information gathering tool used to collect target data and system information for security research and penetration testing.

The system utilizes a reverse proxy to tunnel network traffic and capture real-time HTTP requests and session cookies. It features a live operator panel for intercepting one-time passwords and employs browser-based cloning to replicate authentication pages.

The platform provides capabilities for phishing campaign monitoring, including the tracking of victim IP addresses, geolocation, and device fingerprints. It also includes tools for managing clone templates and sending real-time webhook notifications when credentials are captured.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Features

  • MITM Phishing Frameworks - Implements a complete phishing framework combining reverse proxying with real-time credential capture and 2FA bypass.
  • Credential Interception - Intercepts usernames, passwords, and session cookies from submitted forms and browser storage.
  • Credential Collection - Deploys deceptive social engineering pages to gather sensitive login information and personal data.
  • Page Cloning - Implements automated browser sessions to scrape and replicate target authentication pages for social engineering lures.
  • Reverse Proxy Tunneling Tools - Uses a reverse proxy to tunnel network traffic, allowing the interception and modification of data between the victim and the target site.
  • Traffic Proxying - Tunnels remote traffic through a reverse proxy to intercept and analyze HTTP requests and responses.
  • Phishing Proxies - Utilizes a transparent reverse proxy to tunnel network traffic and intercept HTTP requests and session cookies.
  • Credential Harvesting Simulations - Provides a framework for mimicking login portals to capture usernames, passwords, and 2FA codes.
  • MITM Credential Harvesters - Employs a reverse proxy to intercept and log credentials from proxied traffic in real-time.
  • Multi-Factor Authentication Bypass Testing - Intercepts one-time passwords and session cookies in real time to overcome two-factor security measures.
  • Session Hijacking - Intercepts and logs HTTP cookies and form inputs to steal active authentication tokens from client browsers.
  • Social Engineering Simulations - Creates deceptive login pages to simulate phishing attacks and test human vulnerabilities in security.
  • MFA Interception - Captures one-time passwords in real-time via a live operator panel to bypass multi-factor authentication.
  • Deceptive Pages - Duplicates modern authentication pages to create deceptive lures designed to trick users into revealing credentials.
  • Simulation Platforms - Offers a comprehensive platform to deploy deceptive lures and track victim activity, including geolocation and device fingerprints.
  • Proxy-Based Phishing Campaign Deployers - Manages pre-configured page layouts and capture settings in a database for rapid deployment of proxy-based phishing campaigns.
  • UI Cloning Templates - Allows storing and reusing specific cloning configurations as templates for subsequent targeted campaigns.
  • Operator Panels - Provides a live operator panel to manually intercept two-factor authentication codes as they are submitted by victims.
  • Traffic Interception - Uses a reverse proxy to monitor and analyze HTTP requests and responses from targeted remote users.
  • Information Gathering Tools - Harvests data from targets through simulated attacks to support security research and penetration testing.
  • User Activity Monitoring - Logs IP addresses, geolocation, and device fingerprints to monitor how users interact with phishing lures.
  • Phishing Session Monitors - Tracks victim metadata, including IP addresses and geolocation, to analyze the success of social engineering lures.
  • Offensive Security Tools - Phishing and information collection framework.
  • Social Engineering - Tool for capturing credentials via social engineering.
  • Social Engineering Tools - Phishing framework for social media credential harvesting.
4,764 stars·1,429 forks·CSS·BSD-3-Clause·19 views

Star history

Star history chart for undeadsec/socialfishStar history chart for undeadsec/socialfish

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

Frequently asked questions

What does undeadsec/socialfish do?

SocialFish is a credential harvesting tool and phishing framework designed to intercept usernames, passwords, and two-factor authentication codes through deceptive web pages. It functions as a social engineering platform and information gathering tool used to collect target data and system information for security research and penetration testing.

What are the main features of undeadsec/socialfish?

The main features of undeadsec/socialfish are: MITM Phishing Frameworks, Credential Interception, Credential Collection, Page Cloning, Reverse Proxy Tunneling Tools, Traffic Proxying, Phishing Proxies, Credential Harvesting Simulations.

Which projects share features with undeadsec/socialfish?

Projects with overlapping indexed features include: drk1wi/modlishka — Modlishka is a man-in-the-middle reverse proxy framework designed for automated phishing campaigns. It dynamically… ignitetch/advphishing — AdvPhishing is a tool for social engineering simulations and credential harvesting testing. It generates deceptive web… mishakorzik/allhackingtools — AllHackingTools is a security tool orchestrator and suite designed to install, update, and manage a wide array of… trustedsec/social-engineer-toolkit — The Social-Engineer Toolkit is a social engineering framework and penetration testing suite designed to simulate… kgretzky/evilginx2 — Evilginx2 is a man-in-the-middle phishing framework designed to proxy authentication traffic between a user and a… htr-tech/nexphisher — Nexphisher is a command-line security utility and social engineering simulation framework designed for capturing…

Projects sharing features with SocialFish

These projects share indexed features with SocialFish. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • drk1wi/modlishkadrk1wi avatar

    drk1wi/Modlishka

    5,273View on GitHub↗

    Modlishka is a man-in-the-middle reverse proxy framework designed for automated phishing campaigns. It dynamically generates valid TLS certificates for target domains, aggregates traffic from multiple domains through a single proxy, and injects custom scripts into proxied responses. The framework operates transparently without requiring client-side certificate installation and relays two-factor authentication steps to capture secondary verification tokens. What sets Modlishka apart is its ability to automate the entire credential theft process. It logs all form submissions, headers, and cooki

    Goeducationalmitmpenetration-testing-tools
    View on GitHub↗5,273
  • ignitetch/advphishingIgnitetch avatar

    Ignitetch/AdvPhishing

    3,112View on GitHub↗

    AdvPhishing is a tool for social engineering simulations and credential harvesting testing. It generates deceptive web interfaces, including cloned service provider pages and pre-made layouts that mimic payment and social media platforms, to capture user login details. The tool manages the end-to-end deployment of phishing campaigns by routing captured credentials to a specified email address via an integrated SMTP mail delivery mechanism. It includes utilities for exposing a local development server to the public internet through secure tunneling and redirects users to legitimate third-party

    Hackadvancephishingamazone-tfofacebook-otp
    View on GitHub↗3,112
  • mishakorzik/allhackingtoolsmishakorzik avatar

    mishakorzik/AllHackingTools

    5,186View on GitHub↗

    AllHackingTools is a security tool orchestrator and suite designed to install, update, and manage a wide array of third-party hacking and security utilities from a single command interface. It functions as a centralized hub for network analysis, open source intelligence, penetration testing, and social engineering tools. The project provides specialized frameworks for gathering open source intelligence and searching for user profiles across social platforms. It includes toolkits for network reconnaissance, vulnerability scanning, and the execution of security exploits, as well as a social eng

    Shellall-in-onebruteforcecibersecurity
    View on GitHub↗5,186
  • trustedsec/social-engineer-toolkittrustedsec avatar

    trustedsec/social-engineer-toolkit

    14,984View on GitHub↗

    The Social-Engineer Toolkit is a social engineering framework and penetration testing suite designed to simulate human-centric security attacks. It serves as a phishing simulation tool and credential harvesting utility to evaluate personnel awareness and organizational resilience. The toolkit provides specialized tooling for phishing campaign testing and credential theft simulation. It enables the creation of deceptive emails and landing pages to identify vulnerabilities in how users handle sensitive account information. The system includes capabilities for security awareness training and br

    Python
    View on GitHub↗14,984
Compare all 30 related projects→