Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Evilginx-Phishing-Infra-Setup — Evilginx Phishing Infrastructure Setup Guide - Securing Evilginx and Gophish Infrastructure, Removing IOCs, Phishing TTPs | Kitploit
Tools/GitHubGitHub/an0nud4y/evilginx-phishing-infra-setup
Phishing ToolsIDS/IPS EvasionPhishingCommand and ControlSocial EngineeringLearning & EducationRed TeamingCurated ResourcesEmail Security

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHuban0nud4y/evilginx-phishing-infra-setup

Evilginx-Phishing-Infra-Setup

Evilginx Phishing Infrastructure Setup Guide - Securing Evilginx and Gophish Infrastructure, Removing IOCs, Phishing TTPs

View Repository
598115241 year agoReviewed by Kitploit

Phishing Engagement Infrastructure Setup Guide

Note: These are copy of my personal notes. Please Do not completely rely on them.

Table of Contents

  • Blogs/Talks
  • Red Team/Phishing Infra Automation
  • Domain Purchase and Categorization Techniques
  • Improve Phishing Email Writing Using Tools
  • Test Email Spammyness
  • Emulate Phishing emails / Purple Team Phishing
  • Awesome Enterprise Email Security
  • Delivering Emails in Inbox
  • Phishing Engagements With Evilginx
    • Building Evilginx Phishlets
    • Evilginx Installation Scripts
    • Securing Evilginx Infra tips
    • Evilginx Research Blogs/Talks
    • Defense Tactics Against Evilginx
  • Securing GoPhish Infra
    • GoPhish Research Blogs/Talks
    • Gophish Alternatives
  • AiTM Post Exploitation / Phishing Research Blogs/Talks
  • Other Techniques/Blogs/Researches
  • Phishing Research Talks

Blogs/Talks

  • BHIS | How to Build a Phishing Engagement - Coding TTP's : https://m.youtube.com/watch?si=YTjMa8XBusj_tPdc&v=VglCgoIjztE&feature=youtu.be

Red Team/Phishing Infra Automation

  • https://github.com/dazzyddos/HSC24RedTeamInfra/blob/main/RedTeamInfraAutomation.pdf
  • OFFENSIVEX 2024 - Vincent Yiu - Red Team Tips in 2024 : https://youtu.be/ECIBCbMfeo4?feature=shared
  • https://github.com/bluscreenofjeff/Red-Team-Infrastructure-Wiki
  • Deploy a phishing infrastructure on the fly : https://github.com/VirtualSamuraii/flyphish
  • https://labs.jumpsec.com/putting-the-c2-in-c2loudflare/

Domain Purchase and Categorization Techniques

  • Check for Expired Domain and Possibly purchase the good ones

    • https://expireddomains.net/
  • Domain Categorization

    • Bluecoat/Symantec - https://sitereview.bluecoat.com/#/
    • McAfee - https://www.trustedsource.org
    • Palo Alto Wildfire - https://urlfiltering.paloaltonetworks.com
    • Websense - https://csi.forcepoint.com & https://www.websense.com/content/SiteLookup.aspx (needs registration)
    • FortiGuard - https://www.fortiguard.com/webfilter
    • IBM X-force - https://exchange.xforce.ibmcloud.com
    • Cyren - https://www.cyren.com/security-center/url-category-check-gate
    • Checkpoint - https://www.checkpoint.com/urlcat/main.htm (needs registration)
    • Trend Micro - https://global.sitesafety.trendmicro.com/
    • Sophos - https://secure2.sophos.com/en-us/support/contact-support.aspx (submission only; no checking) (Click Submit a Sample -> Web Address)
    • BrightCloud - http://www.brightcloud.com/tools/url-ip-lookup.php
    • LightSpeed Systems - https://archive.lightspeedsystems.com/
  • Automating Domain Reputation Checking/Submission

    • Domainhunter: https://github.com/threatexpress/domainhunter
    • Chameleon : https://github.com/mdsecactivebreach/Chameleon
  • Blogs

    • https://medium.com/@frsfaisall/mastering-modern-red-teaming-infrastructure-leveraging-old-domains-for-reputation-based-bypasses-1fd8cc1768f7

Improve Phishing Email Writing Using Tools

  • mgeeky : https://github.com/mgeeky/Penetration-Testing-Tools/tree/master/phishing
  • HTML-Linter (avoid common phishing email words) : https://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing/phishing-HTML-linter.py
  • Decode-Spam-Headers : https://github.com/mgeeky/decode-spam-headers

Test Email Spammyness

  • https://www.mail-tester.com/

Emulate Phishing emails / Purple Team Phishing

  • https://delivr.to/

Awesome Enterprise Email Security

  • https://github.com/0xAnalyst/awesome-email-security
  • Gartner Magic Quadrant for Email Security Platforms email-security-providers

Delivering Emails in Inbox

  • Method -1 : Using Email Service Providers

    • Use SendGrid - http://sendgrid.com/
      • useful service but honestly, You need Pro pain plan to be lucky not to be on a spamlist
    • MailGun - https://app.mailgun.com/
      • haven't had any problem
    • Amazon AWS SES
    • Brevo : https://www.brevo.com/free-smtp-server/
    • Outlook
    • Gmail
    • Setup an Azure Tenant to get an onmicrosoft.com domain like attackdomain.onmicrosoft.com which can be used for both email sending and phishing as domain
    • LarkSuite (allows custom domain) : https://www.larksuite.com/
    • Zoho (Use the Zoho "Free for Life" email option) : https://www.zoho.com/mail/custom-domain-email.html
    • Yandex : https://360.yandex.com/business/domain-mail/
  • Method - 2 : Random Techniques

    • Technique 1 : By Andre Rosario - From BreakDev Red Discord

      • If you are having issues with delivering emails due to email filtering, consider using Microsoft 365 and Azure IPP to send encrypted emails to your targets!
        • Emails originate from legit Microsoft SMTP servers so they can't block it.
        • Targets who get the encrypted email are the only ones who can open it, if they forward it to their DFIR, they will have to login as that user to even see your message.
        • Easy orchestration in the Microsoft Admin portal of custom domains, create a ton of fake accounts.
        • M365 allows you to set arbitrary display names. So in a targets outlook the email can look like its from [email protected] but it's really from [email protected] (Technical people can easily figure this out though)
        • Emails come from legit Microsoft IPs and domains, so you don't have to worry about domain categorization or lifespan since it's Microsoft.
    • Technique 2 : Using Azure External Invite functionality - From BreakDev Red Discord

      • Azure External Invite can be used for sending an email with redirect link to phishing url
      • Bulk Emails can also be send, for reference check : https://learn.microsoft.com/en-us/entra/external-id/tutorial-bulk-invite
Download Tool