Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
DefinitelyNotPhishing — Contains evilginx phislets, gophish templates, burp suite extensions etc. | Kitploit
Tools/GitHubGitHub/gmh5225/definitelynotphishing
Phishing ToolsWeb SecuritySocial EngineeringLearning & EducationRed TeamingPayload Development
GitHubgmh5225/definitelynotphishing

DefinitelyNotPhishing

Contains evilginx phislets, gophish templates, burp suite extensions etc.

View Repository
211 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

⚠️ Disclaimer
This repository is intended solely for educational and testing purposes.
All tools, configurations, and resources included here (such as phishing templates, red team utilities, or offensive security scripts) are provided strictly for use in authorized environments, such as labs, demos, or penetration testing setups where explicit permission has been granted.

Do not use this code, data, or any derived content to perform unauthorized attacks, phishing campaigns, or to compromise systems without consent.

I do not take any responsibility for misuse, abuse, or any unlawful activity conducted using any material found here.
Using these tools against systems or individuals without permission may be illegal and punishable by law.

Please act responsibly and ethically.
This is a red team learning and demonstration kit – not a toolkit for real-world malicious use.

Evilginx preview


Evilginx Phishlets

  • Amazon

    🔝 Works Also seems to work for other domains like amazon.de if the user logged in via your prepared link

  • Microsoft 365

    🔝 Works when conditional access allows token takeover and no biometrics are used

  • Okta

    🔝 Works if authentication policies allow token takeover and no biometrics are used for login. You can create a free developer tenant under https://developer.okta.com/signup/ to try it out.

  • Github

    🔝 Works without any problems. Great for testing as it contains no subdomains and the "victim" always stays on your proxy even after logging in.

  • Instagram

    🔜 Not working Instagram Desktop version does not forward to login after logo. Mobile version could be more simple since API calls to Facebook seem not to happen here. (WIP)

  • Ionos

    🔚 Not working Detects proxy, redirects to official login

  • Paypal

    🔚 Not working Detects proxy and prompts for security verification


Gophish Templates

  • M365

    “Budget has exceeded its threshold” Azure phishing mail
    Shows a price of ~7500 € above budget and asks user to verify

  • Okta

    “Important reminder: Overdue reviews!” Okta phishing mail
    Contains 1600 users that would lose access

Download Tool