
king-phisher
Simulate realistic phishing campaigns with credential harvesting, email tracking, and landing page cloning for security awareness training and…

Simulate realistic phishing campaigns with credential harvesting, email tracking, and landing page cloning for security awareness training and…

Open-source interactive security awareness training library with 130+ SCORM exercises covering phishing, vishing, BEC, MFA fatigue, and OWASP AI/LLM…

Security awareness training tool for authorized phishing simulations and internal IT audits

A lightweight, self-hosted simulation tool for "ClickFix" (ClearFake) social engineering training. Safely simulates clipboard-injection attacks with…

camjacking templates

Powerful framework for rogue access point attack.

A security vulnerability has been identified in Krayin CRM <=2.1.0 that allows a low-privileged user to escalate privileges by tricking an admin into…

Automated WPA/WPA2 phishing tool that captures handshakes, spawns a rogue access point, and lures users to a captive portal to harvest credentials…

PLEASE USE NEW VERSION: https://github.com/kgretzky/evilginx2

evilginx3 + gophish

Weaponized Browser-in-the-Middle (BitM) for Penetration Testers

Ruby on Rails Phishing Framework

An SSL Enabled Basic Auth Credential Harvester with a Word Document Template URL Injector

Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice.

A python server tool based on flask , this tool can phish some Facebook credentials!

Gophish with Malicious Attachment and HTTP redirect support

Rogue access point toolkit for WiFi penetration testing, deploying evil portal phishing payloads to capture credentials and perform social…

Addressbar spoofing through blob URL (Firefox browser). An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by…