An authorized adversary-in-the-middle (AiTM) + awareness assessment platform.
phishkit is a local desktop app that wraps evilginx (an AiTM proxy) together with a native email campaign engine into one authorized end-to-end phishing workflow: Assessment → Target → Phishlet/Proxy → Lure → Template → Recipients → Campaign → Results → Session. It is deep enough that expert operators keep full control, and guided enough that a non-technical business user can run a safe click-through campaign out of the box.
Alpha (
v0.1.0). This is a primitive, in-progress release — not a beta and not a production product. Expect breaking changes. Build from source. There is no signed installer.
For authorized security assessments only. phishkit drives an AiTM proxy, sends email, and handles captured credentials and live session tokens. Use it only with explicit written authorization from the owner of the targeted systems and people. Read authorized use and the threat model before running anything.
- Run one assessment end to end — take an engagement from target setup and proxy to a captured session without stitching separate tools together, all in the desktop app.
- Send with the native mail engine — a draft → review → test → launch campaign composer bound to a target, named lure, sender, template, and recipient list; scheduling and send windows; delivered/opened/clicked/bounced tracking via your SMTP or ESP; and CSV/JSON/redacted reporting. Sender and content are snapshotted at creation for auditability.
- Capture and attribute real sessions — evilginx captures what an attacker would actually get, attributed deterministically back to the campaign attempt, with a focused Sessions view (timeline, masked credentials, token/cookie summary, export, and gated replay).
- Serve two audiences — a guided wizard and a curated preset scenario library with safe defaults for business users, layered over full Advanced controls for expert operators.
- Run awareness campaigns — a click-only training mode that never captures credentials.
| Surface | Languages |
|---|---|
| Product (desktop, CLI, engine, demos) | TypeScript + Rust |
scripts/ / kit glue |
Python + shell OK |
vendor/evilginx2 |
Go (upstream only) |
| Path | Role |
|---|---|
apps/desktop/ |
Supported Tauri desktop app (React + Rust) |
apps/cli/ |
Headless phishkit / phishkit_ctl |
crates/phishkit-core/ |
Shared Rust engine |
kit/evilginx/ |
Kit-owned phishlets, scripts, inject helpers |
demos/ |
Localhost practice apps (cookie, firebase) |
docs/ |
VitePress docs; generated videos in docs/media/ (gitignored) |
tests/ |
unit/ (Rust) and integration/ (desktop UI + Docker) |
vendor/ |
evilginx2 submodule + community phishlet packs |
scripts/ |
Automation helpers (Python/shell) |
packaging/ |
Homebrew / AUR / Debian stubs |
phishkit is alpha (v0.1.0) — not beta, not production. Build it from
source and run it locally. Use it only against domains and people you are
authorized to assess.
git clone --recurse-submodules https://github.com/openhat-security/phishkit.git
cd phishkit
make build # ensure vendor sources, then build the evilginx binary
make setup # rust check + desktop deps + docs deps
make start # run the supported desktop app (tauri dev)Requires git, Rust stable (~/.cargo/bin on PATH), Node (see .nvmrc), the Go
toolchain (to build evilginx once), and the Tauri prerequisites for your OS. Full
instructions, including platform support, are in the
install guide.
The supported product is the desktop app under apps/desktop/
with the AiTM kit under kit/evilginx/.
make cli
./target/release/phishkit --help
./target/release/phishkit wiz quickstart # guided new assessment (TTY)
./target/release/phishkit list-assessmentsSee the CLI guide.
Requires Node (see .nvmrc), Rust stable, Make, and the Tauri prerequisites for
your OS. make help lists every target.
make setup # rust check + desktop deps + docs deps
make start # run the desktop appQuality checks before a PR (these mirror CI):
make test # cargo fmt --check + cargo test (core + cli)
make lint # cargo clippy --all-targets
make test-integration-docker # desktop UI suite in Linux+Xvfb (optional)See Testing. Do not run the desktop UI suite against your live Application Support database.
Work on the documentation site:
make docs # hot-reloading preview
make docs-build # production build; fails on unresolved internal linksContributions are welcome under GPL-3.0. Please read CONTRIBUTING.md and our Code of Conduct first. Report security issues privately per SECURITY.md — never in a public issue. phishkit is for authorized use; requests to enable unauthorized use are out of scope.
The full site is at openhat-security.github.io/phishkit.
- What phishkit is
- Authorized use
- Install
- Quick start
- Testing
- Walkthrough
- Campaign guide
- Phishlet authoring
- Command line
- Architecture
- Platform support
- Local data and network activity
- Threat model
- Privacy
- Release process
- Changelog
- Security policy
phishkit is licensed under GPL-3.0. It orchestrates and templates around upstream open-source projects (notably evilginx2); you are responsible for understanding and complying with their licenses.
phishkit is an independent project. Use it lawfully and only with written authorization.