Dual-core local control plane for authorized assessments:
- Destinations (AiTM) — build/import proxy configs, start evilginx, mint tracked links, sync captures
- Mail (BYO) — HTML templates, recipient CSV, campaign send via your SMTP or ESP API keys
No hosted mail. Credentials stay on the operator machine.
| Tab | Role |
|---|---|
| Dashboard | Engagement overview: stats, setup checklist, recent campaigns, quick actions |
| Destinations | Target → destination config → AiTM proxy → tracked link → captures |
| Templates | HTML + merge tags ({{first_name}}, {{email}}, {{link}}, …) |
| Recipients | Lists + CSV import |
| Campaigns | Bind AiTM link → rate-limited send |
| Results | Per-recipient send status |
| Delivery | Sender accounts: SMTP / SES SMTP / Resend / SendGrid / Mailgun / Postmark |
The desktop app is evilginx-only; kit discovery only requires the
kit/evilginx/ tree, and service status reports the AiTM proxy.
- Create a destination and start the proxy → copy tracked link
- Save an HTML template that includes
{{link}} - Import recipients (CSV with
emailcolumn) - Configure delivery in Settings (prefer SES SMTP or self-hosted on a dedicated sim domain)
- Create & start a campaign → watch progress / Results
Hover the ? hints on Settings/Campaigns for SPF/DKIM/DMARC and provider guidance. Gmail/O365 SMTP is labeled test-only.
| Provider | Mode | Notes |
|---|---|---|
| SMTP | Raw | Any relay (self-hosted, corporate) |
| Amazon SES | SMTP | Region → email-smtp.{region}.amazonaws.com |
| Resend / SendGrid / Mailgun / Postmark | HTTP API | BYO API key; check ESP AUP for phishing-sim content |
# from kit root
make desktop
# or
cd desktop && npm install && npm run tauri devRequires Rust (~/.cargo/bin on PATH), Node 18+, and once: make build-evilginx.
Set PHISHKIT_ROOT if kit discovery fails (dev defaults to repo root).
Opt-in check that drives the same control-plane paths as the Destinations
UI (phishkit_ctl), then uses Playwright to open the lure and submit login.
Not part of make test-integration-docker.
TEST_EMAIL='you@example.com' TEST_PASSWORD='…' make test-destinations
# optional
TEST_TARGET=demo-cookie.local.phishkit TEST_HEADED=1 TEST_KEEP_PROXY=1 \
TEST_EMAIL=… TEST_PASSWORD=… make test-destinationsArtifacts land in tests/integration/artifacts/ (result.json, screenshots).
Passes when a capture has username+password and/or Firebase tokens. Prefer the
localhost demos (make demo-cookie / make demo-firebase) for first-run
practice — see demos/. The default desktop UI suite is
make test-integration-docker (see Testing).
- App database: owned by the Rust engine under the OS application data path
(
phishkit paths/ Settings). - Community packs:
vendor/community-phishlets/(vendored in-repo; refresh pins withmake community-phishlets/ lockfile inkit/evilginx/community-phishlets.lock.json)