undeadsec/socialfish

Phishing Tool & Information Collector

View on GitHub ↗Jump to charts ↓

Summary Information

Updated 7 minutes ago
Added to GitGenius on September 14th, 2026
Created on January 29th, 2018
Open Issues & Pull Requests: 2 (+0)
GitHub issues: Enabled
Number of forks: 1,437
Total Stargazers: 4,882 (+0)
Total Subscribers: 364 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 59.0 days
Mean response time: 102.8 days
90th percentile: 308.0 days
Tracked items: 34

Most active contributors

Sign in to see contributor activity.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 1
New in 7 days: 0
Closed in 7 days: 0
Avg open age: 83 days
Stale 30+ days: 1
Stale 90+ days: 1

Recent activity

Opened in 7 days: 0
Closed in 7 days: 0
Comments in 7 days: 0
Events in 7 days: 0

Top labels

  • help wanted (1)

Most active issues this week

No issue events were indexed in the last 7 days.

Detailed Description

SocialFish is a phishing toolkit designed for capturing credentials, cookies, and two-factor authentication codes from cloned login pages.

The tool addresses the challenge of testing authentication security by automating the creation of convincing phishing pages that can capture modern web authentication flows. It uses Playwright browser automation to clone JavaScript-heavy login pages, operates a live operator panel for real-time monitoring, and intercepts session cookies and OTP codes. The toolkit includes a template system for reusing clones, webhook notifications to external services like Slack and Discord, and automatic detection of multi-step authentication flows found on platforms like Office365 and Gmail.

This tool is intended for authorized penetration testing and security research within controlled environments. It suits red team exercises and security assessments where testing the human and technical layers of authentication is part of the engagement scope. The project positions itself as a modern alternative to earlier phishing frameworks by emphasizing support for contemporary web technologies including single-page applications and two-factor authentication interception. It works with any login page using HTML forms, JavaScript submission, XHR/fetch requests, or SPA frameworks.

Development activity shows consistent refinement of core capabilities. The project maintains active documentation including feature guides and implementation details. Updates focus on expanding browser automation support and adding infrastructure for real-time operator interaction with captured sessions. The codebase receives ongoing attention to support emerging authentication patterns and integration points with external notification systems.