Gophish – Open-Source Phishing Framework

Your website & network are Hackable

Gophish is a phishing framework that makes the simulation of real-world phishing attacks very straight forwards. The idea behind gophish is simple – make industry-grade phishing training available to everyone.

Gophish - Open-Source Phishing Framework

There are various other similar tools available such as Simple Phishing Toolkit and sptoolkit Rebirth.

I wonder if this is the beginning of an emergence of portable, compiled Golang based security tools.


  • One-click Installation
  • Standalone, portable binary with static assets
  • Point-and-click Phishing
  • Beautiful Web UI
  • Automated Phishing campaigns
  • RESTful API (JSON)
  • Automated Training
  • Open-Source

What’s New

Gopshish is pretty new and just hit the milestone of it’s first public beta release, so there are the main recent features:

  • Added the timeline feature for campaign results
  • Added default tracking to email templates
  • Added additional events (such as when errors occur)
  • Added the ability to access admin server/ phishing server over TLS
  • Multiple UI fixes/tweaks (datatables, etc.)
  • Added the ability to export results as CSV

You can download the User Guide here: Gopshish User Guide [PDF]

And you can download Gophish here:

Windows 64-Bit –
Linux 64-Bit – gophish_linux_64bit.tar.gz
OSX 64-Bit –

(If you’re still on a 32-Bit OS, you can go to the releases page to find a suitable download)

Or read more here.

Posted in: Countermeasures, Phishing

, , , , , , , ,

Recent in Countermeasures:
- Securing MySQL Installation on Ubuntu 16.04 LTS
- Scirius – Suricata Ruleset Management Web Application
- Raptor WAF – C Based Web Application Firewall

Related Posts:

Most Read in Countermeasures:
- AJAX: Is your application secure enough? - 120,328 views
- Password Hasher Firefox Extension - 117,920 views
- NDR or Backscatter Spam – How Non Delivery Reports Become a Nuisance - 57,760 views

Comments are closed.