muraenateam/muraena
Muraena is an almost-transparent reverse proxy aimed at automating phishing and post-phishing activities. observed · 2026-08-28
Health v2 · maintenance only
66/100
- Activity 95
- Release rhythm 8
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 2673
- days_rel: 659
- days_push: 30
- n_releases_24m: 1
Adoption not part of the score
1079 stars · 191 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
Muraena is an almost-transparent reverse proxy written in Go that automates phishing and post-phishing activities by dynamically proxying and transforming traffic between victims and legitimate websites. It is intended for security professionals running authorized phishing simulations and penetration tests.
Use cases
- set up a reverse proxy phishing site for an authorized penetration test
- run phishing simulations that mirror a legitimate website in real time
- capture credentials during a red-team engagement
- map phishing domains and subdomains to target origins automatically
- transform HTTP traffic between victim and legitimate site
- redirect unwanted or bot traffic away from a phishing campaign
When to choose
- you need a dynamic phishing proxy instead of maintaining static phishing pages
- you are conducting authorized phishing simulations or security awareness testing
- you need transparent subdomain mapping and traffic transformation for a phishing exercise
When to avoid
- you want to phish real users without authorization - this is illegal
- you need a general-purpose production reverse proxy like nginx or traefik
- you need static phishing page hosting rather than dynamic proxying
Facets
cli-tool · maturity active
proxy security http-server caching logging security penetration-testing networking web-development windows go cli phishing reverse-proxy phishing-simulation credential-capture red-team social-engineering security-testing linux macos docker
9 sources
- readme: https://github.com/muraenateam/muraena · fetched 2026-08-28 · 3a1f58aabb03
- homepage: https://muraena.phishing.click/ · fetched 2026-08-29 · b732ec2d494e
- site_page: https://muraena.phishing.click/docs/origins · fetched 2026-08-29 · cdda079e1eb5
- site_page: https://muraena.phishing.click/docs/transform · fetched 2026-08-29 · c7ac63d89144
- site_page: https://muraena.phishing.click/docs/redirect · fetched 2026-08-29 · 4f8acd0f638d
- site_page: https://muraena.phishing.click/docs/tls · fetched 2026-08-29 · dea308e4307e
- site_page: https://muraena.phishing.click/docs/log · fetched 2026-08-29 · 026f042a0e63
- site_page: https://muraena.phishing.click/docs/redis · fetched 2026-08-29 · 99ca58d213e4
- site_page: https://muraena.phishing.click/about · fetched 2026-08-29 · de39e1e15bbc
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| muraenateam/muraena | main | 66 |
For agents
markdown · JSON · MCP: product_card(name="muraenateam/muraena")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem