xiecat/goblin
一款适用于红蓝对抗中的仿真钓鱼系统 observed · 2026-08-28
Health v2 · maintenance only
23/100
- Activity 0
- Release rhythm 8
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 1822
- days_rel: n/a
- days_push: 1191
- n_releases_24m: 0
Adoption not part of the score
1538 stars · 199 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
Goblin is a phishing simulation system for red team/blue team security exercises, built in Go. It works as a reverse proxy that transparently captures user information, allows content modification and JS injection via plugins, and can hide the real server through CDN and SOCKS5 proxying.
Use cases
- run phishing awareness exercises for employees
- clone a login page to capture credentials in an authorized pentest
- reverse proxy a target site and inject JavaScript
- hide a phishing server's real IP behind CDN and socks5
- log and dump all HTTP requests during a phishing drill
- modify response content of a proxied website with plugins
When to choose
- you need a self-hosted phishing simulation platform for authorized red-blue exercises
- you want transparent credential capture via reverse proxy without affecting user experience
- you need plugin-based page content manipulation and JS injection
- you want request logging to ES, syslog, or files during drills
When to avoid
- you need an email-based phishing campaign platform - Goblin handles web proxying, not mail delivery
- you want a general-purpose web proxy for normal development use
- you lack authorization to test target systems - this is a dual-use offensive tool
- you need actively maintained software - the last release was May 2023
Facets
application · maturity maintenance
proxy security http-server plugin-system logging security penetration-testing web-development windows self-hosted cli phishing-simulation red-team blue-team reverse-proxy security-awareness-training honeypot linux macos docker
3 sources
- readme: https://github.com/xiecat/goblin · fetched 2026-08-28 · 4522ff5d493d
- homepage: https://goblin.xiecat.fun/ · fetched 2026-08-29 · efeb3dde29e4
- site_page: https://goblin.xiecat.fun/faq · fetched 2026-08-29 · e55864dea214
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| xiecat/goblin | main | 23 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem