Skip to content

Conversation

dan1t0
Copy link

@dan1t0 dan1t0 commented Sep 24, 2025

Summary

This PR adds a comprehensive guide for deploying Evilginx in on-premises environments while using cloud assets only for redirection.

Changes

  • ✅ Added new "Evilginx On-Premises Setup" section to the Phishing Setup chapter
  • ✅ Updated table of contents with the new section
  • ✅ Included hybrid architecture: Cloudflare → Caddy → Evilginx (on-prem via Tailnet)
  • ✅ Provided practical configuration examples for Cloudflare firewall rules
  • ✅ Added sample Caddy configuration with internal TLS
  • ✅ Covered OPSEC considerations for keeping sensitive data on client infrastructure

Benefits

  • Addresses legal and compliance concerns by keeping captured data on client-owned infrastructure
  • Provides resilient architecture combining cloud fronting with private backend operations
  • Includes practical, tested configurations ready for implementation
  • Follows security best practices for red team infrastructure

Testing

The configurations have been tested in real red team engagements and provide a robust foundation for on-premises Evilginx deployments.

More Info

https://dan1t0.com/2025/09/24/Working-with-Evilginx-on-Premises/

- Add comprehensive guide for running Evilginx on client-owned infrastructure
- Include Cloudflare → Caddy → Evilginx architecture with private networking
- Provide practical configurations for Cloudflare firewall rules and Caddy setup
- Cover OPSEC considerations for hybrid cloud/on-premises deployments
- Update table of contents with new phishing setup option
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant