...The current implementation is written in Go and includes its own HTTP and DNS server components. Site-specific behavior is defined through modular phishing-site configurations known as phishlets. The project is intended for authorized penetration testing, red-team exercises, and defensive research into phishing-resistant authentication. Its capabilities can enable credential theft if misused, so testing should be restricted to systems and users covered by explicit permission.