The PhishU Framework is the closest thing to a phishing kit while still being built for authorized, legal use.
It is not just another awareness platform. It gives operators a web interface to launch realistic phishing workflows, including MiTM/AiTM transparent proxy campaigns, without the usual pain of standing up and managing everything manually.
That is where it differs from something like Evilginx. Instead of a manual, config-heavy setup, the workflow is wrapped in a web UI with campaign management, landing pages, delivery, results, reporting, training, and session hijacking demonstration all in one place.
For red teams, pentest firms, and MSSPs, that is a strong model:
realistic phishing tradecraft
easier AiTM/MiTM transparent proxy setup
session hijacking demonstration, not just credential capture
evidence, reporting, and training built in
It is also stronger than platforms like KnowBe4 if the goal is realism, not just click rates and canned training.
In terms of ease of use, it is closer to what black hats would want from a phishing kit, except built for legitimate security testing and awareness work.