Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Antiphishing: detecting newly registered phishing infrastructure before it becomes a known IOC

0
Medium
Published: 08/09/2026 (08/09/2026, 00:34:13 UTC)
Source: Reddit Cybersecurity

Description

This is an open-source project focused on early detection of phishing infrastructure by monitoring newly registered domains (NRDs) and applying structural and keyword analysis to identify suspicious domains before they become known indicators of compromise (IOCs). The detection pipeline integrates with Suricata rulesets to enable DNS and TLS detection of these suspicious domains, aiming to reduce the time gap between domain registration and network detection. The project is evolving and seeks community feedback for improvement.

Reddit Discussion

r/cybersecurity·posted by u/Limp_Durian_6850
00

I’m working on a new detection layer for the open-source Antiphishing ruleset for Suricata.

The idea is to monitor active Newly Registered Domains (NRDs) and look for early indicators of phishing infrastructure.

The pipeline currently uses:

NRDs → structural analysis with dnstwist → typosquatting / homoglyph detection → high-risk keyword combinations → suspicious-domain classification → automatic inclusion in phishing.lst → Suricata DNS / TLS detection

The important distinction is that these are not simply domains imported from an external phishing feed.

The suspicious domains are identified by our own analysis pipeline. Once a domain meets the classification criteria, it is added to the ruleset and becomes available for DNS and TLS SNI detection.

We also keep the original suspicious domains in nrd_suspicious_domains.txt to provide traceability, auditing and a way to investigate potential false positives.

The goal is to reduce the gap between the registration of a potentially malicious domain and its availability as a network detection indicator.

This is still an evolving detection layer, and I’m particularly interested in feedback from people working with CTI, phishing detection, Suricata and DNS-based detection.

Project: https://github.com/julioliraup/Antiphishing

CyberSecurity #ThreatIntelligence #Suricata #Phishing #CTI #BlueTeam #OpenSource

Links cited in this discussion

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/09/2026, 00:56:15 UTC

Technical Analysis

The Antiphishing project implements a detection layer that monitors newly registered domains to identify potential phishing infrastructure early. It uses a multi-step analysis pipeline including domain structural analysis, typosquatting and homoglyph detection, high-risk keyword identification, and suspicious domain classification. Domains flagged as suspicious are automatically added to a phishing list used by Suricata rules for DNS and TLS detection. This approach does not rely on external phishing feeds but generates its own indicators, providing traceability and auditability through stored suspicious domain lists. The ruleset updates approximately every six hours to track emerging phishing vectors.

Potential Impact

By identifying potentially malicious domains shortly after registration, this project can help defenders detect phishing infrastructure earlier than traditional IOC-based methods. This early detection can reduce the window of exposure to phishing attacks by enabling network-level blocking or alerting on suspicious DNS and TLS traffic. However, as this is a detection enhancement rather than a vulnerability or exploit, it does not represent a direct threat but rather a defensive capability.

Defensive Guidance

This is a defensive tool rather than a vulnerability requiring patching. No remediation or patch is applicable. Organizations interested in enhancing phishing detection can consider integrating this open-source ruleset with Suricata deployments. Users should monitor the project repository for updates and contribute feedback to improve detection accuracy and reduce false positives.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Domain
null
Newsworthiness Assessment
{"score":30,"reasons":["external_link","newsworthy_keywords:ioc","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":["ioc"],"foundNonNewsworthy":[]}
Has External Source
true
Trusted Domain
false

Threat ID: 6a77d024bf8831d53990e9ed

Added to database: 08/09/2026, 00:56:04 UTC

Last enriched: 08/09/2026, 00:56:15 UTC

Last updated: 08/09/2026, 03:40:59 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses