Antiphishing: detecting newly registered phishing infrastructure before it becomes a known IOC
This is an open-source project focused on early detection of phishing infrastructure by monitoring newly registered domains (NRDs) and applying structural and keyword analysis to identify suspicious domains before they become known indicators of compromise (IOCs). The detection pipeline integrates with Suricata rulesets to enable DNS and TLS detection of these suspicious domains, aiming to reduce the time gap between domain registration and network detection. The project is evolving and seeks community feedback for improvement.
AI Analysis
Technical Summary
The Antiphishing project implements a detection layer that monitors newly registered domains to identify potential phishing infrastructure early. It uses a multi-step analysis pipeline including domain structural analysis, typosquatting and homoglyph detection, high-risk keyword identification, and suspicious domain classification. Domains flagged as suspicious are automatically added to a phishing list used by Suricata rules for DNS and TLS detection. This approach does not rely on external phishing feeds but generates its own indicators, providing traceability and auditability through stored suspicious domain lists. The ruleset updates approximately every six hours to track emerging phishing vectors.
Potential Impact
By identifying potentially malicious domains shortly after registration, this project can help defenders detect phishing infrastructure earlier than traditional IOC-based methods. This early detection can reduce the window of exposure to phishing attacks by enabling network-level blocking or alerting on suspicious DNS and TLS traffic. However, as this is a detection enhancement rather than a vulnerability or exploit, it does not represent a direct threat but rather a defensive capability.
Mitigation Recommendations
This is a defensive tool rather than a vulnerability requiring patching. No remediation or patch is applicable. Organizations interested in enhancing phishing detection can consider integrating this open-source ruleset with Suricata deployments. Users should monitor the project repository for updates and contribute feedback to improve detection accuracy and reduce false positives.
Antiphishing: detecting newly registered phishing infrastructure before it becomes a known IOC
Description
This is an open-source project focused on early detection of phishing infrastructure by monitoring newly registered domains (NRDs) and applying structural and keyword analysis to identify suspicious domains before they become known indicators of compromise (IOCs). The detection pipeline integrates with Suricata rulesets to enable DNS and TLS detection of these suspicious domains, aiming to reduce the time gap between domain registration and network detection. The project is evolving and seeks community feedback for improvement.
Reddit Discussion
I’m working on a new detection layer for the open-source Antiphishing ruleset for Suricata.
The idea is to monitor active Newly Registered Domains (NRDs) and look for early indicators of phishing infrastructure.
The pipeline currently uses:
NRDs → structural analysis with dnstwist → typosquatting / homoglyph detection → high-risk keyword combinations → suspicious-domain classification → automatic inclusion in phishing.lst → Suricata DNS / TLS detection
The important distinction is that these are not simply domains imported from an external phishing feed.
The suspicious domains are identified by our own analysis pipeline. Once a domain meets the classification criteria, it is added to the ruleset and becomes available for DNS and TLS SNI detection.
We also keep the original suspicious domains in nrd_suspicious_domains.txt to provide traceability, auditing and a way to investigate potential false positives.
The goal is to reduce the gap between the registration of a potentially malicious domain and its availability as a network detection indicator.
This is still an evolving detection layer, and I’m particularly interested in feedback from people working with CTI, phishing detection, Suricata and DNS-based detection.
Project: https://github.com/julioliraup/Antiphishing
CyberSecurity #ThreatIntelligence #Suricata #Phishing #CTI #BlueTeam #OpenSource
Links cited in this discussion
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Antiphishing project implements a detection layer that monitors newly registered domains to identify potential phishing infrastructure early. It uses a multi-step analysis pipeline including domain structural analysis, typosquatting and homoglyph detection, high-risk keyword identification, and suspicious domain classification. Domains flagged as suspicious are automatically added to a phishing list used by Suricata rules for DNS and TLS detection. This approach does not rely on external phishing feeds but generates its own indicators, providing traceability and auditability through stored suspicious domain lists. The ruleset updates approximately every six hours to track emerging phishing vectors.
Potential Impact
By identifying potentially malicious domains shortly after registration, this project can help defenders detect phishing infrastructure earlier than traditional IOC-based methods. This early detection can reduce the window of exposure to phishing attacks by enabling network-level blocking or alerting on suspicious DNS and TLS traffic. However, as this is a detection enhancement rather than a vulnerability or exploit, it does not represent a direct threat but rather a defensive capability.
Defensive Guidance
This is a defensive tool rather than a vulnerability requiring patching. No remediation or patch is applicable. Organizations interested in enhancing phishing detection can consider integrating this open-source ruleset with Suricata deployments. Users should monitor the project repository for updates and contribute feedback to improve detection accuracy and reduce false positives.
Technical Details
- Source Type
- Subreddit
- cybersecurity
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Domain
- null
- Newsworthiness Assessment
- {"score":30,"reasons":["external_link","newsworthy_keywords:ioc","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":["ioc"],"foundNonNewsworthy":[]}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6a77d024bf8831d53990e9ed
Added to database: 08/09/2026, 00:56:04 UTC
Last enriched: 08/09/2026, 00:56:15 UTC
Last updated: 08/09/2026, 03:40:59 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.