API da Ruleset julioliraup/Antiphishing on air
The julioliraup/Antiphishing project provides a publicly accessible, read-only JSON API that exposes detailed information about phishing-related Suricata rules. It includes data on individual phishing URLs and vector-based rules that match DNS and TLS queries against a large blocklist of suspicious domains. The API is hosted on GitHub Pages and does not require authentication or strict rate limiting. It serves as a threat intelligence source for identifying phishing domains and URLs, with data updated regularly. There is no indication of a vulnerability or exploit in the API itself.
AI Analysis
Technical Summary
This is a public threat intelligence API offering detailed Suricata IDS rules related to phishing detection. It includes endpoints to retrieve specific rule details by SID, a compact index of all rules, and vector-based rules that cover DNS and TLS SNI queries against a blocklist of over 243,000 suspicious domains. The API is read-only, hosted on GitHub Pages, and designed for querying phishing-suspect fully qualified domain names (FQDNs) with metadata such as WHOIS, IP, geolocation, and threat mapping. No authentication or patch information is relevant as this is an intelligence feed rather than a vulnerability or exploit.
Potential Impact
There is no direct security impact or vulnerability described. The API provides threat intelligence data to help defenders identify phishing threats. It does not expose sensitive information or have known exploits. The data can assist security teams in detecting and mitigating phishing attacks by providing up-to-date phishing domain blocklists and Suricata rule details.
Mitigation Recommendations
No mitigation is required as this is not a vulnerability or exploit. The API is a security resource intended for defensive use. Users should consume the API responsibly, respecting the recommended rate limits. No patch or fix is applicable.
API da Ruleset julioliraup/Antiphishing on air
Description
The julioliraup/Antiphishing project provides a publicly accessible, read-only JSON API that exposes detailed information about phishing-related Suricata rules. It includes data on individual phishing URLs and vector-based rules that match DNS and TLS queries against a large blocklist of suspicious domains. The API is hosted on GitHub Pages and does not require authentication or strict rate limiting. It serves as a threat intelligence source for identifying phishing domains and URLs, with data updated regularly. There is no indication of a vulnerability or exploit in the API itself.
Reddit Discussion
Now, it is possible to query phishing-suspect FQDNs through the free API, featuring database information on WHOIS, IP, Geolocation, and threat mapping
https://github.com/julioliraup/AT/wiki/REST-API-USE
A frontend interface is also available: https://julioliraup.github.io/AT
Links cited in this discussion
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This is a public threat intelligence API offering detailed Suricata IDS rules related to phishing detection. It includes endpoints to retrieve specific rule details by SID, a compact index of all rules, and vector-based rules that cover DNS and TLS SNI queries against a blocklist of over 243,000 suspicious domains. The API is read-only, hosted on GitHub Pages, and designed for querying phishing-suspect fully qualified domain names (FQDNs) with metadata such as WHOIS, IP, geolocation, and threat mapping. No authentication or patch information is relevant as this is an intelligence feed rather than a vulnerability or exploit.
Potential Impact
There is no direct security impact or vulnerability described. The API provides threat intelligence data to help defenders identify phishing threats. It does not expose sensitive information or have known exploits. The data can assist security teams in detecting and mitigating phishing attacks by providing up-to-date phishing domain blocklists and Suricata rule details.
Mitigation Recommendations
No mitigation is required as this is not a vulnerability or exploit. The API is a security resource intended for defensive use. Users should consume the API responsibly, respecting the recommended rate limits. No patch or fix is applicable.
Technical Details
- Source Type
- Subreddit
- cybersecurity
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Domain
- null
- Newsworthiness Assessment
- {"score":22,"reasons":["external_link","non_newsworthy_keywords:rules","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":[],"foundNonNewsworthy":["rules"]}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6a6cff6abf32cb7a343709a9
Added to database: 07/31/2026, 20:02:50 UTC
Last enriched: 07/31/2026, 20:03:02 UTC
Last updated: 07/31/2026, 21:17:49 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.