Back to updates
New releaseJul 23, 2026

Antiphishing v29961632599

Suricata rulesets to protect against phishing attack.

Share

Antiphishing logo GitHub commit activity GitHub commit activity

[ DONATE - DASHBOARD VECTORS - CONTRIBUTING - SUBMIT A VECTOR - REST API CTI - WIKI ]

Protect against phishing attacks

Functionality

This rule is built using malicious URLs and domains involved in phishing attacks. We utilize some community APIs and NRD (Newly Registered Domain) to construct these rules, and with them, we create TLS, DNS, and HTTP rules.

Our sources:

  1. Phishstats
  2. Openphish
  3. cbuijs/nrd β€” Newly Registered Domain intelligence

Contribution: CONTRIBUTING.md

Installation guide

Configuration-Ruleset-on-GNU-Linux Configuration-Ruleset-on-cearos Configuration-Ruleset-on-pfSense Configuration: Antiphishing Ruleset on IDSTower

General info

The ruleset is the antiphishing.rules file, which contains two rules (TLS, DNS) that depend on a phishing.lst list. Finally, there is another file named antiphishing.rules.md5 for integrity verification. We provide a compressed file containing these mentioned files, which are constantly updated without changing the URL (tar.gz):

https://github.com/julioliraup/Antiphishing/raw/refs/heads/main/antiphishing.tar.gz

Dot rules file:

https://github.com/julioliraup/Antiphishing/raw/refs/heads/main/antiphishing.rules

πŸ›‘οΈ NRD Threat Intelligence

Antiphishing now includes a Newly Registered Domains (NRD) analysis layer focused on proactive phishing infrastructure detection.

The pipeline analyzes newly registered domains with observed DNS resolution/activity through public recursive DNS resolvers, including:

  • 8.8.8.8 β€” Google Public DNS
  • 1.1.1.1 β€” Cloudflare DNS

The analysis generates more than 1.5 million possible domain combinations for inspection, using techniques associated with:

  • Typosquatting
  • Homoglyph detection
  • Brand impersonation
  • High-risk phishing terminology

The generated combinations are analyzed to identify domains that present suspicious characteristics.

Domains classified as suspicious by the analysis pipeline are automatically incorporated into the Antiphishing intelligence dataset and can become detection indicators for DNS and TLS/SNI traffic in Suricata.

Antiphishing Threat Intel are added to the file:" ou "The CRMs are added to the file:

nrd_suspicious_domains.txt

Upcoming Guides

IPFire julioliraup/antiphishing ruleset on intrusion prevention OPNsense  julioliraup/antiphishing ruleset on Suricata

Updates & Automation

Our ruleset is updated dynamically every ~6 hours to track emerging phishing vectors.

  • SID Range: 6000000 - 6100000 (Carefully assigned to prevent conflicts with other rulesets) .
  • Format: Fully compatible with suricata-update.

πŸ›‘οΈ Enterprise Support & Funding

This project is open-source and free for both personal and commercial use. To maintain high-availability infrastructure, automated collection pipelines, and our Threat Intelligence Lookup Portal (/AT), we rely on community and corporate funding.

Why Sponsor?

  • Infrastructure Sustainability: Funds go directly toward dedicated servers for rule generation and processing licenses.
  • Corporate Visibility: Companies contributing above a certain threshold can feature their logo in this README.

πŸ‡§πŸ‡· Donation via PIX (Brazil)

You can support the project instantly via PIX:

  • PIX Key: 08650081401
  • Beneficiary: JΓΊlio Lira

🌐 International Backers

For recurring sponsorship, priority support, or international donations, please check our FUNDING.md or use the Sponsor button at the top of this repository.


Contact & False Positives

If you encounter any false positives, have suggestions, or want to discuss corporate partnerships:

Categories