GitHub Trends
Project Radar
- Blue team toolsublime-security/sublime-rulesYAML · 368 stars
- Dual-use project0xDanielLopez/TweetFeedRepo · 671 stars
- Dual-use projectphishdestroy/destroylistHTML · 1,662 stars
Research DeskLatest update July 19, 202659 research entries
Independent Research Desk
Phishing Tradecraft · Infrastructure · Detection Engineering
PhishPond researches how modern phishing operations are built, run, and detected — campaign evolution, adversary infrastructure, phishing kits, OAuth and device-code abuse, AiTM frameworks, and the detection and validation workflows that catch them.
Recurring Intel
Attack-Side Tradecraft
Campaign tradecraft, lure mechanics, adversary infrastructure, identity pressure, and operator workflows worth modeling.
12 attack-side readsDetection Engineering
Detection engineering, telemetry analysis, reporting workflows, and validation that security teams can operationalize.
32 detection readsAPT Tradecraft
Emerging procedures, tooling, initial-access patterns, and cross-team tradecraft from real-world actor reporting.
15 tradecraft readsGitHub Trends
New Today
Lead Research
The authentication failures look fragmented by app, but the campaign becomes visible when defenders pivot on missing app names, error semantics, source behavior, and tenant-wide volume.
Two large Entra ID campaigns used hundreds of thousands to millions of fictional OAuth client IDs to spread account enumeration across apparent applications.
Live Collection
Fake verification steps train users into running attacker-provided instructions.
Read more:The Hacker News
A successful click delivers persistent remote access, not just credentials.
Read more:The Hacker News
Trusted suppliers and developer channels can carry phishing risk past normal filters.
Read more:BleepingComputer
Fake verification steps train users into running attacker-provided instructions.
Read more:BleepingComputer
Fake verification steps train users into running attacker-provided instructions.
Read more:The Hacker News
Sublime rules for email attack detection, prevention, and threat hunting. Primary language: YAML. 368 stars.
Open project:GitHub
#email-security#phishing#threat-hunting
TweetFeed collects Indicators of Compromise (IOCs) shared by the infosec community at Twitter. Here you will find malicious URLs, domains, IPs, and SHA256/MD5 hashes. 671 stars.
Open project:GitHub
#blueteam#malware#malware-detection#malware-research
Real-time phishing & scam domain blocklist — 200k+ curated threats, 888K+ community, free API, multiple formats Primary language: HTML. 1,662 stars.
Open project:GitHub
#anti-phishing#blacklist#blocklist#crypto-scam
🐟 PhishTank Blocklist for Pi-hole Primary language: Shell. 12 stars.
Open project:GitHub
#blocklist#hosts#phishing#pihole
Aggregation of lists of malicious domains (phishing) that can be integrated into FortiGate firewalls and other products. Primary language: DIGITAL Command Language. 110 stars.
Open project:GitHub
#blocklist#blocklists#domains-blacklist#domains-list
Coverage Map
Specific campaigns, actor activity, and the lures behind them.
How techniques work end-to-end — walkthroughs and operator workflows.
Adversary infrastructure: kits, AiTM, redirectors, and sending abuse.
Detection engineering, telemetry, validation, and response.
Longer research notes, measurement, and periodic briefs.
Search Tool
Search titles, authors, tags, and body text across the PhishPond research archive.
Showing 10 matching entries.Clear search
Field Analysis
A late-June 2026 intrusion pivoted from an email lure to an external Teams call posing as 'System Administrator,' drove the victim's desktop through Teams screen-control, and staged a Node.js-based EtherRAT that resolves its C2 from an Ethereum smart contract. The trusted channel is the tradecraft.
Read more:Unit 42 (Palo Alto Networks)GBHackers
Field Analysis
Mailbox rules, OAuth grants, replayed sessions, RMM agents, and downstream account changes are not the aftermath of an intrusion — they are the point. A field guide to the persistence layer most response playbooks still treat as cleanup.
Read more:FBI IC3The Hacker News
Field Analysis
Runtimes, platforms, and brands rotate every quarter. The six handoffs that move a victim from manufactured urgency to durable persistence have barely changed in five years, and they are what defenders can actually build for.
Read more:FBI IC3Microsoft Security Blog
Field Analysis
SentinelOne's writeup of the SHub Reaper macOS stealer shows the ClickFix family adapting to platform hardening. When macOS Tahoe 26.4 closed the Terminal-based path, the operators moved to the applescript:// URL scheme and Script Editor instead.
Read more:SentinelOneBleepingComputer
Field Analysis
A reported exploitation wave against Ghost CMS pushed malicious JavaScript onto more than 700 sites, sending visitors into fake verification flows that used ClickFix-style paste-and-run instructions.
Read more:The Hacker NewsMalwarebytes Labs
Field Analysis
An Iranian actor opened an intrusion with a Microsoft Teams chat request and a screen-sharing session, harvested credentials live, then staged ransomware as cover for a state-backed operation.
Read more:The Hacker NewsRapid7
Field Analysis
Recent campaigns using SimpleHelp and ScreenConnect show how phishing can skip credential theft and move straight to persistent endpoint control.
Read more:The Hacker NewsDark Reading
Field Analysis
Device code phishing turns a legitimate OAuth flow into a credential-free token theft technique. Here is how it runs end-to-end and what defenders can hunt on in Sentinel and Defender XDR.
Read more:Microsoft Security BlogIETF
Field Analysis
Most M365 phishing incidents are decided in the first hour. This walkthrough lays out a 60-minute response chain from user report to refresh-token revocation and consent reversal.