GitHub Trends
Project Radar
- Blue team toolromainmarcoux/malicious-outgoing-ipRepo · 42 stars
- Dual-use projectphishdestroy/destroylistHTML · 1,902 stars
- Dual-use project0xDanielLopez/TweetFeedRepo · 687 stars
Research DeskLatest update October 6, 202663 research entries
Independent Research Desk
Phishing Tradecraft · Infrastructure · Detection Engineering
PhishPond researches how modern phishing operations are built, run, and detected — campaign evolution, adversary infrastructure, phishing kits, OAuth and device-code abuse, AiTM frameworks, and the detection and validation workflows that catch them.
Recurring Intel
Attack-Side Tradecraft
Campaign tradecraft, lure mechanics, adversary infrastructure, identity pressure, and operator workflows worth modeling.
12 attack-side readsDetection Engineering
Detection engineering, telemetry analysis, reporting workflows, and validation that security teams can operationalize.
34 detection readsAPT Tradecraft
Emerging procedures, tooling, initial-access patterns, and cross-team tradecraft from real-world actor reporting.
17 tradecraft readsGitHub Trends
New Today
Lead Research
Enrollment urgency is the oldest helpdesk pretext wearing a new word. The objective is still a session token, and the tell is still Graph.
Microsoft tracked Storm-3121 and Storm-3032 running passkey-themed helpdesk calls since May 2026. The passkey narrative is a pretext that routes victims into AiTM and device-code flows — and the detection lives in what happens after the token lands, not in the lure.
Read more:Microsoft Security BlogBleepingComputer
Live Collection
Identity and session abuse can turn a single successful lure into account takeover.
Read more:BleepingComputer
A successful click delivers persistent remote access, not just credentials.
Read more:BleepingComputer
A successful click delivers persistent remote access, not just credentials.
Read more:SANS Internet Storm Center
Identity and session abuse can turn a single successful lure into account takeover.
Read more:Malwarebytes Labs
Trusted suppliers and developer channels can carry phishing risk past normal filters.
Read more:The Hacker News
Aggregation of lists of malicious IP addresses (C2, malware, phishing), to be blocked in the LAN > WAN direction, integrated into firewalls: FortiGate, Palo Alto, pfSense, IPtables 42 stars.
Open project:GitHub
#blocklist#blocklists#c2#firewall
Real-time phishing & scam domain blocklist - 205k+ curated threats, 1M+ community, free API, multiple formats Primary language: HTML. 1,902 stars.
Open project:GitHub
#anti-phishing#blacklist#blocklist#crypto-scam
TweetFeed collects Indicators of Compromise (IOCs) shared by the infosec community at Twitter. Here you will find malicious URLs, domains, IPs, and SHA256/MD5 hashes. 687 stars.
Open project:GitHub
#blueteam#malware#malware-detection#malware-research
Sublime rules for email attack detection, prevention, and threat hunting. Primary language: YAML. 376 stars.
Open project:GitHub
#email-security#phishing#threat-hunting
oisd blocklist 258 stars.
Open project:GitHub
#adblocking#adblocking-dns#adblocking-list#adblocklist
Coverage Map
Specific campaigns, actor activity, and the lures behind them.
How techniques work end-to-end — walkthroughs and operator workflows.
Adversary infrastructure: kits, AiTM, redirectors, and sending abuse.
Detection engineering, telemetry, validation, and response.
Longer research notes, measurement, and periodic briefs.
Search Tool
Search titles, authors, tags, and body text across the PhishPond research archive.
Showing 4 matching entries.Clear search
Field Analysis
Microsoft documented a July 2026 campaign dropping MSP360 RMM v2.5.0.67 as the initial agent and ConnectWise ScreenConnect as a second channel. ANY.RUN tracked the wider operation across 46 countries, with 94% of its kit URLs alive for a single day.
Read more:Microsoft Security BlogThe Hacker News
Field Analysis
Mailbox rules, OAuth grants, replayed sessions, RMM agents, and downstream account changes are not the aftermath of an intrusion — they are the point. A field guide to the persistence layer most response playbooks still treat as cleanup.
Read more:FBI IC3The Hacker News
Field Analysis
Runtimes, platforms, and brands rotate every quarter. The six handoffs that move a victim from manufactured urgency to durable persistence have barely changed in five years, and they are what defenders can actually build for.
Read more:FBI IC3Microsoft Security Blog
Field Analysis
Recent campaigns using SimpleHelp and ScreenConnect show how phishing can skip credential theft and move straight to persistent endpoint control.
Read more:The Hacker NewsDark Reading