Skip to main content
PPPhishPondPhishing Tradecraft Intelligence

Attack · Detection · Validation

CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe
CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe

Research Desk

PhishPond

Phishing tradecraft research desk covering campaign analysis, adversary infrastructure, detection engineering, and validation workflows.

High signal for security teams who need tradecraft, not recycled filler.

Navigate

  • Home
  • Newsroom
  • Research
  • Subscribe

Signals

  • editorial@phishpond.dev
  • Research Mission & Ethics
  • Intel Brief
  • RSS Feed
  • Submit Research Tip
© 2026 PhishPond. Authorized security research use only.

GitHub Trends

Project Radar

Blue-team, red-team, and dual-use phishing security projects found by the scheduled GitHub scanner. The radar is meant to help defenders, testers, and researchers track useful tooling without turning the feed into a credential-theft kit directory.

Last refreshed Jun 12, 202660 tracked projects15 red-team tools36 blue-team tools9 dual-use projects

DIGITAL Command LanguageBlue team tool

romainmarcoux/malicious-domains

Aggregation of lists of malicious domains (phishing) that can be integrated into FortiGate firewalls and other products. Primary language: DIGITAL Command Language. 99 stars.

Read:README previewGitHub project

99 stars17 forkspushed Jun 12, 2026MIT

#blocklist#blocklists#domains-blacklist#domains-list#fortigate#fortinet#malicious-domains#phishing

RepositoryBlue team tool

romainmarcoux/malicious-outgoing-ip

Aggregation of lists of malicious IP addresses (C2, malware, phishing), to be blocked in the LAN > WAN direction, integrated into firewalls: FortiGate, Palo Alto, pfSense, IPtables 27 stars.

Read:README previewGitHub project

27 stars2 forkspushed Jun 12, 2026MIT

#blocklist#blocklists#c2#firewall#fortinet#malware#malware-protection#phishing

ShellBlue team tool

Zaczero/pihole-phishtank

🐟 PhishTank Blocklist for Pi-hole Primary language: Shell. 13 stars.

Read:README previewGitHub project

13 stars2 forkspushed Jun 12, 2026MIT

#blocklist#hosts#phishing#pihole#pihole-phishtank

RepositoryDual-use project

0xDanielLopez/TweetFeed

TweetFeed collects Indicators of Compromise (IOCs) shared by the infosec community at Twitter. Here you will find malicious URLs, domains, IPs, and SHA256/MD5 hashes. 660 stars.

Read:README previewGitHub project

660 stars70 forkspushed Jun 12, 2026

#blueteam#malware#malware-detection#malware-research#osint#phishing#phishing-attacks#phishing-detection

HTMLDual-use project

phishdestroy/destroylist

Real-time phishing & scam domain blocklist — 130k+ curated threats, 888K+ community, free API, multiple formats Primary language: HTML. 920 stars.

Read:README previewGitHub project

920 stars112 forkspushed Jun 12, 2026MIT

#anti-phishing#blacklist#blocklist#crypto-scam#cybersecurity#dns-blocklist#domains#drainer

RepositoryBlue team tool

sjhgvr/oisd

oisd blocklist 211 stars.

Read:README previewGitHub project

211 stars14 forkspushed Jun 12, 2026GPL-3.0

#adblocking#adblocking-dns#adblocking-list#adblocklist#adblockplus#adguardhome#blocklist#dns

ZeekBlue team tool

CriticalPathSecurity/Zeek-Intelligence-Feeds

Zeek-Formatted Threat Intelligence Feeds Primary language: Zeek. 401 stars.

Read:README previewGitHub project

401 stars50 forkspushed Jun 12, 2026MIT

#malware#phishing#threat-intelligence#threatintel#zeek#zeek-ids

YAMLBlue team tool

sublime-security/sublime-rules

Sublime rules for email attack detection, prevention, and threat hunting. Primary language: YAML. 364 stars.

Read:README previewGitHub project

364 stars99 forkspushed Jun 12, 2026MIT

#email-security#phishing#threat-hunting

PythonDual-use project

Bd-Mutant7/Cybersecurity-Threats-Guide

Cybersecurity Threats & Vulnerabilities Guide is a comprehensive educational resource that provides detailed documentation, detection scripts, and prevention strategies for various cybersecurity threats. Primary language: Python. 17 stars.

Read:README previewGitHub project

17 stars2 forkspushed Jun 12, 2026

#arp-poisoning#csrf#ddos-attacks#man-in-the-middle-attack#phishing#port-scanning#ransomware-dectection#researchers

RepositoryBlue team tool

Tempest-Solutions-Company/pihole_blocklists

Pi-hole and AdguardHome Block lists updated every 24Hrs, we aim for less than 0.01% false positive rate, block malware, C&C infrastructure, phishing and banking threats 51 stars.

Read:README previewGitHub project

51 stars1 forkspushed Jun 12, 2026

#adguard-blocklist#adguard-blocklists#adguard-home-blocklist#botnet-blocklist#malware-protection#malware-research#phishing#phishing-detection

PythonBlue team tool

sublime-security/static-files

A collection of static files maintained by the Sublime team, primarily used for phishing defense. Primary language: Python. 96 stars.

Read:README previewGitHub project

96 stars39 forkspushed Jun 12, 2026MIT

#disposable-domains#disposable-email-domains#email#phishing#phishing-defense#spam-detection#spam-filtering

GoDual-use project

cybercdh/kitphishr

A tool designed to hunt for Phishing Kit source code Primary language: Go. 231 stars.

Read:README previewGitHub project

231 stars39 forkspushed Jun 12, 2026NOASSERTION

#blue-team#golang#incident-response#osint#phishing#phishing-kit#security-tools#threat-intelligence

CSSBlue team tool

thalesgroup-cert/suspicious

AI-powered phishing & threat-analysis platform to automatically inspect, classify, and report suspicious emails, files, URLs, IPs, and hashes built for teams and organizations Primary language: CSS. 83 stars.

Read:README previewGitHub project

83 stars10 forkspushed Jun 12, 2026AGPL-3.0

#django#django-project#docker#docker-compose#javascript#mail#mail-analysis#python

Adblock Filter ListBlue team tool

FiltersHeroes/KADhosts

Wersja hosts, PiHole, dnsmasq, domenowa (Forti Guard) filtrów KAD Primary language: Adblock Filter List. 60 stars.

Read:README previewGitHub project

60 stars7 forkspushed Jun 12, 2026CC-BY-SA-4.0

#kad#kadhole#malware#phishing#phishing-sites#pi-hole#polish#polskie

Adblock Filter ListBlue team tool

FiltersHeroes/KAD

Filtry do uBlocka Origin i AdGuarda, chroniące przed różnymi zagrożeniami w polskiej sieci, takimi jak wirusy, fałszywe sklepy i subskrypcje SMS. Primary language: Adblock Filter List. 64 stars.

Read:README previewGitHub project

64 stars8 forkspushed Jun 12, 2026CC-BY-SA-4.0

#adguard#blocker#filter-lists#filterlist#filters#filtr#filtry#kad

RepositoryBlue team tool

cenk/nrd

Newly Registered Domains (NRD) lists generated from WhoisDS.com free database — daily domain lists for security and threat analysis. 47 stars.

Read:README previewGitHub project

47 stars2 forkspushed Jun 12, 2026NOASSERTION

#bloatware#botnet#malware#newly-registered-domains#nrd#phishing#scam#spyware

EJSRed team tool

Bd-Mutant7/Phishing-Simulation-Tool

Bd-Mutant7/Phishing-Simulation-Tool is a phishing-adjacent repository. Primary language: EJS. 9 stars.

Read:README previewGitHub project

9 stars0 forkspushed Jun 12, 2026

PythonBlue team tool

molangning/fire-av

Fire-AV is a collection of lists that you can use to block av providers and bad ips Primary language: Python. 24 stars.

Read:README previewGitHub project

24 stars1 forkspushed Jun 12, 2026Apache-2.0

#anti-av#firewall#phishing#wordlists

GoRed team tool

Bd-Mutant7/evilginx2

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication Primary language: Go. 5 stars.

Read:README previewGitHub project

5 stars1 forkspushed Jun 12, 2026BSD-3-Clause

ShellBlue team tool

Chocolate4U/Iran-clash-rules

Enhanced Clash and Clash.Meta routing rules with Iranian domains ruleset and a focus on security and adblocking. Primary language: Shell. 79 stars.

Read:README previewGitHub project

79 stars5 forkspushed Jun 12, 2026GPL-3.0

#adblock#clash#clash-meta#domains#geosite#gfw#iran#malware

ShellBlue team tool

j-moriarti/pDNSf-Hosts-collection

My personalized Hosts file collection of various sources, cleaned and optimized specially for pDNSf Primary language: Shell. 31 stars.

Read:README previewGitHub project

31 stars5 forkspushed Jun 12, 2026

#ad-block#ad-blocker#adblock#ads#blocklist#collection#filterlist#hosts

RepositoryBlue team tool

Chocolate4U/Iran-sing-box-rules

Enhanced sing-box and sing-box-clients routing rules with built-in Iranian domains and a focus on security and adblocking. 317 stars.

Read:README previewGitHub project

317 stars25 forkspushed Jun 12, 2026GPL-3.0

#adblock#domains#geoip#geosite#gfw#iran#malware#phishing

GoRed team tool

phishingclub/phishingclub

Simulation and red team Phishing Framework Primary language: Go. 223 stars.

Read:README previewGitHub project

223 stars30 forkspushed Jun 12, 2026NOASSERTION

#aitm#gophish-alternative#mitm-framework#mitm-proxy#phishing#phishing-attacks#phishing-servers#phishing-simulation

ShellBlue team tool

Chocolate4U/Iran-v2ray-rules

Enhanced v2ray/xray and v2ray/xray-clients routing rules with built-in Iranian domains and a focus on security and adblocking. Primary language: Shell. 677 stars.

Read:README previewGitHub project

677 stars53 forkspushed Jun 12, 2026GPL-3.0

#adblock#domains#geoip#geosite#gfw#iran#malware#phishing

PythonBlue team tool

KnightmareVIIVIIXC/AIO-Firebog-Blocklists

A collection of unified blocklists designed to provide complete filtering capabilities for different online threats. These blocklists are curated from multiple sources, offering a robust solution for blocking ads, malware, trackers, and other unwanted content. Primary language: Python. 123 stars.

Read:README previewGitHub project

123 stars2 forkspushed Jun 12, 2026GPL-3.0

#adblock#adguard#adguard-home#ads#blocklist#crypto#dnsmasq#domains

TextBlue team tool

hagezi/dns-blocklists

DNS-Blocklists: For a better internet - keep the internet clean! Primary language: Text. 23,667 stars.

Read:README previewGitHub project

23,667 stars711 forkspushed Jun 12, 2026GPL-3.0

#adblock#adguard#ads#blacklist#blocklist#coins#dns#domains

JavaScriptBlue team tool

Phishcan/phishcan-data

Canadian threat feeds updated every 12 hours. Primary language: JavaScript. 20 stars.

Read:README previewGitHub project

20 stars1 forkspushed Jun 12, 2026

#blocklist#canada#phishing#threat-intelligence

PythonRed team tool

dedsec1121fk/DedSec

Official DedSec Project GitHub Repository Primary language: Python. 958 stars.

Read:README previewGitHub project

958 stars493 forkspushed Jun 12, 2026NOASSERTION

#android-security#cybersecurity#ethical-hacking#hacking-tools#information-security#mobile-hacking#network-security#osint

HTMLRed team tool

HailBytes/gophish-training-templates

Professional email templates and landing pages for employee security awareness phishing simulations using GoPhish. Ready-to-deploy campaigns with realistic scenarios, educational content, and customizable branding for enterprise security training programs. Primary language: HTML. 39 stars.

Read:README previewGitHub project

39 stars5 forkspushed Jun 12, 2026MPL-2.0

#cybersecurity-training#email-template#gophish#hailbytes#phishing-simulation#security-awareness#security-awareness-training

PythonBlue team tool

Bert-JanP/Open-Source-Threat-Intel-Feeds

This repository contains Open Source freely usable Threat Intel feeds that can be used without additional requirements. Contains multiple types such as IP, URL, CVE and Hash. Primary language: Python. 850 stars.

Read:README previewGitHub project

850 stars92 forkspushed Jun 12, 2026BSD-3-Clause

#c2#ioc#iocfeed#malware#misp#phishing#threat-hunting#threat-intelligence

RepositoryDual-use project

0xDanielLopez/phishing_kits

Exposing phishing kits seen from phishunt.io 267 stars.

Read:README previewGitHub project

267 stars36 forkspushed Jun 12, 2026

#malware#osint#phishing#phishing-attacks#phishing-detection#phishing-kit#phishing-sites#scam

RepositoryDual-use project

WhoisFreaks/daily-expired-and-dropped-domains

A public, research-focused dataset of expired, and recently dropped domains curated for cybersecurity analysis, brand monitoring, threat intelligence, and market research. 7 stars.

Read:README previewGitHub project

7 stars1 forkspushed Jun 12, 2026

#daily-dropped-domains#daily-expired-domains#domain-intelligence#drop-lists#dropped-domains#expired-domains#expiring-domains#osint

TypeScriptRed team tool

COS301-SE-2026/Tyto-PhishShield

Tyto-PhishShield is an AI-powered phishing awareness and simulation platform. Tyto-PhishShield is an enterprise-grade Human Risk Management (HRM) platform. Primary language: TypeScript. 5 stars.

Read:README previewGitHub project

5 stars0 forkspushed Jun 12, 2026

PythonBlue team tool

julioliraup/Antiphishing

Suricata rulesets for protect against phishing attack. Primary language: Python. 7 stars.

Read:README previewGitHub project

7 stars2 forkspushed Jun 12, 2026GPL-3.0

#anti-phishing#antiphishing#ids#ips#ndr#openphish#otx#otx-alienvault

PythonBlue team tool

overwrite00/EMLyzer

Open-source email analytics platform to identify spam, phishing, and malicious content. Primary language: Python. 17 stars.

Read:README previewGitHub project

17 stars1 forkspushed Jun 12, 2026MIT

#cybersecurity#cybersecurity-tools#email#email-phishing#email-verification#threath-analysis

HTMLBlue team tool

2002hackerr/zphishing

Phshing tool Primary language: HTML. 30 stars.

Read:README previewGitHub project

30 stars4 forkspushed Jun 11, 2026GPL-3.0

#hacking#hacking-tools#phishing#termux#termux-hacking

PythonDual-use project

syed-sameer-ul-hassan/MailSpoof

MailSpoof is a professional, open-source email spoofing and phishing simulation framework designed for authorized penetration testing, red team operations and security awareness training. Primary language: Python. 7 stars.

Read:README previewGitHub project

7 stars0 forkspushed Jun 11, 2026

#attachment-testing#bulk-phishing#cybersecurity#email-security#email-spoofing#email-tracking#penetration-testing#phishing-awareness

RepositoryDual-use project

spmedia/Crypto-Scam-and-Crypto-Phishing-Threat-Intel-Feed

A fresh feed of crypto phishing and crypto scam websites. Automatically updated daily/frequently. 61 stars.

Read:README previewGitHub project

61 stars11 forkspushed Jun 11, 2026MIT

#blacklist#blocklist#crypto-scam#cryptocurrency#osint#phishing#phishing-detection#phishing-page

PythonDual-use project

elliotwutingfeng/GlobalAntiScamOrg-blocklist

Machine-readable .txt blocklist of scam URLs and IP Addresses from the Global Anti Scam Organization (https://www.globalantiscam.org) website, updated once a day. Primary language: Python. 34 stars.

Read:README previewGitHub project

34 stars3 forkspushed Jun 11, 2026BSD-3-Clause

#blocklist#dnsbl#ip#ipv4#osint#pfblockerng#phishing#pihole

JavaScriptBlue team tool

OspreyProject/Osprey

Browser extension that protects you from phishing and malicious websites. Primary language: JavaScript. 167 stars.

Read:README previewGitHub project

167 stars15 forkspushed Jun 11, 2026GPL-3.0

#browser#browser-extension#chrome#chrome-extension#css#cybersecurity#cybersecurity-tools#firefox

GoRed team tool

OppressionBreedsResistance/gophish-ng

Make Gophish great again Primary language: Go. 11 stars.

Read:README previewGitHub project

11 stars1 forkspushed Jun 11, 2026NOASSERTION

BladeRed team tool

Advait251206/Phishing-Awareness-Simulator

A Laravel-based phishing awareness simulator for safe, hands-on cybersecurity training. Primary language: Blade. 24 stars.

Read:README previewGitHub project

24 stars0 forkspushed Jun 11, 2026NOASSERTION

Adblock Filter ListBlue team tool

ammnt/DeadEnd

The enhanced and optimized DNS filter for AdGuard Home🚧 Primary language: Adblock Filter List. 18 stars.

Read:README previewGitHub project

18 stars0 forkspushed Jun 11, 2026GPL-3.0

#adblock#adguard#ads#advertisement#advertising#adware#banners#blocking

YARABlue team tool

t4d/PhishingKit-Yara-Rules

Repository of Yara rules dedicated to Phishing Kits Zip files Primary language: YARA. 240 stars.

Read:README previewGitHub project

240 stars40 forkspushed Jun 11, 2026AGPL-3.0

#fraud-detection#fraud-prevention#phishing#phishing-detection#phishing-kit#phishing-sites#phishing-tool#virustotal

ShellRed team tool

cisagov/postfix-docker

Docker container with a postfix server designed for use during phishing campaigns Primary language: Shell. 67 stars.

Read:README previewGitHub project

67 stars16 forkspushed Jun 10, 2026CC0-1.0

Jupyter NotebookBlue team tool

Himanshu49Gaur/PhishDefender-PhishingResponseSystem

An end-to-end AI-powered phishing detection and response platform built as a Chrome browser extension. Combines machine learning, threat intelligence APIs, and rule-based automation to detect, analyze, and respond to phishing emails in real time directly inside Gmail. Primary language: Jupyter Notebook. 12 stars.

Read:README previewGitHub project

12 stars10 forkspushed Jun 10, 2026MIT

GoRed team tool

kgretzky/evilginx2

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication Primary language: Go. 15,178 stars.

Read:README previewGitHub project

15,178 stars2,654 forkspushed Jun 10, 2026BSD-3-Clause

TypeScriptBlue team tool

txkit/mono

Safe bridge between AI agents and Web3 transactions. Open-source React kit + protocol with anti-phishing UI patterns built in. Primary language: TypeScript. 5 stars.

Read:README previewGitHub project

5 stars0 forkspushed Jun 10, 2026MIT

#accessibility#account-abstraction#ai-agents#anti-phishing#arbitrum#eip-7702#erc-8265#ethereum

HTMLRed team tool

Apinke/dont-get-hooked

🎣 Don't Get Hooked! — A phishing awareness comic by Gbemisola Esho | AFRALO / ICANN At-Large Primary language: HTML. 6 stars.

Read:README previewGitHub project

6 stars1 forkspushed Jun 10, 2026NOASSERTION

PythonBlue team tool

SeriousHoax/Cloudflare-Gateway-Adblock-Updater

Automates Cloudflare Gateway updates with Hagezi Pro++ DNS filter to block ads, trackers, and malicious domains - A completely free alternative to NextDNS, AdGuard, ControlD and other similar services Primary language: Python. 11 stars.

Read:README previewGitHub project

11 stars26 forkspushed Jun 9, 2026MIT

#adblock#anti-phishing#anti-tracking#antimalware#cloudflare#cloudflare-gateway#cloudflare-zero-trust#privacy

GoBlue team tool

abhizaik/urlvet

Open-source phishing detection engine with explainable verdict. Self-hostable alternative to VirusTotal, CheckPhish, URLScan.io Primary language: Go. 103 stars.

Read:README previewGitHub project

103 stars12 forkspushed Jun 9, 2026AGPL-3.0

#domain-analysis#golang#link-scanner#phishing#phishing-detection#security-tools#self-hosted#svelte

PythonRed team tool

dan1t0/gophish-mcp

A lightweight toolkit of scripts and utilities to automate Gophish campaigns, streamline phishing assessments, and speed up MCP security workflows. Primary language: Python. 20 stars.

Read:README previewGitHub project

20 stars4 forkspushed Jun 8, 2026MIT

HTMLRed team tool

Pericena/CiclopeClic

Security awareness training tool for authorized phishing simulations and internal IT audits Primary language: HTML. 15 stars.

Read:README previewGitHub project

15 stars1 forkspushed Jun 6, 2026MIT

#apk#app#hacker#hacking#tools

PythonBlue team tool

syed-sameer-ul-hassan/Phish-Vigil

An enterprise-grade Human Risk Intelligence Platform & Phishing Simulator. Tracks Risk Velocity, Employee Resilience, and Learning Momentum with immutable audit logs Primary language: Python. 8 stars.

Read:README previewGitHub project

8 stars0 forkspushed Jun 5, 2026NOASSERTION

JavaScriptRed team tool

phishingclub/session-sushi

Zero dependency browser extension for handling import of cookies, Microsoft 365 OAuth tokens, and Graph API interactions. Primary language: JavaScript. 30 stars.

Read:README previewGitHub project

30 stars4 forkspushed Jun 5, 2026NOASSERTION

#extension#phishing#redteam

RepositoryBlue team tool

NoMorePhish/Tycoon2FADomains

Repository with Domains Related to Tycoon2FA Phishing Infrastructure 18 stars.

Read:README previewGitHub project

18 stars3 forkspushed Jun 5, 2026

PythonBlue team tool

lindsey98/Phishpedia

Official Implementation of "Phishpedia: A Hybrid Deep Learning Based Approach to Visually Identify Phishing Webpages" USENIX'21 Primary language: Python. 352 stars.

Read:README previewGitHub project

352 stars55 forkspushed Jun 5, 2026CC0-1.0

#computer-vision#cybersecurity#phishing-detection

PythonBlue team tool

lindsey98/PhishIntention

PhishIntention: Phishing detection through webpage intention Primary language: Python. 258 stars.

Read:README previewGitHub project

258 stars23 forkspushed Jun 5, 2026CC0-1.0

#deep-learning-classification#deep-learning-object-detection#dynamic-web-interaction#phishing-detection#phishing-identification

ShellBlue team tool

sublime-security/sublime-platform

A free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing. Gain visibility and control, hunt for advanced threats, collaborate with the community, and write detections-as-code. Primary language: Shell. 260 stars.

Read:README previewGitHub project

260 stars29 forkspushed Jun 4, 2026MIT

#detection-rules#email-security#phishing#phishing-detection#security#security-tools

HTMLRed team tool

phishingclub/templates

Phishing Template Workbench Primary language: HTML. 39 stars.

Read:README previewGitHub project

39 stars7 forkspushed Jun 3, 2026MIT

#gophish-template#phishing-page#phishing-templates#phishing-tool#phishing-toolkit#phishingclub