Repository files navigation

PHISHER 🐠

Development of tools for identifying resources such as Phishing and Shadow-IT

Tool for detecting phishing resources and Shadow IT services in enterprise environments

🎯 Description

PHISHER is a command-line utility for automated detection of:

  • Phishing domains and pages — using signatures, trusted resource lists, SSL certificate analysis, and brand similarity checks.
  • Shadow IT — unauthorized cloud services, SaaS applications, unregistered subdomains, and third-party tools used within the company. The tool combines several methods: domain mutation generation, subdomain search by brand names, WHOIS data analysis, and image/keyword verification.

The tool combines several methods: domain mutation generation, subdomain search by brand names, WHOIS data analysis, and image/keyword verification.

✨ Features

  • Generation and search of domain mutations — uses dnstwist to create similar domains (typosquatting, homoglyphs, etc.) and verifies their existence through Netlas.
  • Subdomain search by brand — searches for subdomains of the brandname.* type at level 3-4, excluding legitimate top domains.
  • WHOIS verification — verifies registration data (organization, phone, email) with reference data.
  • Double checking of suspicious domains:
    • Detection of official images (based on links from the perimeter)
    • Search for keywords (brand terms) on the page
  • Criticality score — each domain gets a rank from Legitimate (0) to High (3).
  • A beautiful output to the console is a table with a color indication of danger (rich library).

Important

An active API key is required for the service Netlas.io (registration is free, but there are limits on the number of requests)

🚀 Installation

From source

#!/bin/bash
git clone https://github.com/your-org/fisher.git
cd fisher
pip install -r requirements.txt
python setup.py install

✨ Features

  • Generation and search of domain mutations — uses dnstwist to create similar domains (typosquatting, homoglyphs, etc.) and verifies their existence through Netlas.
  • Subdomain search by brand — searches for subdomains of the brandname.* type at level 3-4, excluding legitimate top domains.
  • WHOIS verification — verifies registration data (organization, phone, email) with reference data.
  • Double checking of suspicious domains:
    • Detection of official images (based on links from the perimeter)
    • Search for keywords (brand terms) on the page
  • Criticality score — each domain gets a rank from Legitimate (0) to High (3).
  • A beautiful output to the console is a table with a color indication of danger (rich library).

Important

An active API key is required for the service Netlas.io (registration is free, but there are limits on the number of requests)

🔧 Setting up

From source

Manual installation (PIP is recommended):

#!/bin/bash
pip install netlas dnstwist beautifulsoup4 requests rich

Tip

dnstwist may require the compilation of C extensions. If problems arise, install the dnstwist system package (for example, sudo apt install dnstwist), but the code uses the dnstwist.run() call, which the Python module expects. In this case, adaptation will be required.

📄 Preparation of the input JSON file (perimeter)

The tool accepts a JSON file with a description of the protected perimeter. An example is perimeter_example.json:

 {
"domains": ["pochtabank.ru", "pochtabank.phx.media"],
"topdomains": ["pochtabank.ru", "phx.media", "nalogia.ru"],
"brandnames": ["pochtabank", "pochta-bank", "postbank"],
"whois": {
"organisation": ["SC \"Post Bank\""]
},
"keywords": ["Почта Банк", "кредиты", "дебетовые", "карты", "вклады", "ипотека", "банк", "почта"],
"imglinks": [
"https://cdn.pochtabank.ru/_next/image?url=...background_2901_24.jpg"
]
}
FieldTypePurpose
domainslist of rowsThe organization's reference domains. Mutations (typos, substitutions) will be generated for them
topdomainslist of stringsValid "top" domains (for example, pochtabank.ru ). They are used to exclude legitimate subdomains during the search
brandnameslist of stringsBrand names (keywords for searching subdomains like brandname.*)
whoisobjectExpected registration data. The organization key (a list of strings) is supported, as well as phone and email (present in the code, but not in the example)
keywordslist of stringsWords and phrases specific to the official website (will be searched on suspicious pages)
imglinkslist of stringsAbsolute links to official images (for example, logos, banners). Their presence on the verified resource is checked

🚀 Launching

#!/bin/bash
python __main__.py -p <perimeter.json> -a <NETLAS_API_KEY>

At startup, an ASCII banner, the version, the name of the team, and the progress of the steps are displayed.

📊 Interpretation of criticality

The cout.print_domains() table converts a numeric value to a text level:

NumberLevelValue
0LegitimateRegistration data matched the reference → trusted domain
1LowWHOIS didn't match, but there are no official images or keywords on the page
2MediumWHOIS mismatch + one additional feature (image or keyword)
3HighWHOIS mismatch + both signs (image + keywords) → high probability of phishing

output_example

Note: The Critical level (4) is not reached in the current implementation, but is reserved in the code.

🐞 Possible errors and solutions

ErrorPossible causeSolution
ModuleNotFoundError: No module named "cout"Launch not from the root directory of the projectGo to the folder where __ is located main__.py, and execute python __main__.py
read error: File does not existIncorrect path to the JSON file is specifiedCheck the path, use absolute or relative correctly
dnstwist.run was not foundThe dnstwist package is not installed or is installed as a CLI utilityInstall via pip install dnstwist or adapt the code to invoke the system command
Netlas API key invalidInvalid or expired keyCheck the key in your Netlas account, create a new one
Failed connection with domainThe domain is not responding via HTTP/HTTPSCheck the availability of the domain in the browser. Some resources block bots
list index out of range in cout.print_domainswrong_domains contains values greater than 3 or non-numericCheck the source data: wrong_domains should be dict[domain, int]

🤝 License and authorship

The tool was developed by the Knights of the Round Table team. Version: 1.0.1#dev. The license is not specified in the source files, but it is intended to be used at the discretion of the authors (probably proprietary). When distributing, keep the title and the mention of authorship.

Caution

🐟 Phisher helps to detect digital threats and unauthorized resources in a timely manner. Use it as part of the perimeter monitoring process.

About

Development of tools for identifying resources such as “Phishing” and “Shadow IT”

Resources

Stars

3 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

PHISHER 🐠

Development of tools for identifying resources such as Phishing and Shadow-IT

Tool for detecting phishing resources and Shadow IT services in enterprise environments

🎯 Description

PHISHER is a command-line utility for automated detection of:

  • Phishing domains and pages — using signatures, trusted resource lists, SSL certificate analysis, and brand similarity checks.
  • Shadow IT — unauthorized cloud services, SaaS applications, unregistered subdomains, and third-party tools used within the company. The tool combines several methods: domain mutation generation, subdomain search by brand names, WHOIS data analysis, and image/keyword verification.

The tool combines several methods: domain mutation generation, subdomain search by brand names, WHOIS data analysis, and image/keyword verification.

✨ Features

  • Generation and search of domain mutations — uses dnstwist to create similar domains (typosquatting, homoglyphs, etc.) and verifies their existence through Netlas.
  • Subdomain search by brand — searches for subdomains of the brandname.* type at level 3-4, excluding legitimate top domains.
  • WHOIS verification — verifies registration data (organization, phone, email) with reference data.
  • Double checking of suspicious domains:
    • Detection of official images (based on links from the perimeter)
    • Search for keywords (brand terms) on the page
  • Criticality score — each domain gets a rank from Legitimate (0) to High (3).
  • A beautiful output to the console is a table with a color indication of danger (rich library).

Important

An active API key is required for the service Netlas.io (registration is free, but there are limits on the number of requests)

🚀 Installation

From source

#!/bin/bash
git clone https://github.com/your-org/fisher.git
cd fisher
pip install -r requirements.txt
python setup.py install

✨ Features

  • Generation and search of domain mutations — uses dnstwist to create similar domains (typosquatting, homoglyphs, etc.) and verifies their existence through Netlas.
  • Subdomain search by brand — searches for subdomains of the brandname.* type at level 3-4, excluding legitimate top domains.
  • WHOIS verification — verifies registration data (organization, phone, email) with reference data.
  • Double checking of suspicious domains:
    • Detection of official images (based on links from the perimeter)
    • Search for keywords (brand terms) on the page
  • Criticality score — each domain gets a rank from Legitimate (0) to High (3).
  • A beautiful output to the console is a table with a color indication of danger (rich library).

Important

An active API key is required for the service Netlas.io (registration is free, but there are limits on the number of requests)

🔧 Setting up

From source

Manual installation (PIP is recommended):

#!/bin/bash
pip install netlas dnstwist beautifulsoup4 requests rich

Tip

dnstwist may require the compilation of C extensions. If problems arise, install the dnstwist system package (for example, sudo apt install dnstwist), but the code uses the dnstwist.run() call, which the Python module expects. In this case, adaptation will be required.

📄 Preparation of the input JSON file (perimeter)

The tool accepts a JSON file with a description of the protected perimeter. An example is perimeter_example.json:

 {
"domains": ["pochtabank.ru", "pochtabank.phx.media"],
"topdomains": ["pochtabank.ru", "phx.media", "nalogia.ru"],
"brandnames": ["pochtabank", "pochta-bank", "postbank"],
"whois": {
"organisation": ["SC \"Post Bank\""]
},
"keywords": ["Почта Банк", "кредиты", "дебетовые", "карты", "вклады", "ипотека", "банк", "почта"],
"imglinks": [
"https://cdn.pochtabank.ru/_next/image?url=...background_2901_24.jpg"
]
}
FieldTypePurpose
domainslist of rowsThe organization's reference domains. Mutations (typos, substitutions) will be generated for them
topdomainslist of stringsValid "top" domains (for example, pochtabank.ru ). They are used to exclude legitimate subdomains during the search
brandnameslist of stringsBrand names (keywords for searching subdomains like brandname.*)
whoisobjectExpected registration data. The organization key (a list of strings) is supported, as well as phone and email (present in the code, but not in the example)
keywordslist of stringsWords and phrases specific to the official website (will be searched on suspicious pages)
imglinkslist of stringsAbsolute links to official images (for example, logos, banners). Their presence on the verified resource is checked

🚀 Launching

#!/bin/bash
python __main__.py -p <perimeter.json> -a <NETLAS_API_KEY>

At startup, an ASCII banner, the version, the name of the team, and the progress of the steps are displayed.

📊 Interpretation of criticality

The cout.print_domains() table converts a numeric value to a text level:

NumberLevelValue
0LegitimateRegistration data matched the reference → trusted domain
1LowWHOIS didn't match, but there are no official images or keywords on the page
2MediumWHOIS mismatch + one additional feature (image or keyword)
3HighWHOIS mismatch + both signs (image + keywords) → high probability of phishing

output_example

Note: The Critical level (4) is not reached in the current implementation, but is reserved in the code.

🐞 Possible errors and solutions

ErrorPossible causeSolution
ModuleNotFoundError: No module named "cout"Launch not from the root directory of the projectGo to the folder where __ is located main__.py, and execute python __main__.py
read error: File does not existIncorrect path to the JSON file is specifiedCheck the path, use absolute or relative correctly
dnstwist.run was not foundThe dnstwist package is not installed or is installed as a CLI utilityInstall via pip install dnstwist or adapt the code to invoke the system command
Netlas API key invalidInvalid or expired keyCheck the key in your Netlas account, create a new one
Failed connection with domainThe domain is not responding via HTTP/HTTPSCheck the availability of the domain in the browser. Some resources block bots
list index out of range in cout.print_domainswrong_domains contains values greater than 3 or non-numericCheck the source data: wrong_domains should be dict[domain, int]

🤝 License and authorship

The tool was developed by the Knights of the Round Table team. Version: 1.0.1#dev. The license is not specified in the source files, but it is intended to be used at the discretion of the authors (probably proprietary). When distributing, keep the title and the mention of authorship.

Caution

🐟 Phisher helps to detect digital threats and unauthorized resources in a timely manner. Use it as part of the perimeter monitoring process.

About

Development of tools for identifying resources such as “Phishing” and “Shadow IT”

Resources

Stars

3 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

PHISHER 🐠

Development of tools for identifying resources such as Phishing and Shadow-IT

Tool for detecting phishing resources and Shadow IT services in enterprise environments

🎯 Description

PHISHER is a command-line utility for automated detection of:

  • Phishing domains and pages — using signatures, trusted resource lists, SSL certificate analysis, and brand similarity checks.
  • Shadow IT — unauthorized cloud services, SaaS applications, unregistered subdomains, and third-party tools used within the company. The tool combines several methods: domain mutation generation, subdomain search by brand names, WHOIS data analysis, and image/keyword verification.

The tool combines several methods: domain mutation generation, subdomain search by brand names, WHOIS data analysis, and image/keyword verification.

✨ Features

  • Generation and search of domain mutations — uses dnstwist to create similar domains (typosquatting, homoglyphs, etc.) and verifies their existence through Netlas.
  • Subdomain search by brand — searches for subdomains of the brandname.* type at level 3-4, excluding legitimate top domains.
  • WHOIS verification — verifies registration data (organization, phone, email) with reference data.
  • Double checking of suspicious domains:
    • Detection of official images (based on links from the perimeter)
    • Search for keywords (brand terms) on the page
  • Criticality score — each domain gets a rank from Legitimate (0) to High (3).
  • A beautiful output to the console is a table with a color indication of danger (rich library).

Important

An active API key is required for the service Netlas.io (registration is free, but there are limits on the number of requests)

🚀 Installation

From source

#!/bin/bash
git clone https://github.com/your-org/fisher.git
cd fisher
pip install -r requirements.txt
python setup.py install

✨ Features

  • Generation and search of domain mutations — uses dnstwist to create similar domains (typosquatting, homoglyphs, etc.) and verifies their existence through Netlas.
  • Subdomain search by brand — searches for subdomains of the brandname.* type at level 3-4, excluding legitimate top domains.
  • WHOIS verification — verifies registration data (organization, phone, email) with reference data.
  • Double checking of suspicious domains:
    • Detection of official images (based on links from the perimeter)
    • Search for keywords (brand terms) on the page
  • Criticality score — each domain gets a rank from Legitimate (0) to High (3).
  • A beautiful output to the console is a table with a color indication of danger (rich library).

Important

An active API key is required for the service Netlas.io (registration is free, but there are limits on the number of requests)

🔧 Setting up

From source

Manual installation (PIP is recommended):

#!/bin/bash
pip install netlas dnstwist beautifulsoup4 requests rich

Tip

dnstwist may require the compilation of C extensions. If problems arise, install the dnstwist system package (for example, sudo apt install dnstwist), but the code uses the dnstwist.run() call, which the Python module expects. In this case, adaptation will be required.

📄 Preparation of the input JSON file (perimeter)

The tool accepts a JSON file with a description of the protected perimeter. An example is perimeter_example.json:

 {
"domains": ["pochtabank.ru", "pochtabank.phx.media"],
"topdomains": ["pochtabank.ru", "phx.media", "nalogia.ru"],
"brandnames": ["pochtabank", "pochta-bank", "postbank"],
"whois": {
"organisation": ["SC \"Post Bank\""]
},
"keywords": ["Почта Банк", "кредиты", "дебетовые", "карты", "вклады", "ипотека", "банк", "почта"],
"imglinks": [
"https://cdn.pochtabank.ru/_next/image?url=...background_2901_24.jpg"
]
}
FieldTypePurpose
domainslist of rowsThe organization's reference domains. Mutations (typos, substitutions) will be generated for them
topdomainslist of stringsValid "top" domains (for example, pochtabank.ru ). They are used to exclude legitimate subdomains during the search
brandnameslist of stringsBrand names (keywords for searching subdomains like brandname.*)
whoisobjectExpected registration data. The organization key (a list of strings) is supported, as well as phone and email (present in the code, but not in the example)
keywordslist of stringsWords and phrases specific to the official website (will be searched on suspicious pages)
imglinkslist of stringsAbsolute links to official images (for example, logos, banners). Their presence on the verified resource is checked

🚀 Launching

#!/bin/bash
python __main__.py -p <perimeter.json> -a <NETLAS_API_KEY>

At startup, an ASCII banner, the version, the name of the team, and the progress of the steps are displayed.

📊 Interpretation of criticality

The cout.print_domains() table converts a numeric value to a text level:

NumberLevelValue
0LegitimateRegistration data matched the reference → trusted domain
1LowWHOIS didn't match, but there are no official images or keywords on the page
2MediumWHOIS mismatch + one additional feature (image or keyword)
3HighWHOIS mismatch + both signs (image + keywords) → high probability of phishing

output_example

Note: The Critical level (4) is not reached in the current implementation, but is reserved in the code.

🐞 Possible errors and solutions

ErrorPossible causeSolution
ModuleNotFoundError: No module named "cout"Launch not from the root directory of the projectGo to the folder where __ is located main__.py, and execute python __main__.py
read error: File does not existIncorrect path to the JSON file is specifiedCheck the path, use absolute or relative correctly
dnstwist.run was not foundThe dnstwist package is not installed or is installed as a CLI utilityInstall via pip install dnstwist or adapt the code to invoke the system command
Netlas API key invalidInvalid or expired keyCheck the key in your Netlas account, create a new one
Failed connection with domainThe domain is not responding via HTTP/HTTPSCheck the availability of the domain in the browser. Some resources block bots
list index out of range in cout.print_domainswrong_domains contains values greater than 3 or non-numericCheck the source data: wrong_domains should be dict[domain, int]

🤝 License and authorship

The tool was developed by the Knights of the Round Table team. Version: 1.0.1#dev. The license is not specified in the source files, but it is intended to be used at the discretion of the authors (probably proprietary). When distributing, keep the title and the mention of authorship.

Caution

🐟 Phisher helps to detect digital threats and unauthorized resources in a timely manner. Use it as part of the perimeter monitoring process.

About

Development of tools for identifying resources such as “Phishing” and “Shadow IT”

Resources

Stars

3 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

PHISHER 🐠

Development of tools for identifying resources such as Phishing and Shadow-IT

Tool for detecting phishing resources and Shadow IT services in enterprise environments

🎯 Description

PHISHER is a command-line utility for automated detection of:

  • Phishing domains and pages — using signatures, trusted resource lists, SSL certificate analysis, and brand similarity checks.
  • Shadow IT — unauthorized cloud services, SaaS applications, unregistered subdomains, and third-party tools used within the company. The tool combines several methods: domain mutation generation, subdomain search by brand names, WHOIS data analysis, and image/keyword verification.

The tool combines several methods: domain mutation generation, subdomain search by brand names, WHOIS data analysis, and image/keyword verification.

✨ Features

  • Generation and search of domain mutations — uses dnstwist to create similar domains (typosquatting, homoglyphs, etc.) and verifies their existence through Netlas.
  • Subdomain search by brand — searches for subdomains of the brandname.* type at level 3-4, excluding legitimate top domains.
  • WHOIS verification — verifies registration data (organization, phone, email) with reference data.
  • Double checking of suspicious domains:
    • Detection of official images (based on links from the perimeter)
    • Search for keywords (brand terms) on the page
  • Criticality score — each domain gets a rank from Legitimate (0) to High (3).
  • A beautiful output to the console is a table with a color indication of danger (rich library).

Important

An active API key is required for the service Netlas.io (registration is free, but there are limits on the number of requests)

🚀 Installation

From source

#!/bin/bash
git clone https://github.com/your-org/fisher.git
cd fisher
pip install -r requirements.txt
python setup.py install

✨ Features

  • Generation and search of domain mutations — uses dnstwist to create similar domains (typosquatting, homoglyphs, etc.) and verifies their existence through Netlas.
  • Subdomain search by brand — searches for subdomains of the brandname.* type at level 3-4, excluding legitimate top domains.
  • WHOIS verification — verifies registration data (organization, phone, email) with reference data.
  • Double checking of suspicious domains:
    • Detection of official images (based on links from the perimeter)
    • Search for keywords (brand terms) on the page
  • Criticality score — each domain gets a rank from Legitimate (0) to High (3).
  • A beautiful output to the console is a table with a color indication of danger (rich library).

Important

An active API key is required for the service Netlas.io (registration is free, but there are limits on the number of requests)

🔧 Setting up

From source

Manual installation (PIP is recommended):

#!/bin/bash
pip install netlas dnstwist beautifulsoup4 requests rich

Tip

dnstwist may require the compilation of C extensions. If problems arise, install the dnstwist system package (for example, sudo apt install dnstwist), but the code uses the dnstwist.run() call, which the Python module expects. In this case, adaptation will be required.

📄 Preparation of the input JSON file (perimeter)

The tool accepts a JSON file with a description of the protected perimeter. An example is perimeter_example.json:

 {
"domains": ["pochtabank.ru", "pochtabank.phx.media"],
"topdomains": ["pochtabank.ru", "phx.media", "nalogia.ru"],
"brandnames": ["pochtabank", "pochta-bank", "postbank"],
"whois": {
"organisation": ["SC \"Post Bank\""]
},
"keywords": ["Почта Банк", "кредиты", "дебетовые", "карты", "вклады", "ипотека", "банк", "почта"],
"imglinks": [
"https://cdn.pochtabank.ru/_next/image?url=...background_2901_24.jpg"
]
}
FieldTypePurpose
domainslist of rowsThe organization's reference domains. Mutations (typos, substitutions) will be generated for them
topdomainslist of stringsValid "top" domains (for example, pochtabank.ru ). They are used to exclude legitimate subdomains during the search
brandnameslist of stringsBrand names (keywords for searching subdomains like brandname.*)
whoisobjectExpected registration data. The organization key (a list of strings) is supported, as well as phone and email (present in the code, but not in the example)
keywordslist of stringsWords and phrases specific to the official website (will be searched on suspicious pages)
imglinkslist of stringsAbsolute links to official images (for example, logos, banners). Their presence on the verified resource is checked

🚀 Launching

#!/bin/bash
python __main__.py -p <perimeter.json> -a <NETLAS_API_KEY>

At startup, an ASCII banner, the version, the name of the team, and the progress of the steps are displayed.

📊 Interpretation of criticality

The cout.print_domains() table converts a numeric value to a text level:

NumberLevelValue
0LegitimateRegistration data matched the reference → trusted domain
1LowWHOIS didn't match, but there are no official images or keywords on the page
2MediumWHOIS mismatch + one additional feature (image or keyword)
3HighWHOIS mismatch + both signs (image + keywords) → high probability of phishing

output_example

Note: The Critical level (4) is not reached in the current implementation, but is reserved in the code.

🐞 Possible errors and solutions

ErrorPossible causeSolution
ModuleNotFoundError: No module named "cout"Launch not from the root directory of the projectGo to the folder where __ is located main__.py, and execute python __main__.py
read error: File does not existIncorrect path to the JSON file is specifiedCheck the path, use absolute or relative correctly
dnstwist.run was not foundThe dnstwist package is not installed or is installed as a CLI utilityInstall via pip install dnstwist or adapt the code to invoke the system command
Netlas API key invalidInvalid or expired keyCheck the key in your Netlas account, create a new one
Failed connection with domainThe domain is not responding via HTTP/HTTPSCheck the availability of the domain in the browser. Some resources block bots
list index out of range in cout.print_domainswrong_domains contains values greater than 3 or non-numericCheck the source data: wrong_domains should be dict[domain, int]

🤝 License and authorship

The tool was developed by the Knights of the Round Table team. Version: 1.0.1#dev. The license is not specified in the source files, but it is intended to be used at the discretion of the authors (probably proprietary). When distributing, keep the title and the mention of authorship.

Caution

🐟 Phisher helps to detect digital threats and unauthorized resources in a timely manner. Use it as part of the perimeter monitoring process.

About

Development of tools for identifying resources such as “Phishing” and “Shadow IT”

Resources

Stars

3 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

PHISHER 🐠

Development of tools for identifying resources such as Phishing and Shadow-IT

Tool for detecting phishing resources and Shadow IT services in enterprise environments

🎯 Description

PHISHER is a command-line utility for automated detection of:

  • Phishing domains and pages — using signatures, trusted resource lists, SSL certificate analysis, and brand similarity checks.
  • Shadow IT — unauthorized cloud services, SaaS applications, unregistered subdomains, and third-party tools used within the company. The tool combines several methods: domain mutation generation, subdomain search by brand names, WHOIS data analysis, and image/keyword verification.

The tool combines several methods: domain mutation generation, subdomain search by brand names, WHOIS data analysis, and image/keyword verification.

✨ Features

  • Generation and search of domain mutations — uses dnstwist to create similar domains (typosquatting, homoglyphs, etc.) and verifies their existence through Netlas.
  • Subdomain search by brand — searches for subdomains of the brandname.* type at level 3-4, excluding legitimate top domains.
  • WHOIS verification — verifies registration data (organization, phone, email) with reference data.
  • Double checking of suspicious domains:
    • Detection of official images (based on links from the perimeter)
    • Search for keywords (brand terms) on the page
  • Criticality score — each domain gets a rank from Legitimate (0) to High (3).
  • A beautiful output to the console is a table with a color indication of danger (rich library).

Important

An active API key is required for the service Netlas.io (registration is free, but there are limits on the number of requests)

🚀 Installation

From source

#!/bin/bash
git clone https://github.com/your-org/fisher.git
cd fisher
pip install -r requirements.txt
python setup.py install

✨ Features

  • Generation and search of domain mutations — uses dnstwist to create similar domains (typosquatting, homoglyphs, etc.) and verifies their existence through Netlas.
  • Subdomain search by brand — searches for subdomains of the brandname.* type at level 3-4, excluding legitimate top domains.
  • WHOIS verification — verifies registration data (organization, phone, email) with reference data.
  • Double checking of suspicious domains:
    • Detection of official images (based on links from the perimeter)
    • Search for keywords (brand terms) on the page
  • Criticality score — each domain gets a rank from Legitimate (0) to High (3).
  • A beautiful output to the console is a table with a color indication of danger (rich library).

Important

An active API key is required for the service Netlas.io (registration is free, but there are limits on the number of requests)

🔧 Setting up

From source

Manual installation (PIP is recommended):

#!/bin/bash
pip install netlas dnstwist beautifulsoup4 requests rich

Tip

dnstwist may require the compilation of C extensions. If problems arise, install the dnstwist system package (for example, sudo apt install dnstwist), but the code uses the dnstwist.run() call, which the Python module expects. In this case, adaptation will be required.

📄 Preparation of the input JSON file (perimeter)

The tool accepts a JSON file with a description of the protected perimeter. An example is perimeter_example.json:

 {
"domains": ["pochtabank.ru", "pochtabank.phx.media"],
"topdomains": ["pochtabank.ru", "phx.media", "nalogia.ru"],
"brandnames": ["pochtabank", "pochta-bank", "postbank"],
"whois": {
"organisation": ["SC \"Post Bank\""]
},
"keywords": ["Почта Банк", "кредиты", "дебетовые", "карты", "вклады", "ипотека", "банк", "почта"],
"imglinks": [
"https://cdn.pochtabank.ru/_next/image?url=...background_2901_24.jpg"
]
}
FieldTypePurpose
domainslist of rowsThe organization's reference domains. Mutations (typos, substitutions) will be generated for them
topdomainslist of stringsValid "top" domains (for example, pochtabank.ru ). They are used to exclude legitimate subdomains during the search
brandnameslist of stringsBrand names (keywords for searching subdomains like brandname.*)
whoisobjectExpected registration data. The organization key (a list of strings) is supported, as well as phone and email (present in the code, but not in the example)
keywordslist of stringsWords and phrases specific to the official website (will be searched on suspicious pages)
imglinkslist of stringsAbsolute links to official images (for example, logos, banners). Their presence on the verified resource is checked

🚀 Launching

#!/bin/bash
python __main__.py -p <perimeter.json> -a <NETLAS_API_KEY>

At startup, an ASCII banner, the version, the name of the team, and the progress of the steps are displayed.

📊 Interpretation of criticality

The cout.print_domains() table converts a numeric value to a text level:

NumberLevelValue
0LegitimateRegistration data matched the reference → trusted domain
1LowWHOIS didn't match, but there are no official images or keywords on the page
2MediumWHOIS mismatch + one additional feature (image or keyword)
3HighWHOIS mismatch + both signs (image + keywords) → high probability of phishing

output_example

Note: The Critical level (4) is not reached in the current implementation, but is reserved in the code.

🐞 Possible errors and solutions

ErrorPossible causeSolution
ModuleNotFoundError: No module named "cout"Launch not from the root directory of the projectGo to the folder where __ is located main__.py, and execute python __main__.py
read error: File does not existIncorrect path to the JSON file is specifiedCheck the path, use absolute or relative correctly
dnstwist.run was not foundThe dnstwist package is not installed or is installed as a CLI utilityInstall via pip install dnstwist or adapt the code to invoke the system command
Netlas API key invalidInvalid or expired keyCheck the key in your Netlas account, create a new one
Failed connection with domainThe domain is not responding via HTTP/HTTPSCheck the availability of the domain in the browser. Some resources block bots
list index out of range in cout.print_domainswrong_domains contains values greater than 3 or non-numericCheck the source data: wrong_domains should be dict[domain, int]

🤝 License and authorship

The tool was developed by the Knights of the Round Table team. Version: 1.0.1#dev. The license is not specified in the source files, but it is intended to be used at the discretion of the authors (probably proprietary). When distributing, keep the title and the mention of authorship.

Caution

🐟 Phisher helps to detect digital threats and unauthorized resources in a timely manner. Use it as part of the perimeter monitoring process.

About

Development of tools for identifying resources such as “Phishing” and “Shadow IT”

Resources

Stars

3 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

PHISHER 🐠

Development of tools for identifying resources such as Phishing and Shadow-IT

Tool for detecting phishing resources and Shadow IT services in enterprise environments

🎯 Description

PHISHER is a command-line utility for automated detection of:

  • Phishing domains and pages — using signatures, trusted resource lists, SSL certificate analysis, and brand similarity checks.
  • Shadow IT — unauthorized cloud services, SaaS applications, unregistered subdomains, and third-party tools used within the company. The tool combines several methods: domain mutation generation, subdomain search by brand names, WHOIS data analysis, and image/keyword verification.

The tool combines several methods: domain mutation generation, subdomain search by brand names, WHOIS data analysis, and image/keyword verification.

✨ Features

  • Generation and search of domain mutations — uses dnstwist to create similar domains (typosquatting, homoglyphs, etc.) and verifies their existence through Netlas.
  • Subdomain search by brand — searches for subdomains of the brandname.* type at level 3-4, excluding legitimate top domains.
  • WHOIS verification — verifies registration data (organization, phone, email) with reference data.
  • Double checking of suspicious domains:
    • Detection of official images (based on links from the perimeter)
    • Search for keywords (brand terms) on the page
  • Criticality score — each domain gets a rank from Legitimate (0) to High (3).
  • A beautiful output to the console is a table with a color indication of danger (rich library).

Important

An active API key is required for the service Netlas.io (registration is free, but there are limits on the number of requests)

🚀 Installation

From source

#!/bin/bash
git clone https://github.com/your-org/fisher.git
cd fisher
pip install -r requirements.txt
python setup.py install

✨ Features

  • Generation and search of domain mutations — uses dnstwist to create similar domains (typosquatting, homoglyphs, etc.) and verifies their existence through Netlas.
  • Subdomain search by brand — searches for subdomains of the brandname.* type at level 3-4, excluding legitimate top domains.
  • WHOIS verification — verifies registration data (organization, phone, email) with reference data.
  • Double checking of suspicious domains:
    • Detection of official images (based on links from the perimeter)
    • Search for keywords (brand terms) on the page
  • Criticality score — each domain gets a rank from Legitimate (0) to High (3).
  • A beautiful output to the console is a table with a color indication of danger (rich library).

Important

An active API key is required for the service Netlas.io (registration is free, but there are limits on the number of requests)

🔧 Setting up

From source

Manual installation (PIP is recommended):

#!/bin/bash
pip install netlas dnstwist beautifulsoup4 requests rich

Tip

dnstwist may require the compilation of C extensions. If problems arise, install the dnstwist system package (for example, sudo apt install dnstwist), but the code uses the dnstwist.run() call, which the Python module expects. In this case, adaptation will be required.

📄 Preparation of the input JSON file (perimeter)

The tool accepts a JSON file with a description of the protected perimeter. An example is perimeter_example.json:

 {
"domains": ["pochtabank.ru", "pochtabank.phx.media"],
"topdomains": ["pochtabank.ru", "phx.media", "nalogia.ru"],
"brandnames": ["pochtabank", "pochta-bank", "postbank"],
"whois": {
"organisation": ["SC \"Post Bank\""]
},
"keywords": ["Почта Банк", "кредиты", "дебетовые", "карты", "вклады", "ипотека", "банк", "почта"],
"imglinks": [
"https://cdn.pochtabank.ru/_next/image?url=...background_2901_24.jpg"
]
}
FieldTypePurpose
domainslist of rowsThe organization's reference domains. Mutations (typos, substitutions) will be generated for them
topdomainslist of stringsValid "top" domains (for example, pochtabank.ru ). They are used to exclude legitimate subdomains during the search
brandnameslist of stringsBrand names (keywords for searching subdomains like brandname.*)
whoisobjectExpected registration data. The organization key (a list of strings) is supported, as well as phone and email (present in the code, but not in the example)
keywordslist of stringsWords and phrases specific to the official website (will be searched on suspicious pages)
imglinkslist of stringsAbsolute links to official images (for example, logos, banners). Their presence on the verified resource is checked

🚀 Launching

#!/bin/bash
python __main__.py -p <perimeter.json> -a <NETLAS_API_KEY>

At startup, an ASCII banner, the version, the name of the team, and the progress of the steps are displayed.

📊 Interpretation of criticality

The cout.print_domains() table converts a numeric value to a text level:

NumberLevelValue
0LegitimateRegistration data matched the reference → trusted domain
1LowWHOIS didn't match, but there are no official images or keywords on the page
2MediumWHOIS mismatch + one additional feature (image or keyword)
3HighWHOIS mismatch + both signs (image + keywords) → high probability of phishing

output_example

Note: The Critical level (4) is not reached in the current implementation, but is reserved in the code.

🐞 Possible errors and solutions

ErrorPossible causeSolution
ModuleNotFoundError: No module named "cout"Launch not from the root directory of the projectGo to the folder where __ is located main__.py, and execute python __main__.py
read error: File does not existIncorrect path to the JSON file is specifiedCheck the path, use absolute or relative correctly
dnstwist.run was not foundThe dnstwist package is not installed or is installed as a CLI utilityInstall via pip install dnstwist or adapt the code to invoke the system command
Netlas API key invalidInvalid or expired keyCheck the key in your Netlas account, create a new one
Failed connection with domainThe domain is not responding via HTTP/HTTPSCheck the availability of the domain in the browser. Some resources block bots
list index out of range in cout.print_domainswrong_domains contains values greater than 3 or non-numericCheck the source data: wrong_domains should be dict[domain, int]

🤝 License and authorship

The tool was developed by the Knights of the Round Table team. Version: 1.0.1#dev. The license is not specified in the source files, but it is intended to be used at the discretion of the authors (probably proprietary). When distributing, keep the title and the mention of authorship.

Caution

🐟 Phisher helps to detect digital threats and unauthorized resources in a timely manner. Use it as part of the perimeter monitoring process.

About

Development of tools for identifying resources such as “Phishing” and “Shadow IT”

Resources

Stars

3 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

PHISHER 🐠

Development of tools for identifying resources such as Phishing and Shadow-IT

Tool for detecting phishing resources and Shadow IT services in enterprise environments

🎯 Description

PHISHER is a command-line utility for automated detection of:

  • Phishing domains and pages — using signatures, trusted resource lists, SSL certificate analysis, and brand similarity checks.
  • Shadow IT — unauthorized cloud services, SaaS applications, unregistered subdomains, and third-party tools used within the company. The tool combines several methods: domain mutation generation, subdomain search by brand names, WHOIS data analysis, and image/keyword verification.

The tool combines several methods: domain mutation generation, subdomain search by brand names, WHOIS data analysis, and image/keyword verification.

✨ Features

  • Generation and search of domain mutations — uses dnstwist to create similar domains (typosquatting, homoglyphs, etc.) and verifies their existence through Netlas.
  • Subdomain search by brand — searches for subdomains of the brandname.* type at level 3-4, excluding legitimate top domains.
  • WHOIS verification — verifies registration data (organization, phone, email) with reference data.
  • Double checking of suspicious domains:
    • Detection of official images (based on links from the perimeter)
    • Search for keywords (brand terms) on the page
  • Criticality score — each domain gets a rank from Legitimate (0) to High (3).
  • A beautiful output to the console is a table with a color indication of danger (rich library).

Important

An active API key is required for the service Netlas.io (registration is free, but there are limits on the number of requests)

🚀 Installation

From source

#!/bin/bash
git clone https://github.com/your-org/fisher.git
cd fisher
pip install -r requirements.txt
python setup.py install

✨ Features

  • Generation and search of domain mutations — uses dnstwist to create similar domains (typosquatting, homoglyphs, etc.) and verifies their existence through Netlas.
  • Subdomain search by brand — searches for subdomains of the brandname.* type at level 3-4, excluding legitimate top domains.
  • WHOIS verification — verifies registration data (organization, phone, email) with reference data.
  • Double checking of suspicious domains:
    • Detection of official images (based on links from the perimeter)
    • Search for keywords (brand terms) on the page
  • Criticality score — each domain gets a rank from Legitimate (0) to High (3).
  • A beautiful output to the console is a table with a color indication of danger (rich library).

Important

An active API key is required for the service Netlas.io (registration is free, but there are limits on the number of requests)

🔧 Setting up

From source

Manual installation (PIP is recommended):

#!/bin/bash
pip install netlas dnstwist beautifulsoup4 requests rich

Tip

dnstwist may require the compilation of C extensions. If problems arise, install the dnstwist system package (for example, sudo apt install dnstwist), but the code uses the dnstwist.run() call, which the Python module expects. In this case, adaptation will be required.

📄 Preparation of the input JSON file (perimeter)

The tool accepts a JSON file with a description of the protected perimeter. An example is perimeter_example.json:

 {
"domains": ["pochtabank.ru", "pochtabank.phx.media"],
"topdomains": ["pochtabank.ru", "phx.media", "nalogia.ru"],
"brandnames": ["pochtabank", "pochta-bank", "postbank"],
"whois": {
"organisation": ["SC \"Post Bank\""]
},
"keywords": ["Почта Банк", "кредиты", "дебетовые", "карты", "вклады", "ипотека", "банк", "почта"],
"imglinks": [
"https://cdn.pochtabank.ru/_next/image?url=...background_2901_24.jpg"
]
}
FieldTypePurpose
domainslist of rowsThe organization's reference domains. Mutations (typos, substitutions) will be generated for them
topdomainslist of stringsValid "top" domains (for example, pochtabank.ru ). They are used to exclude legitimate subdomains during the search
brandnameslist of stringsBrand names (keywords for searching subdomains like brandname.*)
whoisobjectExpected registration data. The organization key (a list of strings) is supported, as well as phone and email (present in the code, but not in the example)
keywordslist of stringsWords and phrases specific to the official website (will be searched on suspicious pages)
imglinkslist of stringsAbsolute links to official images (for example, logos, banners). Their presence on the verified resource is checked

🚀 Launching

#!/bin/bash
python __main__.py -p <perimeter.json> -a <NETLAS_API_KEY>

At startup, an ASCII banner, the version, the name of the team, and the progress of the steps are displayed.

📊 Interpretation of criticality

The cout.print_domains() table converts a numeric value to a text level:

NumberLevelValue
0LegitimateRegistration data matched the reference → trusted domain
1LowWHOIS didn't match, but there are no official images or keywords on the page
2MediumWHOIS mismatch + one additional feature (image or keyword)
3HighWHOIS mismatch + both signs (image + keywords) → high probability of phishing

output_example

Note: The Critical level (4) is not reached in the current implementation, but is reserved in the code.

🐞 Possible errors and solutions

ErrorPossible causeSolution
ModuleNotFoundError: No module named "cout"Launch not from the root directory of the projectGo to the folder where __ is located main__.py, and execute python __main__.py
read error: File does not existIncorrect path to the JSON file is specifiedCheck the path, use absolute or relative correctly
dnstwist.run was not foundThe dnstwist package is not installed or is installed as a CLI utilityInstall via pip install dnstwist or adapt the code to invoke the system command
Netlas API key invalidInvalid or expired keyCheck the key in your Netlas account, create a new one
Failed connection with domainThe domain is not responding via HTTP/HTTPSCheck the availability of the domain in the browser. Some resources block bots
list index out of range in cout.print_domainswrong_domains contains values greater than 3 or non-numericCheck the source data: wrong_domains should be dict[domain, int]

🤝 License and authorship

The tool was developed by the Knights of the Round Table team. Version: 1.0.1#dev. The license is not specified in the source files, but it is intended to be used at the discretion of the authors (probably proprietary). When distributing, keep the title and the mention of authorship.

Caution

🐟 Phisher helps to detect digital threats and unauthorized resources in a timely manner. Use it as part of the perimeter monitoring process.

About

Development of tools for identifying resources such as “Phishing” and “Shadow IT”

Resources

Stars

3 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

PHISHER 🐠

Development of tools for identifying resources such as Phishing and Shadow-IT

Tool for detecting phishing resources and Shadow IT services in enterprise environments

🎯 Description

PHISHER is a command-line utility for automated detection of:

  • Phishing domains and pages — using signatures, trusted resource lists, SSL certificate analysis, and brand similarity checks.
  • Shadow IT — unauthorized cloud services, SaaS applications, unregistered subdomains, and third-party tools used within the company. The tool combines several methods: domain mutation generation, subdomain search by brand names, WHOIS data analysis, and image/keyword verification.

The tool combines several methods: domain mutation generation, subdomain search by brand names, WHOIS data analysis, and image/keyword verification.

✨ Features

  • Generation and search of domain mutations — uses dnstwist to create similar domains (typosquatting, homoglyphs, etc.) and verifies their existence through Netlas.
  • Subdomain search by brand — searches for subdomains of the brandname.* type at level 3-4, excluding legitimate top domains.
  • WHOIS verification — verifies registration data (organization, phone, email) with reference data.
  • Double checking of suspicious domains:
    • Detection of official images (based on links from the perimeter)
    • Search for keywords (brand terms) on the page
  • Criticality score — each domain gets a rank from Legitimate (0) to High (3).
  • A beautiful output to the console is a table with a color indication of danger (rich library).

Important

An active API key is required for the service Netlas.io (registration is free, but there are limits on the number of requests)

🚀 Installation

From source

#!/bin/bash
git clone https://github.com/your-org/fisher.git
cd fisher
pip install -r requirements.txt
python setup.py install

✨ Features

  • Generation and search of domain mutations — uses dnstwist to create similar domains (typosquatting, homoglyphs, etc.) and verifies their existence through Netlas.
  • Subdomain search by brand — searches for subdomains of the brandname.* type at level 3-4, excluding legitimate top domains.
  • WHOIS verification — verifies registration data (organization, phone, email) with reference data.
  • Double checking of suspicious domains:
    • Detection of official images (based on links from the perimeter)
    • Search for keywords (brand terms) on the page
  • Criticality score — each domain gets a rank from Legitimate (0) to High (3).
  • A beautiful output to the console is a table with a color indication of danger (rich library).

Important

An active API key is required for the service Netlas.io (registration is free, but there are limits on the number of requests)

🔧 Setting up

From source

Manual installation (PIP is recommended):

#!/bin/bash
pip install netlas dnstwist beautifulsoup4 requests rich

Tip

dnstwist may require the compilation of C extensions. If problems arise, install the dnstwist system package (for example, sudo apt install dnstwist), but the code uses the dnstwist.run() call, which the Python module expects. In this case, adaptation will be required.

📄 Preparation of the input JSON file (perimeter)

The tool accepts a JSON file with a description of the protected perimeter. An example is perimeter_example.json:

 {
"domains": ["pochtabank.ru", "pochtabank.phx.media"],
"topdomains": ["pochtabank.ru", "phx.media", "nalogia.ru"],
"brandnames": ["pochtabank", "pochta-bank", "postbank"],
"whois": {
"organisation": ["SC \"Post Bank\""]
},
"keywords": ["Почта Банк", "кредиты", "дебетовые", "карты", "вклады", "ипотека", "банк", "почта"],
"imglinks": [
"https://cdn.pochtabank.ru/_next/image?url=...background_2901_24.jpg"
]
}
FieldTypePurpose
domainslist of rowsThe organization's reference domains. Mutations (typos, substitutions) will be generated for them
topdomainslist of stringsValid "top" domains (for example, pochtabank.ru ). They are used to exclude legitimate subdomains during the search
brandnameslist of stringsBrand names (keywords for searching subdomains like brandname.*)
whoisobjectExpected registration data. The organization key (a list of strings) is supported, as well as phone and email (present in the code, but not in the example)
keywordslist of stringsWords and phrases specific to the official website (will be searched on suspicious pages)
imglinkslist of stringsAbsolute links to official images (for example, logos, banners). Their presence on the verified resource is checked

🚀 Launching

#!/bin/bash
python __main__.py -p <perimeter.json> -a <NETLAS_API_KEY>

At startup, an ASCII banner, the version, the name of the team, and the progress of the steps are displayed.

📊 Interpretation of criticality

The cout.print_domains() table converts a numeric value to a text level:

NumberLevelValue
0LegitimateRegistration data matched the reference → trusted domain
1LowWHOIS didn't match, but there are no official images or keywords on the page
2MediumWHOIS mismatch + one additional feature (image or keyword)
3HighWHOIS mismatch + both signs (image + keywords) → high probability of phishing

output_example

Note: The Critical level (4) is not reached in the current implementation, but is reserved in the code.

🐞 Possible errors and solutions

ErrorPossible causeSolution
ModuleNotFoundError: No module named "cout"Launch not from the root directory of the projectGo to the folder where __ is located main__.py, and execute python __main__.py
read error: File does not existIncorrect path to the JSON file is specifiedCheck the path, use absolute or relative correctly
dnstwist.run was not foundThe dnstwist package is not installed or is installed as a CLI utilityInstall via pip install dnstwist or adapt the code to invoke the system command
Netlas API key invalidInvalid or expired keyCheck the key in your Netlas account, create a new one
Failed connection with domainThe domain is not responding via HTTP/HTTPSCheck the availability of the domain in the browser. Some resources block bots
list index out of range in cout.print_domainswrong_domains contains values greater than 3 or non-numericCheck the source data: wrong_domains should be dict[domain, int]

🤝 License and authorship

The tool was developed by the Knights of the Round Table team. Version: 1.0.1#dev. The license is not specified in the source files, but it is intended to be used at the discretion of the authors (probably proprietary). When distributing, keep the title and the mention of authorship.

Caution

🐟 Phisher helps to detect digital threats and unauthorized resources in a timely manner. Use it as part of the perimeter monitoring process.

About

Development of tools for identifying resources such as “Phishing” and “Shadow IT”

Resources

Stars

3 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages