Skip to content
/ IOK Public
forked from phish-report/IOK

IOK (Indicator Of Kit) is an open source ruleset of phishing threat actor tools and tactics

License

Notifications You must be signed in to change notification settings

mattreduce/IOK

 
 

Repository files navigation

IOK logo

Screenshot of one of the IOK indicator rules

Open source detection rules for phishing site techniques, kits, and threat actors 🕵️

  • Simple: based on Sigma, a simple detection rules language 🚀
  • Rich metadata: rules have descriptions, tags, and links to blog posts or related rules.

Use cases:

📝 Creating indicators

IOK indicators are written using Sigma

Field name Type Description
html string The contents of the page HTML (as returned by the server)
js []string Contents of JavaScript from the page (includes inline scripts as well as scripts loaded externally)
css []string Contents of CSS from the page (includes inline stylesheets as well as externally loaded stylesheets)
cookies []string Cookies from the page. Each is in the form cookieName=value
headers []string Headers sent by the server. Each is in the form Header-Name: value
requests []string URLs of requests made by the page (and assets loaded by the page)

We are always looking for contributions—there's far more phishing kits and techniques than a single team can analyse!

To contribute a new rule:

  1. Try to make sure it doesn't already exist
  2. Open a pull request, adding your new file in the indicators/ folder
  3. We'll review it and merge your PR
  4. It'll go live on phish.report/IOK!

💭 Comparison to similar projects

IOK PhishingKit-Yara-Rules Wappalyzer
Open Source
Ruleset size > 190 Rules 🦐 > 450 rules 🐠 1000s of rules 🐳
Can scan Live websites 🕸 Phishing kit zips 📦 Live websites 🕸
Phishing focused
Supports complex conditions
Sends out stickers to contributors 🎁

🤝 Contributing

Documentation on how to write a rule is coming soon...

📝 License

This project is ODbL licensed. You're free to use the rules in your own projects (including commercial ones!) as long as you credit phish.report/IOK as the source.

For more details, read OpenStreetMap's guidance (who also use the ODbL license).

About

IOK (Indicator Of Kit) is an open source ruleset of phishing threat actor tools and tactics

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • Go 100.0%