NoLimitSecu #512 - StalkPhish

NoLimitSecu #512 - StalkPhish

🎙 NoLimitSecu 👥 2K 📅 September 15, 2025 ⏱ 26 min 👁 173 📄 interview 🧭 2026-08-16
Available in: English (current) Français

Keywords

phishingStalkPhishthreat intelligenceopen sourcecybersecurity

Summary

In this episode of NoLimitSecu, host Hervé Chaur and co-hosts Nicolas Ruf and Vladimir Cola interview Thomas Damonneville, a cybersecurity expert with over 25 years of experience, about his project StalkPhish. Damonneville explains that StalkPhish is an open-source tool designed to collect and enrich phishing feeds, including phishing kits and their configurations. The project aims to understand phishing actors, their infrastructure, and exfiltration vectors. He details how StalkPhish uses certificate transparency logs and community-driven feeds like PhishTank to gather data. The tool can pivot on IP addresses, favicon hashes, and other artifacts to identify campaigns and actors. Damonneville also discusses the commercial version, StalkPhish.io, which offers more advanced features for threat intelligence professionals. He highlights the importance of analyzing phishing kits to extract configuration files that reveal Telegram bots, channels, and other exfiltration methods. The conversation covers countermeasures used by phishers, such as geofencing and user-agent filtering, and the challenges of bypassing them. Damonneville emphasizes the need to focus on actors rather than just taking down URLs, and mentions his collaboration with law enforcement. He concludes by encouraging listeners to support the project and engage in the fight against phishing.

190 words

Critical Evaluation

Value of the Information & Strength of the Argument

The interview provides valuable insights into the practical aspects of phishing intelligence, detailing the technical methods used to collect and analyze phishing kits. Damonneville’s argumentation is solid, based on his extensive experience and the concrete functionality of StalkPhish. He clearly explains the importance of pivoting on infrastructure and actors, and supports his claims with examples of how the tool works. The discussion is well-structured and informative, offering a realistic view of the phishing landscape.

83 words

Title / Content Match

The title accurately reflects the content, which focuses on the StalkPhish project and its role in phishing intelligence.

Quality & Reliability

8/10

The interview features a recognized expert in phishing intelligence, Thomas Damonneville, who provides detailed technical insights and references open-source projects and commercial services. The information is consistent with known cybersecurity practices, though it is primarily anecdotal and not peer-reviewed.

Key Moments

Cited Sources

Concurring Sources

  • PhishTank — Referenced as a source of phishing feeds.

Contribution & Novelties

The interview provides a unique perspective on phishing intelligence, emphasizing the importance of analyzing phishing kits and pivoting on infrastructure to identify actors. It offers practical insights into the tools and techniques used by threat intelligence professionals. The discussion highlights the evolving nature of phishing and the need for proactive measures.

Pour aller plus loin :

  • PhishTank — A community-driven platform for reporting and verifying phishing URLs, relevant to the feeds mentioned.
  • Certificate Transparency — The concept of logging SSL/TLS certificates, used by StalkPhish to discover phishing domains.
  • YARA Rules — A tool for pattern matching, used in the Phishing Kit Yara Rules project.

104 words

Radar Profile

The radar profile shows high scores in information quantity, quality, and reliability, with a slightly lower technical level, indicating a well-balanced and accessible discussion for a technical audience.

Reliability 8/10