Skip to content
ForgeSynapse

London, UK

ForgeSynapsePhishNetIn development

PhishNet: sharing threat intelligence with people you have no reason to trust

Two organisations both being attacked by the same campaign have every reason to warn each other, and no shared infrastructure to do it through. That gap is where most of the damage happens.

Threat intelligence has a coordination problem. The indicators that would let one organisation block an attack are usually already sitting in another organisation’s logs. Getting them from one to the other requires either a shared platform both parties already run, or a level of mutual trust that frequently does not exist — between competitors, across borders, or in any ad-hoc grouping formed faster than procurement moves.

PhishNet is built for exactly that situation: validating, recording and sharing indicators of compromise between parties with no shared infrastructure and no prior trust. The design premise is that trust should not be a prerequisite for cooperation. What is required instead is that every action be attributable and every record be tamper-evident.

Every request is recorded in an append-only ledger where each entry is cryptographically chained to the one before it. Deleting an entry, reordering entries or altering one after the fact all break the chain, and the break is detectable by anyone with access to the ledger. Access itself is governed by explicit capabilities rather than broad roles: an account can register an indicator, or read the audit trail, or run a detection, and each of those is granted separately.

It is also deliberately light. Existing platforms in this space tend to be heavy to deploy and assume good connectivity — which is fine for a corporate SOC and useless in the environments where sharing matters most: sovereign deployments, ad-hoc coalitions, low-bandwidth conditions and anywhere a full platform rollout is slower than the attack.

The honest state of it: the system runs end to end and has been exercised against real phishing data, but the validation set is small, there is no formal false-positive benchmark yet, and it has run in a controlled local environment rather than with real users in the field. It sits at the point where the components work and the evidence that they work at scale does not exist yet. Both of those things are true at once, and only saying the first would be marketing.

← All entries