Hunting Phish Kits

DerbyCon 9.0 - Finish Line

Presented by: Josh Rickard
Date: Saturday September 07, 2019
Time: 15:00 - 15:30
Location: Stable Talks

New phishing websites are setup every few seconds with intentions on stealing your credentials, infecting your system, or convincing you via social engineering. Most of these sites are distributed and deployed through (mostly crude) automation which usually results in attackers leaving their kits behind. During this talk we will walk through what phish kits are, why they are important for security research, and how you can automate identifying these kits in the wild.

Josh Rickard

Josh Rickard serves as a security research engineer at Swimlane. He is a GIAC Certified Windows Security Administrator (GCWN) and GIAC Certified Forensic Analyst (GCFA). He has a diverse background ranging from system administration to digital forensics and incident response to managing teams and products. As a Windows security expert, Josh focuses on creating tools to help defend and automate everyday processes using PowerShell and Python. You can engage with Josh via his blog,, or Twitter at @MSAdministrator.

KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats