Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Gone Phishin’ – Q&A with Tim Helming, Director Of Product Management, DomainTools
Articles

Gone Phishin’ – Q&A with Tim Helming, Director Of Product Management, DomainTools

ISBuzz TeamBy ISBuzz TeamNovember 8, 20164 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
phishing
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

What sparked the need for solution specific to hunting for phishing activity, a once very manual/time intensive process?

All too often, the first alert that organizations get about a phishing attempt or campaign is the phishing email itself. That’s definitely not the alerting system you want! PhishEye is designed to help the organization get ahead of phishing attempts, moving from a reactive posture to a preventive one. By identifying domains that are crafted to imitate legitimate domains as soon as they come into existence, PhishEye helps the security team create custom blacklists based specifically on the keywords that matter the most to them–typically their company name or brand names.

How does PhishEye work and who within an enterprise will be using the technology?

Phishing depends on domains, so if you can identify and block the domains in question, you disrupt the attack. PhishEye takes keywords that the user inputs, such as a company domain name or brand name, and generates a list of possible variants of that keyword. The variants include typos (such as domaint00ls, and many other ‘species’ of morphed spelling) and substring inclusions (such as domaintoolsaccount). Then PhishEye searches our database of around 315 million current domains to identify offending domains that exist. Finally, and perhaps most importantly, the user can set up alerts so that they get notified when PhishEye discovers new matching domains. They can take these names and create custom blacklists to deny the phishing traffic, whether that comes in the form of the “from” domain in the phish, or a malicious link, or both. PhishEye users are typically SOC analysts, or security team members who perform “SOC-like functions” in organizations that don’t have a formal SOC.

As cyber criminals become increasingly sophisticated, it seems almost daily that you hear about a “successful” phishing incident. What can and should companies do to mitigate risk (educate staff, leverage solutions, etc.)?

It has to be a blend of tools and processes. Education is definitely a key part of this. Organizations should weave security awareness into the very fabric of their culture. It shouldn’t be an add-on. Poorly trained employees can be a real liability, but well-trained ones can be a sensor network that helps the security team discover badness early in its progress. As far as tools go, email and web filters can certainly cut down on the noise, but one of the reasons we think predictive domain-based prevention like PhishEye is so valuable is because many spear phishes/BEC emails are custom-crafted–so they may not be picked up by reputation/blacklist services that rely on observing the emails in the wild, or on heuristics that could miss a one-off, unique email.

What do you believe makes phishing scams so successful and how will this impact business in the next year?

Phishing attacks are a form of social engineering, and they prey on human traits and habits such as pattern recognition (our brains turn close typos into the real thing sometimes), trust (some spearphishers do a lot of homework to create a very convincing impersonation of a colleague or boss), and distraction. That adds up to people clicking things they shouldn’t. And the phishes with the highest potential for single-event harm–BEC or similar targeted spear phishes–are often done very skillfully. Phishers are skilled at evading technological as well as human filtering mechanisms. APWG finds huge increases in the numbers of phishing domains, so it’s clear that attack rates are going to climb. If enterprises’ catch rates don’t increase at a higher rate than the attacks, then the successes will mount. The good news is that I think enterprises have a chance to drive their successful catch rates up through a combination of training, filtering tools, and alerting tools such as PhishEye.

What other types of malicious cyber activity will enterprises be faced with in 2017?

Certainly the familiar strains of malware and non-malware-based attacks will continue. It’s easy (and interesting) to get caught up in extreme hacking techniques like extracting data based on listening to CPU fan speed fluctuations, but it’s the basics, such as phishing, ransomware, botnet-based DDoS, etc., that are likely to cause the most harm. Personally, I’m intrigued by the idea of attacks that are designed to destabilize systems and undermine trust–not by making one big catastrophic strike, but by making a series of small disruptions or anomalies that cause an enterprise to lose trust in the integrity of their systems overall. This could potentially create various kinds of openings for other exploits.

[su_box title=”About ” style=”noise” box_color=”#336588″][short_info id=’84617′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}