![Image 1 — [Project Update] The Open-Source Antiphishing CTI just hit 1,000+ active deployments. Now, we need to talk about scaling the infrastructure](https://preview.redd.it/78dtaq7zadkh1.png?width=403&format=png&auto=webp&s=1f9894079a0080b703265386b0769baf0c2d3bf5)
![Image 2 — [Project Update] The Open-Source Antiphishing CTI just hit 1,000+ active deployments. Now, we need to talk about scaling the infrastructure](https://preview.redd.it/mjclpdekbdkh1.png?width=377&format=png&auto=webp&s=f4388c1cca9fa547f55a2bbbcd0cf1462d91beb0)
[Project Update] The Open-Source Antiphishing CTI just hit 1,000+ active deployments. Now, we need to talk about scaling the infrastructure
Hey everyone,
A couple of weeks ago, I shared the Antiphishing CTI Ruleset here - a completely free, GPLv3 predictive threat intelligence engine focused on Newly Registered Domains (NRDs) for Suricata, on OPNsense.
The community response was insane. Looking at the repo metrics, we just crossed 1,000+ active automated deployments in the last 14 days. It’s amazing to see so many of you integrating this into your perimeters.
The Architectural Challenge (Why I’m posting this):
Right now, the Python heuristic core is ingesting, deduplicating, and correlating over 1.5 Million raw threat vectors and NRDs daily. We are filtering the noise from public OSINT to generate high-fidelity, aggressive blocklists.
The problem is: the math of cloud infrastructure is catching up. Processing this volume and querying historical WHOIS/Passive DNS APIs requires serious compute power. We are starting to hit rate limits on our enrichment APIs.
The Corporate Sponsorship Open Call:
To be clear: The core ruleset is, and will always be, 100% free and open-source for homelabbers and the community. I hate paywalled security feeds.
However, I know many of you are running this in production MSSPs, SOCs, and ISPs, saving thousands of dollars on commercial threat feeds.
If your business relies on this engine, I am officially opening GitHub Sponsors tiers for Corporate Partners. This isn't a donation; it's funding for the cloud nodes and API keys that keep the intelligence flowing.
What businesses get in return:
- Priority SLA (8h - 24h): If my aggressive heuristics block a legitimate domain (False Positive) on your client's network, you get a direct VIP queue for immediate whitelisting and rule tuning.
- access to the maintainer (me) for specific architectural questions.
- Direct
If your company can support the project, check out the GitHub Sponsors page here: https://github.com/sponsors/julioliraup
Thanks again to everyone testing, reporting FPs, and helping the ruleset get better. The fight against day-zero phishing continues!