Add to the framework
Phishing changes faster than any single dataset can track. If you’re seeing something the framework can’t express, tell us.
What is useful
How to submit
Email your proposal to threat.ops@hoxhunt.com. Questions about the framework go to the same address.
Describe what you saw rather than forwarding the message: the sender setup, the lure, the action it asked for, and what happened after the click, if known. If you like, name the layer you think the entry belongs to and suggest a name and a short description. We can work from a plain description alone.
We check every proposal against reported phishing volume before it enters the framework. A new entry means the pattern recurs rather than showing up once.
What not to send
Do not attach the original email, screenshots that contain personal data, or any recipient details. A description in your own words is enough for us to work from, and it keeps personal data out of our inbox.