Skip to content
Notifications
Clear all

How reliable is the phishing kit detection? Need real-world feedback.

3 Posts
3 Users
0 Reactions
1 Views
(@cloud_ops_learner)
Reputable Member
Joined: 2 months ago
Posts: 182
Topic starter   [#22449]

I’m looking into Recorded Future for our AWS environment, specifically to help with threat intelligence. I keep hearing about their phishing kit detection module.

For anyone using it: how reliable is it in practice? Does it catch things early enough to actually prevent phishing campaigns? I’m curious about false positives too—does it flood you with alerts, or is it pretty accurate?

Just trying to figure out if it’s worth the budget compared to other built-in AWS services or other vendors. Real-world experiences would be super helpful!


Still learning


   
Quote
(@georgep)
Trusted Member
Joined: 2 weeks ago
Posts: 63
 

Reliability depends heavily on how you define "early enough." It can identify kits and infrastructure being staged, but whether that's before they're used against your domain is the real question. In my experience, the detection is technically accurate, but the actionable intelligence often arrives too late for prevention. You're looking at containment, not true prevention.

Regarding false positives, it's not noise in the sense of bad alerts, but you will get a steady stream of notifications about threats that aren't directly targeting you. You need a team or process to triage that external intelligence into something operational for your AWS environment.

Compared to built-in AWS services, you're paying for a different layer. GuardDuty isn't doing this. You're buying external threat intel. Compared to other vendors, their coverage is broad, but the value is in integration. If you aren't feeding these findings directly into your security automation to block or alert, you're just paying for a scary news feed.


— geo


   
ReplyQuote
(@harryj)
Estimable Member
Joined: 2 weeks ago
Posts: 121
 

You nailed it with the "containment, not prevention" point. That's exactly the operational reality I've seen.

It feeds our SOAR well. When we get a kit alert tied to a new domain, it auto-creates a ticket and adds indicators to our blocklists. That's where the value is. Without that automation pipeline, you're just watching a dashboard.

The intel on infrastructure being staged is solid, but like you said, timing is everything. We've caught a few before they launched, but mostly we're blocking the first wave of emails faster.


Automate the boring stuff.


   
ReplyQuote