All drills

Phishing & Malicious-URL Detector

What you'll be able to do

Build the brain of an SMS/URL firewall — score a link as safe or phishing in real time, the way Google Safe Browsing, Proofpoint, and Cloudflare protect billions of users.

The engine behind safe-browsing and anti-phishing filters — Google Safe Browsing, Microsoft Defender, Proofpoint, Cloudflare — and the SMS/link firewalls telecom operators run.
Start this internship
Create an account to unlock the 10 sections, the workbench, and AskThili.
Begin

Sections

1. Building a Phishing and Malicious-URL Detector
🔒 locked
2. Lesson 1 - The problem & the data
🔒 locked
3. Lesson 2 - Read a URL like an attacker
🔒 locked
4. Lesson 3 - A baseline & why accuracy lies
🔒 locked
5. Lesson 4 - Naive Bayes from scratch
🔒 locked
6. Lesson 5 - Train / test — the honest score
🔒 locked
7. Lesson 6 - Tuning the threshold
🔒 locked
8. Lesson 7 - Production classifier
🔒 locked
9. Lesson 8 - What the model learned & evasion
🔒 locked
10. Lesson 9 - The phishing detector (ship it)
🔒 locked

Dig deeper

📄Beyond Blacklists: Learning to Detect Malicious Web Sites from Suspicious URLs (Ma, Saul, Savage & Voelker, 2009, KDD)
paper
🔗scikit-learn — Text feature extraction and classification
docs
🔗PhishTank — a live community feed of verified phishing URLs
docs

Part of these learning paths

I'm a security professional and I want to test AI/ML systems for vulnerabilities
View path →