📜 PhishAID Rule Framework

🟢 Category A — URL & Transport

Rule NoDescription
1HTTPS usage check
2Raw IP address detection
3URL length analysis
4@ symbol detection
5Subdomain depth
6Suspicious TLD detection
7Certificate age check
8Hyphen usage
9URL shorteners
10Login keywords

🟡 Category B — Identity Deception

Rule NoDescription
21Unicode / Homoglyph detection
22Typosquatting detection

🔵 Category C — Structural Anomaly

Rule NoDescription
18 Clone phishing (DOM similarity heuristic)
28 Clipboard hijacking detection (L1/L2 behavioural analysis)

🔴 Category D — Semantic Intent

Rule NoDescription
30Semantic phishing intent detection

⚙️ Future Rules (Not Yet Implemented)

Rules 11–17, 19, 20, 23, 24, 25, 27 and 29 are part of the extended PhishAID framework. These require advanced techniques such as machine learning, behavioral analysis, and external threat intelligence APIs.