PhiShark 2026 · Access policy

Research access conditions

The dataset is available through a controlled academic access process designed to protect researchers, observed infrastructure, and the integrity of resulting work. Approved applicants must complete a PhiShark Data Use Agreement before access is granted.

Academic and nonprofit useManual review requiredSigned Data Use Agreement

1. Eligibility and permitted purpose

Access may be granted to verified university students, faculty, academic staff, and researchers employed by a verifiable nonprofit research organization. Use is limited to the non-commercial research project described in the approved Google Form application.

For-profit organizations, commercial product development, client work, paid threat-intelligence enrichment, resale, and any use intended to create direct or indirect commercial advantage are not permitted.

2. Project-specific access

Approval applies only to the named applicant, approved collaborators, institution, and project. Access may not be transferred. New collaborators or a material change in research purpose requires a new request or written approval.

3. Secure handling

  • Store the archive in an isolated, access-controlled research environment.
  • Do not execute captured files or load captured pages in an unrestricted browser.
  • Do not visit live targets, submit forms, authenticate, probe, scan, or contact observed systems or individuals.
  • Do not use the dataset to facilitate phishing, impersonation, credential collection, unauthorized access, or evasion.
  • Delete local and derived sensitive copies when the approved project ends or access is revoked.

4. No redistribution

The archive, scan packages, captured artifacts, and substantially reconstructable subsets may not be mirrored, republished, uploaded to public repositories, or shared with unapproved people. Publications should report aggregate findings and avoid exposing live harmful content.

5. Responsible interpretation

Labels and observations are research data, not legal determinations. Hosting provider, country, registrar, ASN, certificate authority, or infrastructure association must not be treated as proof of responsibility or malicious intent.

6. Review and revocation

Submitting the Google Form does not guarantee access. PhiShark may request verification, refuse a request, or revoke access when eligibility, security, research integrity, or compliance concerns arise.

7. Data Use Agreement and contact

Applicants approved after manual review are provided with a PhiShark Data Use Agreement. Dataset access is granted only after the agreement has been reviewed, signed, and returned. The executed agreement governs the approved project, permitted users and uses, secure handling, retention and deletion, non-redistribution, and suspension or revocation of access.

Questions may be directed to [email protected].