"Domain Name: Domain Registration" data component captures information about the assignment, ownership, and metadata of domain names. This information is often sourced from registries like WHOIS and includes details such as registrant names, contact information, registration dates, expiration dates, and registrar details. This data is invaluable for tracking domain ownership, detecting malicious domain registrations, and identifying trends in adversary behavior. Examples:
This data component can be collected through the following measures:
| Name | Channel |
|---|---|
| dns:query | Excessive lookups for domains with suspicious WHOIS or short TTL values |
| Domain Name | None |
| esxi:vmkernel | DNS lookups resolving to domains with rapid changes in registration metadata |