CertaDNS

Domain Abuse & Impersonation

Analysing a suspicious domain: generating the permutation space, reading registration and infrastructure signals, using Certificate Transparency as a detection channel, and classifying a finding before acting on it.

lessons
18
total
3 h
level
Intermediate

Assumes Domain Security Fundamentals.

You will be able to

  • Describe the economics that make a lookalike cheap and effective
  • Generate a permutation space and cut it to what is worth watching
  • Read registration signals without mistaking privacy for guilt
  • Escalate on infrastructure signals, and say which one matters most
  • Use Certificate Transparency as a detection channel and state its limits
  • Classify a domain into one of four outcomes and defend the classification
  • Account for the cost of each misclassification, in both directions

Syllabus

  1. 1. The Economics

    What a lookalike costs an attacker, and the lifecycle of one from registration to abandonment.

    1. The attacker’s arithmetic11 min
    2. The lifecycle of a phishing domain11 min
  2. 2. The Permutation Space

    Generating every variant, cutting it to what matters, and the deception that needs no registration.

    1. Generating the space12 min
    2. Cutting it to what matters11 min
    3. Deception that needs no registration11 min
  3. 3. Registration Signals

    Age, registrar, privacy and reuse — what each is worth and what it is not.

    1. Age and timing10 min
    2. Privacy is not guilt10 min
    3. Reuse across a set11 min
  4. 4. Infrastructure Signals

    The MX that changes everything, hosting patterns, and what passive DNS adds.

    1. The MX that changes everything11 min
    2. Hosting patterns10 min
    3. What passive DNS adds10 min
  5. 5. Certificates as a Channel

    Reading a log entry, and the volume problem that makes CT hard to use well.

    1. Reading a log entry11 min
    2. The volume problem11 min
  6. 6. Classifying a Finding

    Four outcomes, how to rank them, and what each misclassification costs.

    1. Four outcomes12 min
    2. Ranking a queue11 min
    3. The cost of being wrong11 min
  7. 7. What Detection Misses

    The impersonation no monitoring finds, and the false-positive cost nobody budgets for.

    1. What monitoring cannot see11 min
    2. The failure mode nobody budgets for10 min
  8. 8. Final assessment

    15 scenario questions · 80% to pass · unlimited retakes

    What the assessment covers

Domain Impersonation Analyst

  • Complete every lesson in Domain Abuse & Impersonation
  • Pass the Domain Abuse & Impersonation assessment with at least 80%
About the certificates

CertaDNS Engineering · last reviewed