Domain Abuse & Impersonation
Analysing a suspicious domain: generating the permutation space, reading registration and infrastructure signals, using Certificate Transparency as a detection channel, and classifying a finding before acting on it.
- lessons
- 18
- total
- 3 h
- level
- Intermediate
Assumes Domain Security Fundamentals.
You will be able to
- Describe the economics that make a lookalike cheap and effective
- Generate a permutation space and cut it to what is worth watching
- Read registration signals without mistaking privacy for guilt
- Escalate on infrastructure signals, and say which one matters most
- Use Certificate Transparency as a detection channel and state its limits
- Classify a domain into one of four outcomes and defend the classification
- Account for the cost of each misclassification, in both directions
Syllabus
1. The Economics
What a lookalike costs an attacker, and the lifecycle of one from registration to abandonment.
2. The Permutation Space
Generating every variant, cutting it to what matters, and the deception that needs no registration.
3. Registration Signals
Age, registrar, privacy and reuse — what each is worth and what it is not.
4. Infrastructure Signals
The MX that changes everything, hosting patterns, and what passive DNS adds.
5. Certificates as a Channel
Reading a log entry, and the volume problem that makes CT hard to use well.
6. Classifying a Finding
Four outcomes, how to rank them, and what each misclassification costs.
7. What Detection Misses
The impersonation no monitoring finds, and the false-positive cost nobody budgets for.
8. Final assessment
15 scenario questions · 80% to pass · unlimited retakes
What the assessment covers
Domain Impersonation Analyst
- Complete every lesson in Domain Abuse & Impersonation
- Pass the Domain Abuse & Impersonation assessment with at least 80%
CertaDNS Engineering · last reviewed