Thirdshift
Mar 20th, 2026

The Domain Lifecycle Problem in Threat Hunting

Threat Hunting

New domains in cybersecurity are often viewed with suspicion because they lack history and frequently appear in early detections. However, many new domains are benign, and malicious domains often do not remain active long enough for thorough analysis.

This creates a core challenge for analysts: domains are dynamic, not static indicators. Recognizing their evolution and its impact on detection and response is essential for effective threat hunting.

The Problem with “Point-in-Time” Thinking

Traditional security workflows often ask, “Is this domain malicious right now?” This approach is limited in scope. Threat actors exploit the delay between domain registration, detection, and enforcement. A domain may appear benign at first, become malicious within hours, and disappear once detected. By the time it is widely flagged, the attacker has already moved on.

This creates an asymmetry:

  • Defenders rely on historical and consensus-based reputation.
  • Attackers rely on speed, scale, and short-lived infrastructure.

As a result, point-in-time analysis often misses broader trends.

New Domains Are Frequently Abused

Newly registered domains are attractive to attackers because they have no reputation history, are not flagged by security vendors, and enable instant infrastructure deployment.

  • Immediate usability - Attackers can deploy infrastructure within minutes.
  • Short lifespan - Domains are often discarded quickly, limiting exposure.

Phishing, malware delivery, and command-and-control commonly use domains that are only hours or days old. However, “new” means uncertainty, not necessarily maliciousness—uncertainty that attackers exploit.

Domain Agility: The Attacker Advantage

Modern adversaries rarely rely on a single domain. Instead, they use domain agility, frequently shifting their infrastructure through rapid domain registration, frequent DNS changes, infrastructure rotation, and reuse of shared components such as TLS certificates. They also quickly abandon assets once detected. Some malware families automate this process, generating many potential domains, though only a few become active. This approach creates a moving target, fragments intelligence, and complicates tracking.

The Challenge of DNS and Reputation Volatility

DNS data and reputation systems are dynamic and often inconsistent. A single domain may be classified differently by various vendors and can shift from newly registered to suspicious or malicious within hours. Domains may also resolve to multiple IP addresses in different regions or providers, sharing infrastructure with both benign and malicious domains. Automated TLS certificate issuance further complicates detection, as attackers can quickly make their domains appear legitimate.

This volatility creates significant blind spots throughout a threat's lifecycle. Early-stage threats often seem harmless, mid-stage threats generate conflicting signals, and late-stage threats are usually detected too late to prevent substantial damage.

Domains as Lifecycle, Not Indicators

To address this, it is more effective to view domains as entities with a lifecycle rather than as static indicators. A typical lifecycle includes:

  • Emerging - These are newly observed domains with minimal context. While they typically do not generate alerts, they may still pose a risk due to their novelty and lack of established behavior.
  • Suspicious - Weak signals emerge, such as unusual DNS behavior, sandbox detections, or low-confidence classifications.
  • Active Threat - The domain is now confirmed to be used for malicious activity, such as phishing, malware distribution, or command-and-control operations. Evidence and consensus clearly assign malicious intent.
  • Burned - The domain, having been widely detected and blocked by security vendors, is no longer considered effective by attackers. Its malicious activity is broadly recognized, reducing its threat.
  • Dormant / Retired - The domain has stopped active operations. However, it remains relevant for historical analysis, attribution, and the recognition of future patterns or connections. Its past lifecycle provides valuable context for threat intelligence.

Key Questions for Effective Investigation

To evaluate a domain effectively, analysts must go beyond basic reputation checks and consider deeper, time-aware questions:

  • What is the domain’s age, and how has its reputation changed over time?
  • Has its classification shifted across security vendors?
  • Does it have a valid TLS certificate, and is that certificate shared with other domains?
  • Is the domain linked to known incidents, campaigns, or threat actors?
  • Is it currently active, or has it already been abandoned?

These questions help build context not only about the domain itself but also its role within a broader campaign.


Send a Scribble

Opening note…