Back
Idb6e26c67-f596-5c0f-8614-c88d715508c5
RulenameWhisper Security - Domain Registrar Change Anomaly
DescriptionDetects domains whose registrar has changed across WHOIS history snapshots within the last 30 days. Registrar changes may indicate domain hijacking or adversary infrastructure acquisition.
SeverityMedium
TacticsResourceDevelopment
TechniquesT1584
Required data connectorsWhisperSecurityConnector
KindScheduled
Query frequency1h
Query period14d
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Whisper/Analytic%20Rules/DomainRegistrarChangeAnomaly.yaml
Version1.0.0
Arm templateb6e26c67-f596-5c0f-8614-c88d715508c5.json
Deploy To Azure
// MITRE ATT&CK: T1584 - Compromise Infrastructure
// Tactic: Resource Development
// Detects registrar changes across WHOIS history snapshots
let lookbackPeriod = 14d;
WhisperHistory_CL
    | where TimeGenerated > ago(lookbackPeriod)
    | where indicatorType == "domain"
    | where isnotempty(registrar)
    | summarize Registrars = make_set(registrar), SnapshotCount = count(), EarliestSnapshot = min(snapshotDate), LatestSnapshot = max(snapshotDate) by indicator
    | where array_length(Registrars) > 1
    | mv-expand CurrentRegistrar = Registrars
    | extend CurrentRegistrar = tostring(CurrentRegistrar)
    | join kind=inner (
        WhisperHistory_CL
        | where TimeGenerated > ago(lookbackPeriod)
        | where indicatorType == "domain"
        | where isnotempty(registrar)
        | serialize
        | extend PreviousRegistrar = prev(registrar), PreviousIndicator = prev(indicator)
        | where indicator == PreviousIndicator
        | where registrar != PreviousRegistrar
        | where isnotempty(PreviousRegistrar)
        | project indicator, OldRegistrar = PreviousRegistrar, NewRegistrar = registrar, ChangeDate = snapshotDate
    ) on indicator
    | project TimeGenerated = ChangeDate, DnsDomain = indicator, OldRegistrar, NewRegistrar, ChangeDate, SnapshotCount
    | distinct TimeGenerated, DnsDomain, OldRegistrar, NewRegistrar, ChangeDate, SnapshotCount
incidentConfiguration:
  groupingConfiguration:
    lookbackDuration: PT5H
    reopenClosedIncident: false
    matchingMethod: AllEntities
    enabled: true
  createIncident: true
name: Whisper Security - Domain Registrar Change Anomaly
triggerOperator: gt
query: |
  // MITRE ATT&CK: T1584 - Compromise Infrastructure
  // Tactic: Resource Development
  // Detects registrar changes across WHOIS history snapshots
  let lookbackPeriod = 14d;
  WhisperHistory_CL
      | where TimeGenerated > ago(lookbackPeriod)
      | where indicatorType == "domain"
      | where isnotempty(registrar)
      | summarize Registrars = make_set(registrar), SnapshotCount = count(), EarliestSnapshot = min(snapshotDate), LatestSnapshot = max(snapshotDate) by indicator
      | where array_length(Registrars) > 1
      | mv-expand CurrentRegistrar = Registrars
      | extend CurrentRegistrar = tostring(CurrentRegistrar)
      | join kind=inner (
          WhisperHistory_CL
          | where TimeGenerated > ago(lookbackPeriod)
          | where indicatorType == "domain"
          | where isnotempty(registrar)
          | serialize
          | extend PreviousRegistrar = prev(registrar), PreviousIndicator = prev(indicator)
          | where indicator == PreviousIndicator
          | where registrar != PreviousRegistrar
          | where isnotempty(PreviousRegistrar)
          | project indicator, OldRegistrar = PreviousRegistrar, NewRegistrar = registrar, ChangeDate = snapshotDate
      ) on indicator
      | project TimeGenerated = ChangeDate, DnsDomain = indicator, OldRegistrar, NewRegistrar, ChangeDate, SnapshotCount
      | distinct TimeGenerated, DnsDomain, OldRegistrar, NewRegistrar, ChangeDate, SnapshotCount
queryFrequency: 1h
description: |
  Detects domains whose registrar has changed across WHOIS history snapshots within the last 30 days. Registrar changes may indicate domain hijacking or adversary infrastructure acquisition.
id: b6e26c67-f596-5c0f-8614-c88d715508c5
triggerThreshold: 0
queryPeriod: 14d
version: 1.0.0
kind: Scheduled
customDetails:
  ChangeDate: ChangeDate
  OldRegistrar: OldRegistrar
  NewRegistrar: NewRegistrar
status: Available
severity: Medium
requiredDataConnectors:
- connectorId: WhisperSecurityConnector
  dataTypes:
  - WhisperHistory_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Whisper/Analytic%20Rules/DomainRegistrarChangeAnomaly.yaml
relevantTechniques:
- T1584
tactics:
- ResourceDevelopment
entityMappings:
- fieldMappings:
  - identifier: DomainName
    columnName: DnsDomain
  entityType: DNS
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/b6e26c67-f596-5c0f-8614-c88d715508c5')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/b6e26c67-f596-5c0f-8614-c88d715508c5')]",
      "properties": {
        "alertRuleTemplateName": "b6e26c67-f596-5c0f-8614-c88d715508c5",
        "customDetails": {
          "ChangeDate": "ChangeDate",
          "NewRegistrar": "NewRegistrar",
          "OldRegistrar": "OldRegistrar"
        },
        "description": "Detects domains whose registrar has changed across WHOIS history snapshots within the last 30 days. Registrar changes may indicate domain hijacking or adversary infrastructure acquisition.\n",
        "displayName": "Whisper Security - Domain Registrar Change Anomaly",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "DNS",
            "fieldMappings": [
              {
                "columnName": "DnsDomain",
                "identifier": "DomainName"
              }
            ]
          }
        ],
        "incidentConfiguration": {
          "createIncident": true,
          "groupingConfiguration": {
            "enabled": true,
            "lookbackDuration": "PT5H",
            "matchingMethod": "AllEntities",
            "reopenClosedIncident": false
          }
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Whisper/Analytic%20Rules/DomainRegistrarChangeAnomaly.yaml",
        "query": "// MITRE ATT&CK: T1584 - Compromise Infrastructure\n// Tactic: Resource Development\n// Detects registrar changes across WHOIS history snapshots\nlet lookbackPeriod = 14d;\nWhisperHistory_CL\n    | where TimeGenerated > ago(lookbackPeriod)\n    | where indicatorType == \"domain\"\n    | where isnotempty(registrar)\n    | summarize Registrars = make_set(registrar), SnapshotCount = count(), EarliestSnapshot = min(snapshotDate), LatestSnapshot = max(snapshotDate) by indicator\n    | where array_length(Registrars) > 1\n    | mv-expand CurrentRegistrar = Registrars\n    | extend CurrentRegistrar = tostring(CurrentRegistrar)\n    | join kind=inner (\n        WhisperHistory_CL\n        | where TimeGenerated > ago(lookbackPeriod)\n        | where indicatorType == \"domain\"\n        | where isnotempty(registrar)\n        | serialize\n        | extend PreviousRegistrar = prev(registrar), PreviousIndicator = prev(indicator)\n        | where indicator == PreviousIndicator\n        | where registrar != PreviousRegistrar\n        | where isnotempty(PreviousRegistrar)\n        | project indicator, OldRegistrar = PreviousRegistrar, NewRegistrar = registrar, ChangeDate = snapshotDate\n    ) on indicator\n    | project TimeGenerated = ChangeDate, DnsDomain = indicator, OldRegistrar, NewRegistrar, ChangeDate, SnapshotCount\n    | distinct TimeGenerated, DnsDomain, OldRegistrar, NewRegistrar, ChangeDate, SnapshotCount\n",
        "queryFrequency": "PT1H",
        "queryPeriod": "P14D",
        "severity": "Medium",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "ResourceDevelopment"
        ],
        "techniques": [
          "T1584"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}