What does 'Newly-Activated Subdomain' mean in DNS-layer or SOC analysis?
It indicates that one or more subdomains under a given domain have recently become active or resolvable in DNS. This pattern often occurs in malicious infrastructures that dynamically generate subdomains to evade blacklists or conduct phishing and command-and-control operations.