Skip to content

Domain Ownership Transition in Last Month

It indicates that the WHOIS ownership or registrant details of a domain have recently changed. Such transitions may occur legitimately (brand migration or registrar updates) or maliciously (expired-domain reuse, reputation hijacking, or stealth acquisition).

Also surfaces as:
Domain Ownership Transition in Last 3 MonthsDomain Ownership Transition in Last YearDomain Ownership Transition in Last 1+ Years
Analyst Q&A

What this signal answers

Three questions every analyst asks before acting on this signal.

What it detects01

What does 'Domain Ownership Transition' mean in threat intelligence context?

It indicates that the WHOIS ownership or registrant details of a domain have recently changed. Such transitions may occur legitimately (brand migration or registrar updates) or maliciously (expired-domain reuse, reputation hijacking, or stealth acquisition).

Why it matters02

Why is a recent ownership transition a risk indicator?

Because attackers often acquire previously legitimate or dormant domains and repurpose them for malicious use, benefiting from their prior reputation. A sudden WHOIS ownership transition without consistent DNS, SSL, or content history continuity is considered suspicious.

How analysts use it03

How should SOC or CTI teams handle this indicator?

Analysts should correlate WHOIS transitions with infrastructure changes such as new name servers, SSL re-issuance, or IP migrations. Unexpected transitions, especially in high-value or previously trusted domains, should be flagged for deeper investigation.

Often paired with:alert_only
Evidence shape

What Domain Ownership Transition in Last Month looks like in the response

A realistic shape of the entry the engine appends to the risk_signals array when this signal fires. Evidence keys are subgroup-default; per-signal overrides documented in the API reference.

json
{
  "slug": "whois_owner_changed",
  "name": "Domain Ownership Transition in Last Month",
  "group": "whois",
  "subgroup": "ownership_changes",
  "direction": "malicious",
  "evidence": {
    "owner_changes_12m": 3,
    "last_owner_change_days_ago": 14,
    "registrant_anonymized": true,
    "last_update_days_ago": 14
  }
}
See in API reference
Siblings

Peers in Ownership Changes

1 other signal shares the same subgroup. They detect related behaviors and often co-fire on the same IOC.

WHOIS Record Updated in Last Week

It indicates that the domain's WHOIS data — such as ownership, registrar, or contact details — has been updated within a

Malicious
In the wild

See Domain Ownership Transition in Last Month fire on real IOCs

The Verdict Gallery is a curated stream of real verdicts. Filter by this signal to see exactly which IOCs it caught, what other signals fired alongside it, and what the engine recommended.

Open Verdict Gallery
Pre-filtered to Domain Ownership Transition in Last Month. See real IOCs this signal caught and the verdicts the engine returned.
Verdicts ✓

Start free, in five minutes

100 IOCs/day on the free tier, LLM layer included. No card required.