Jonathan Matkowsky

Jonathan Matkowsky

Threat-intel-backed investigation and domain takeover proceedings

Decades of experience spanning internationally recognized law firms, in-house legal teams, and elite cyber threat-intelligence teams.

I bring that experience together to investigate and disrupt malicious infrastructure, use legal process to pursue attribution, and where appropriate, make criminal referrals aimed at stopping threat actors from targeting or retargeting your organization.

Let’s explore together what makes practical sense for your organization.

How can an organization build an internal threat-actor attribution and infrastructure-disruption capability?

The capability should connect functions that are often separated: threat intelligence, investigations, security operations, legal, provider escalation, evidence management, and executive decision-making. A persistent workspace should preserve indicators and relationships across incidents instead of resetting the investigation every time a new domain appears.

A mature operating model can include data and intelligence integrations, investigation and correlation workflows, confidence and evidence standards, escalation criteria, administrative or legal-process pathways, disruption tracking, and post-action learning. The organization can operate it internally, co-manage it with outside expertise, or use an initial managed phase to build repeatable procedures before transitioning ownership.

The core design principle is continuity: every investigation should be able to contribute evidence to later attribution, detection, disruption, and referral work, while maintaining provenance and separating verified facts from hypotheses.

Sources: MITRE ATT&CK — Resource Development

AI can make mistakes. By using this site, you hereby agree to the Terms and Privacy Notice.