Jonathan Matkowsky

Jonathan Matkowsky

Threat-intel-backed investigation and domain takeover proceedings

Decades of experience spanning internationally recognized law firms, in-house legal teams, and elite cyber threat-intelligence teams.

I bring that experience together to investigate and disrupt malicious infrastructure, use legal process to pursue attribution, and where appropriate, make criminal referrals aimed at stopping threat actors from targeting or retargeting your organization.

Let’s explore together what makes practical sense for your organization.

How do you find other infrastructure controlled by the same threat actor?

Start with the known indicator and pivot across relationships that are difficult for an operator to keep completely independent: passive DNS, IP and ASN history, nameservers, MX records, registration timing, registrar patterns, redirects, site resources, analytics or affiliate identifiers, reused contact artifacts, and public-record relationships.

The objective is not to declare common control from one weak match. It is to develop and test a network hypothesis using combinations of technical, temporal, identity, and behavioral evidence. New nodes should be rechecked against the original evidence so the investigation does not expand merely because two assets share a common hosting provider or other high-frequency characteristic.

In a 2016 dispute brought by Yahoo! Inc. (WIPO D2016-0461), common registration data, IP and nameserver relationships, support-phone and address artifacts, and redirects helped connect otherwise separate domain groups. The decision is cited in WIPO Overview 3.0 and 3.1.

Sources: MITRE ATT&CK — Acquire Infrastructure: Domains

AI can make mistakes. By using this site, you hereby agree to the Terms and Privacy Notice.