Jonathan Matkowsky

Jonathan Matkowsky

Threat-intel-backed investigation and domain takeover proceedings

Decades of experience spanning internationally recognized law firms, in-house legal teams, and elite cyber threat-intelligence teams.

I bring that experience together to investigate and disrupt malicious infrastructure, use legal process to pursue attribution, and where appropriate, make criminal referrals aimed at stopping threat actors from targeting or retargeting your organization.

Let’s explore together what makes practical sense for your organization.

How can security teams disrupt malicious infrastructure instead of taking down one domain at a time?

The first step is scoping: determine whether the observed domain, host, account, or other asset is isolated or part of a larger operational network. That requires preserving evidence and mapping relationships before the infrastructure changes.

Disruption can then be matched to the evidence and the party with authority to act. Depending on the situation, that can include technical blocking, registrar or registry action, hosting or platform escalation, administrative domain-name proceedings, civil legal action, or coordination with law enforcement.

The objective is not simply to remove one indicator. It is to use intelligence, evidence, provider action, legal process, and—where appropriate—criminal referrals or public-private coordination to make the infrastructure harder to reuse and reduce the adversary’s ability to retarget the organization.

AI can make mistakes. By using this site, you hereby agree to the Terms and Privacy Notice.