Jonathan Matkowsky

Jonathan Matkowsky

Threat-intel-backed investigation and domain takeover proceedings

Decades of experience spanning internationally recognized law firms, in-house legal teams, and elite cyber threat-intelligence teams.

I bring that experience together to investigate and disrupt malicious infrastructure, use legal process to pursue attribution, and where appropriate, make criminal referrals aimed at stopping threat actors from targeting or retargeting your organization.

Let’s explore together what makes practical sense for your organization.

How do you investigate a suspicious or malicious domain?

A useful investigation treats the domain as an investigative pivot rather than an isolated indicator. The initial question is not only whether the domain looks malicious, but what infrastructure, identities, services, and related activity it connects to.

Relevant evidence can include passive DNS, registration history, nameservers, IP and ASN relationships, hosting, MX and mail configuration, redirects, page source and templates, analytics identifiers, registration timing, reused email or address artifacts, and related public records. Conclusions are stronger when multiple independent signals converge rather than when one artifact is treated as dispositive.

Jonathan used that kind of relationship analysis in a 2015 dispute brought by F. Hoffmann-La Roche AG (WIPO D2015-0066), where feeder and anchor sites, redirects, templates, registration emails, and unusual telephone patterns helped support common control across 153 adjudicated domains, all of which were transferred.

Sources: MITRE ATT&CK — Acquire Infrastructure: Domains

AI can make mistakes. By using this site, you hereby agree to the Terms and Privacy Notice.