Jonathan Matkowsky

Jonathan Matkowsky

Threat-intel-backed investigation and domain takeover proceedings

Decades of experience spanning internationally recognized law firms, in-house legal teams, and elite cyber threat-intelligence teams.

I bring that experience together to investigate and disrupt malicious infrastructure, use legal process to pursue attribution, and where appropriate, make criminal referrals aimed at stopping threat actors from targeting or retargeting your organization.

Let’s explore together what makes practical sense for your organization.

How can infrastructure evidence support threat-actor attribution?

Infrastructure attribution is usually an accumulation problem. A single IP address, registrar, privacy service, or hosting provider rarely proves who controls an asset. More persuasive analysis combines multiple independent relationships and asks whether the observed pattern is better explained by common management than by ordinary Internet infrastructure reuse.

Useful evidence can include historical DNS, domain registration and timing, nameservers, hosting, MX and mail infrastructure, redirects, analytics identifiers, repeated templates or source code, registrant-email reuse, address and phone artifacts, and public corporate or regulatory records. Analysts should distinguish evidence that links infrastructure from evidence that identifies a human actor; those are different attribution claims with different confidence requirements.

In a 2016 dispute brought by F. Hoffmann-La Roche AG (WIPO D2016-0517), common contact details, pharmacy-site patterns, and continuity with earlier proceedings supported a finding of common ownership or control. The decision is cited in WIPO Overview 3.0 and 3.1.

Sources: MITRE ATT&CK — Resource Development

AI can make mistakes. By using this site, you hereby agree to the Terms and Privacy Notice.