Jonathan Matkowsky

Jonathan Matkowsky

Threat-intel-backed investigation and domain takeover proceedings

Decades of experience spanning internationally recognized law firms, in-house legal teams, and elite cyber threat-intelligence teams.

I bring that experience together to investigate and disrupt malicious infrastructure, use legal process to pursue attribution, and where appropriate, make criminal referrals aimed at stopping threat actors from targeting or retargeting your organization.

Let’s explore together what makes practical sense for your organization.

How do you investigate threat actors targeting employees or suppliers for initial access?

Targeting an employee, executive, vendor, or supplier can be an access strategy rather than a standalone fraud event. The investigative question is whether the observed lure, domain, sender, or impersonation site is connected to a broader infrastructure set being prepared or reused for access.

MITRE ATT&CK describes domains and other infrastructure as resources adversaries may acquire before an operation and notes that such domains can support phishing, drive-by compromise, and command and control. That makes domain and infrastructure analysis relevant before an intrusion is confirmed, particularly when the same actor appears to target multiple people or organizations.

Useful pivots include registration timing, nameservers, mail infrastructure, passive DNS, hosting, redirects, reused site resources, and identity artifacts. The purpose is to identify related staging infrastructure early enough to block, disrupt, preserve evidence, and inform the people or partners who may also be at risk.

Sources: MITRE ATT&CK — Resource Development · MITRE ATT&CK — Acquire Infrastructure: Domains

AI can make mistakes. By using this site, you hereby agree to the Terms and Privacy Notice.