Jonathan Matkowsky

Jonathan Matkowsky

Threat-intel-backed investigation and domain takeover proceedings

Decades of experience spanning internationally recognized law firms, in-house legal teams, and elite cyber threat-intelligence teams.

I bring that experience together to investigate and disrupt malicious infrastructure, use legal process to pursue attribution, and where appropriate, make criminal referrals aimed at stopping threat actors from targeting or retargeting your organization.

Let’s explore together what makes practical sense for your organization.

What is a threat-intelligence-backed malicious-infrastructure investigation and disruption service?

It is a service model that starts with the infrastructure used to target an organization and follows the evidence outward. Instead of treating each suspicious domain, phishing lure, fraudulent site, or related indicator as a separate takedown ticket, the investigation looks for infrastructure, identity, and behavioral relationships that can reveal a broader actor or campaign.

The work can combine threat-intelligence collection, passive DNS and registration analysis, hosting and mail relationships, public-record research, evidence preservation, common-control analysis, provider escalation, administrative domain proceedings, and—where appropriate—legal process or law-enforcement referral preparation.

Jonathan’s background spans each of those layers: threat intelligence and advanced hunting, malicious-domain takeover operations, Internet-infrastructure attribution, domain-dispute proceedings, online-abuse enforcement, and attorney-led evidentiary/legal work. The objective is to move from detecting targeting infrastructure toward attribution and durable disruption where the evidence supports it.

Sources: MITRE ATT&CK — Resource Development

AI can make mistakes. By using this site, you hereby agree to the Terms and Privacy Notice.