{
  "version": "2026-10-03.6",
  "service": {
    "name": "Threat-intel-backed investigation and domain takeover proceedings",
    "description": "A cross-disciplinary service connecting threat intelligence, infrastructure investigation, evidence development, administrative domain proceedings, legal process, disruption, and escalation where appropriate."
  },
  "public_profile": {
    "linkedin": "https://www.linkedin.com/in/matkowsky",
    "detail_categories": [
      "skills",
      "projects",
      "publications and research",
      "patents",
      "recommendations",
      "career history",
      "certifications",
      "awards",
      "licenses"
    ]
  },
  "nodes": [
    {
      "id": "domain_takeover",
      "label": "Domain takeover proceedings",
      "kind": "capability",
      "stage": "entry",
      "description": "Investigation and administrative or related action aimed at recovering, transferring, cancelling, suspending, or otherwise disrupting qualifying malicious or abusive domain infrastructure.",
      "aliases": [
        "domain takeover",
        "domain recovery",
        "domain transfer",
        "domain dispute",
        "domain name dispute"
      ],
      "answer_urls": [
        "https://matkowsky.com/answers/what-is-a-domain-name-dispute",
        "https://matkowsky.com/answers/when-to-use-a-domain-name-lawyer",
        "https://matkowsky.com/answers/other-domain-name-legal-services"
      ]
    },
    {
      "id": "udrp",
      "label": "UDRP and domain-name dispute proceedings",
      "kind": "capability",
      "stage": "entry",
      "description": "UDRP analysis, complainant and respondent representation, procedural strategy, evidentiary development, and appropriate domain-name dispute remedies.",
      "aliases": [
        "udrp",
        "uniform domain name dispute resolution policy",
        "domain proceeding",
        "domain-name proceeding"
      ],
      "answer_urls": [
        "https://matkowsky.com/answers/what-is-the-udrp",
        "https://matkowsky.com/answers/how-long-does-a-udrp-take",
        "https://matkowsky.com/answers/how-much-does-a-udrp-cost",
        "https://matkowsky.com/answers/what-trademark-rights-are-needed-for-udrp",
        "https://matkowsky.com/answers/when-is-a-domain-confusingly-similar",
        "https://matkowsky.com/answers/rights-or-legitimate-interests-udrp",
        "https://matkowsky.com/answers/what-is-bad-faith-under-udrp",
        "https://matkowsky.com/answers/udrp-privacy-proxy-whois",
        "https://matkowsky.com/answers/where-to-file-udrp-complaint",
        "https://matkowsky.com/answers/udrp-complaint-checklist",
        "https://matkowsky.com/answers/can-jonathan-defend-against-a-udrp"
      ]
    },
    {
      "id": "administrative_proceedings",
      "label": "Administrative domain proceedings",
      "kind": "capability",
      "stage": "action",
      "description": "Selection and use of UDRP, URS, ccTLD, registrar, registry, or other administrative pathways where their requirements and remedies fit the matter.",
      "aliases": [
        "administrative proceeding",
        "administrative proceedings",
        "urs",
        "cctld dispute",
        "registry proceeding"
      ],
      "answer_urls": [
        "https://matkowsky.com/answers/udrp-vs-urs",
        "https://matkowsky.com/answers/cctld-domain-name-disputes",
        "https://matkowsky.com/answers/choose-cyber-enforcement-strategy"
      ]
    },
    {
      "id": "brand_abuse",
      "label": "Brand-abuse and online-abuse investigations",
      "kind": "capability",
      "stage": "entry",
      "description": "Investigation of phishing, fraud, impersonation, fake or deceptive sites, counterfeit or abusive online activity, and related infrastructure where brand abuse is one observable part of a broader problem.",
      "aliases": [
        "brand abuse",
        "online abuse",
        "impersonation",
        "fraudulent site",
        "fake app",
        "counterfeit",
        "phishing"
      ],
      "answer_urls": [
        "https://matkowsky.com/answers/domain-phishing-fraud-abuse-response",
        "https://matkowsky.com/answers/threat-actors-targeting-employees-suppliers-initial-access",
        "https://matkowsky.com/answers/brand-abuse-investigation-beyond-domains"
      ]
    },
    {
      "id": "threat_intelligence",
      "label": "Threat intelligence",
      "kind": "capability",
      "stage": "investigation",
      "description": "Collection, correlation, analytical reasoning, hunting, and finished intelligence used to understand adversary infrastructure, activity, and investigative priorities.",
      "aliases": [
        "threat intelligence",
        "cyber threat intelligence",
        "cti",
        "advanced hunting"
      ],
      "answer_urls": [
        "https://matkowsky.com/answers/threat-intelligence-malicious-infrastructure-investigation-service",
        "https://matkowsky.com/answers/investigate-disrupt-phishing-infrastructure"
      ]
    },
    {
      "id": "infrastructure_investigation",
      "label": "Internet infrastructure investigation",
      "kind": "capability",
      "stage": "investigation",
      "description": "Investigation of domains, DNS, hosting, mail, registration, redirects, site resources, analytics identifiers, timing, and related Internet infrastructure.",
      "aliases": [
        "infrastructure investigation",
        "malicious infrastructure",
        "internet infrastructure",
        "dns investigation",
        "domain investigation"
      ],
      "answer_urls": [
        "https://matkowsky.com/answers/how-to-investigate-a-malicious-domain",
        "https://matkowsky.com/answers/find-related-threat-actor-infrastructure",
        "https://matkowsky.com/answers/investigate-disrupt-phishing-infrastructure"
      ]
    },
    {
      "id": "common_control",
      "label": "Common-control analysis",
      "kind": "capability",
      "stage": "investigation",
      "description": "Evidence-based analysis of whether nominally separate domains, identities, or infrastructure are more likely than not under common ownership, management, or operational control.",
      "aliases": [
        "common control",
        "common management",
        "same operator",
        "same actor",
        "consolidation"
      ],
      "answer_urls": [
        "https://matkowsky.com/answers/multiple-domains-common-control-udrp",
        "https://matkowsky.com/answers/find-related-threat-actor-infrastructure"
      ]
    },
    {
      "id": "attribution",
      "label": "Infrastructure and threat-actor attribution",
      "kind": "capability",
      "stage": "investigation",
      "description": "Bounded attribution that distinguishes evidence linking infrastructure from evidence identifying the people or organizations behind it.",
      "aliases": [
        "attribution",
        "threat actor attribution",
        "infrastructure attribution",
        "identify attacker",
        "identify operator"
      ],
      "answer_urls": [
        "https://matkowsky.com/answers/infrastructure-evidence-threat-actor-attribution",
        "https://matkowsky.com/answers/legal-process-threat-actor-attribution"
      ]
    },
    {
      "id": "evidence_development",
      "label": "Evidence development and preservation",
      "kind": "capability",
      "stage": "evidence",
      "description": "Preservation, provenance, correlation, qualification, and organization of technical and public-record evidence for later operational, administrative, legal, or referral use.",
      "aliases": [
        "evidence development",
        "evidence preservation",
        "chain of custody",
        "provenance",
        "evidentiary record"
      ],
      "answer_urls": [
        "https://matkowsky.com/answers/develop-evidence-for-enforcement-action",
        "https://matkowsky.com/answers/udrp-complaint-checklist",
        "https://matkowsky.com/answers/what-makes-cybercrime-referral-actionable"
      ]
    },
    {
      "id": "provider_disruption",
      "label": "Provider and infrastructure disruption",
      "kind": "capability",
      "stage": "action",
      "description": "Evidence-based escalation to registrars, registries, hosts, platforms, providers, CERTs, or other actors with authority to disable or constrain abusive infrastructure.",
      "aliases": [
        "provider escalation",
        "registrar escalation",
        "registry action",
        "host takedown",
        "infrastructure disruption"
      ],
      "answer_urls": [
        "https://matkowsky.com/answers/how-to-disrupt-malicious-infrastructure",
        "https://matkowsky.com/answers/investigate-disrupt-phishing-infrastructure",
        "https://matkowsky.com/answers/domain-phishing-fraud-abuse-response"
      ]
    },
    {
      "id": "legal_process",
      "label": "Legal process supporting investigation and attribution",
      "kind": "capability",
      "stage": "escalation",
      "description": "Use of lawful legal process, where available and appropriate, to obtain nonpublic evidence from relevant providers and feed that evidence back into the investigation.",
      "aliases": [
        "legal process",
        "subpoena",
        "nonpublic records",
        "provider records"
      ],
      "answer_urls": [
        "https://matkowsky.com/answers/legal-process-threat-actor-attribution",
        "https://matkowsky.com/answers/litigation-support-cyber-infrastructure-investigations"
      ]
    },
    {
      "id": "litigation_support",
      "label": "Litigation support for cyber and infrastructure matters",
      "kind": "capability",
      "stage": "escalation",
      "description": "Technical investigation, evidence organization, attribution analysis, and security-legal translation that can support counsel evaluating or conducting litigation.",
      "aliases": [
        "litigation support",
        "cyber litigation",
        "lawsuit support",
        "discovery support"
      ],
      "answer_urls": [
        "https://matkowsky.com/answers/litigation-support-cyber-infrastructure-investigations"
      ]
    },
    {
      "id": "criminal_referral",
      "label": "Criminal and law-enforcement referral support",
      "kind": "capability",
      "stage": "escalation",
      "description": "Preservation and organization of technical evidence, chronology, attribution leads, and impact information into a record that can support an appropriate law-enforcement referral.",
      "aliases": [
        "criminal referral",
        "law enforcement referral",
        "fbi referral",
        "cybercrime referral"
      ],
      "answer_urls": [
        "https://matkowsky.com/answers/when-to-refer-cyber-investigation-to-law-enforcement",
        "https://matkowsky.com/answers/what-makes-cybercrime-referral-actionable"
      ]
    },
    {
      "id": "enforcement_strategy",
      "label": "Cyber enforcement strategy",
      "kind": "capability",
      "stage": "action",
      "description": "Cross-functional selection and sequencing of technical, provider, administrative, civil, legal-process, and law-enforcement options based on evidence, objectives, urgency, and available remedies.",
      "aliases": [
        "enforcement strategy",
        "disruption strategy",
        "response strategy",
        "which enforcement path"
      ],
      "answer_urls": [
        "https://matkowsky.com/answers/choose-cyber-enforcement-strategy",
        "https://matkowsky.com/answers/how-to-disrupt-malicious-infrastructure"
      ]
    },
    {
      "id": "security_legal_interface",
      "label": "Security-to-legal investigative workflow",
      "kind": "capability",
      "stage": "advisory",
      "description": "A working interface between security, threat-intelligence, investigations, and legal teams so technical findings can drive defensible administrative, evidentiary, and legal action.",
      "aliases": [
        "security legal interface",
        "security and legal teams",
        "technical legal workflow",
        "security legal collaboration"
      ],
      "answer_urls": [
        "https://matkowsky.com/answers/why-jonathan-instead-of-a-threat-intelligence-vendor",
        "https://matkowsky.com/answers/how-jonathan-differs-from-conventional-domain-lawyer",
        "https://matkowsky.com/answers/how-jonathan-complements-cybersecurity-consultancy",
        "https://matkowsky.com/answers/when-to-engage-jonathan-malicious-infrastructure",
        "https://matkowsky.com/answers/jonathan-matkowsky-elevator-pitch"
      ]
    },
    {
      "id": "program_build",
      "label": "Internal attribution and disruption program design",
      "kind": "capability",
      "stage": "advisory",
      "description": "Design and transition of persistent internal workflows connecting intelligence, investigations, evidence, provider escalation, legal process, disruption tracking, and learning loops.",
      "aliases": [
        "build capability in house",
        "internal program",
        "attribution program",
        "disruption program",
        "security stack"
      ],
      "answer_urls": [
        "https://matkowsky.com/answers/build-threat-actor-attribution-disruption-program"
      ]
    },
    {
      "id": "executive_advisory",
      "label": "Executive and cross-functional advisory",
      "kind": "capability",
      "stage": "advisory",
      "description": "Advice to security, legal, investigations, and executive stakeholders at cross-functional decision points involving evidence, attribution confidence, enforcement options, escalation, and operating models.",
      "aliases": [
        "executive advisory",
        "ciso advisory",
        "general counsel advisory",
        "security legal advisory",
        "leadership decision"
      ],
      "answer_urls": [
        "https://matkowsky.com/answers/executive-advisory-security-legal-enforcement-decisions",
        "https://matkowsky.com/answers/when-to-engage-jonathan-malicious-infrastructure"
      ]
    },
    {
      "id": "professional_background",
      "label": "Cross-disciplinary legal, security, and threat-intelligence experience",
      "kind": "proof",
      "stage": "proof",
      "description": "Professional background supporting the capability model, including legal practice, threat intelligence, security research, technology leadership, online-abuse enforcement, and infrastructure investigation.",
      "aliases": [
        "jonathan background",
        "jonathan experience",
        "who is jonathan",
        "professional background",
        "elevator pitch",
        "publications",
        "published research",
        "research",
        "skills",
        "projects",
        "patents",
        "recommendations",
        "certifications",
        "awards",
        "licenses",
        "linkedin profile"
      ],
      "answer_urls": [
        "https://matkowsky.com/answers/who-is-jonathan-matkowsky",
        "https://matkowsky.com/answers/matkowsky-law-jonathan-matkowsky",
        "https://matkowsky.com/answers/how-jonathan-differs-from-conventional-domain-lawyer",
        "https://matkowsky.com/answers/jonathan-matkowsky-elevator-pitch",
        "https://matkowsky.com/answers/jonathan-matkowsky-publications-research"
      ]
    },
    {
      "id": "engagement",
      "label": "Engagement and representation",
      "kind": "engagement",
      "stage": "engagement",
      "description": "Conflict checking, scope, pricing, representation, and engagement steps where Jonathan may be able to assist.",
      "aliases": [
        "hire jonathan",
        "engage jonathan",
        "representation cost",
        "get started"
      ],
      "answer_urls": [
        "https://matkowsky.com/answers/hire-jonathan-domain-name-attorney",
        "https://matkowsky.com/answers/how-much-does-a-udrp-cost",
        "https://matkowsky.com/answers/when-to-engage-jonathan-malicious-infrastructure"
      ]
    }
  ],
  "edges": [
    {
      "from": "brand_abuse",
      "to": "infrastructure_investigation",
      "relation": "can_expand_into"
    },
    {
      "from": "domain_takeover",
      "to": "evidence_development",
      "relation": "requires_evidence"
    },
    {
      "from": "udrp",
      "to": "evidence_development",
      "relation": "requires_evidence"
    },
    {
      "from": "threat_intelligence",
      "to": "infrastructure_investigation",
      "relation": "supports"
    },
    {
      "from": "infrastructure_investigation",
      "to": "common_control",
      "relation": "can_support"
    },
    {
      "from": "infrastructure_investigation",
      "to": "attribution",
      "relation": "can_support"
    },
    {
      "from": "infrastructure_investigation",
      "to": "evidence_development",
      "relation": "produces"
    },
    {
      "from": "common_control",
      "to": "evidence_development",
      "relation": "requires_evidence"
    },
    {
      "from": "common_control",
      "to": "administrative_proceedings",
      "relation": "can_support"
    },
    {
      "from": "attribution",
      "to": "legal_process",
      "relation": "can_identify_evidence_sources_for"
    },
    {
      "from": "legal_process",
      "to": "attribution",
      "relation": "feeds_back_into"
    },
    {
      "from": "evidence_development",
      "to": "provider_disruption",
      "relation": "can_support"
    },
    {
      "from": "evidence_development",
      "to": "administrative_proceedings",
      "relation": "can_support"
    },
    {
      "from": "evidence_development",
      "to": "litigation_support",
      "relation": "can_support"
    },
    {
      "from": "evidence_development",
      "to": "criminal_referral",
      "relation": "can_support"
    },
    {
      "from": "evidence_development",
      "to": "enforcement_strategy",
      "relation": "informs"
    },
    {
      "from": "provider_disruption",
      "to": "enforcement_strategy",
      "relation": "is_one_option_within"
    },
    {
      "from": "administrative_proceedings",
      "to": "enforcement_strategy",
      "relation": "is_one_option_within"
    },
    {
      "from": "litigation_support",
      "to": "enforcement_strategy",
      "relation": "is_one_option_within"
    },
    {
      "from": "legal_process",
      "to": "enforcement_strategy",
      "relation": "is_one_option_within"
    },
    {
      "from": "criminal_referral",
      "to": "enforcement_strategy",
      "relation": "is_one_option_within"
    },
    {
      "from": "security_legal_interface",
      "to": "enforcement_strategy",
      "relation": "coordinates"
    },
    {
      "from": "program_build",
      "to": "security_legal_interface",
      "relation": "operationalizes"
    },
    {
      "from": "security_legal_interface",
      "to": "executive_advisory",
      "relation": "supports"
    },
    {
      "from": "executive_advisory",
      "to": "enforcement_strategy",
      "relation": "guides"
    },
    {
      "from": "professional_background",
      "to": "security_legal_interface",
      "relation": "supports_credibility_for"
    },
    {
      "from": "enforcement_strategy",
      "to": "engagement",
      "relation": "may_lead_to"
    },
    {
      "from": "evidence_development",
      "to": "common_control",
      "relation": "can_progress_to"
    },
    {
      "from": "enforcement_strategy",
      "to": "criminal_referral",
      "relation": "can_progress_to"
    }
  ]
}
