Skip to content
CIM-245 Cyber Incidents & Offender Methods

What is attacker infrastructure?

The practical answer

Attacker infrastructure is the collection of systems, services, accounts and network resources used to support malicious activity.

The key evidential caution

The dangerous assumption is that finding one server or domain identifies the whole operation.

It may not.

Attacker infrastructure may include:

Key points

  • command-and-control servers
  • phishing sites
  • malware-delivery hosts
  • cloud accounts
  • domains
  • proxies
  • VPNs
  • bulletproof hosting
  • compromised websites
  • staging servers
  • file-storage accounts
  • communication platforms
  • payment services

Different parts may be controlled by different people.

Some infrastructure may be rented, compromised, shared or short-lived.

What investigators should establish

Investigators should establish:

Key points

  • what role the infrastructure played
  • who provided or hosted it
  • which account controlled it
  • when it was active
  • how it was accessed
  • what systems or victims it connected to
  • whether it was dedicated or shared

A malicious IP address does not automatically identify the offender.

A domain registrant may be false, privacy-protected or an intermediary.

A cloud account may have been compromised.

Relevant evidence

Relevant evidence may include provider records, account identifiers, payment details, access logs, certificates, registration data, malware configuration and links to victim activity.

Infrastructure often changes during an incident. One domain may deliver the first payload, another may receive command traffic and a third may store stolen data. Preserve the relationship between each component and its time period. A later provider or address should not be assumed to have played the same role as an earlier one.

Also distinguish infrastructure prepared for possible use from infrastructure actually observed in the incident. Registration, payment or configuration may show preparation, while victim traffic, logins or payload delivery show operational use.

Operational takeaway

Treat infrastructure as a set of technical roles and provider accounts, and build personal attribution separately from hosting, registration and network evidence.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.