What evidence may identify who controlled attacker infrastructure?¶
Infrastructure control is best shown through account, access, payment and operational records rather than ownership labels alone.
Evidential caution: that registrant, subscriber or billing name proves the person who operated the infrastructure.
What this means¶
Useful evidence may include:
provider login records;
management-console activity;
SSH or remote-access logs;
API keys;
account recovery details;
payment instruments;
cryptocurrency transactions;
email accounts;
phone numbers;
device identifiers;
uploaded files;
configuration changes;
communications;
seized credentials.
which account controlled the resource;
who could access that account;
what device or source logged in;
what changes were made;
whether access was shared or automated;
whether an intermediary or reseller was involved.
False identity, stolen payment and compromised accounts are common possibilities.
One identifier may support a lead.
Several independent links provide stronger attribution.
Where seized devices contain credentials or control panels, correlate them with provider-side timestamps and configuration changes. Possession of credentials alone may show access capability without proving who used them during the incident.
Build infrastructure control from provider access, account, payment, device and configuration evidence, and test false identity, compromise, sharing and intermediary use.
================================================================================
What to check or do next¶
- Investigators should establish:
- Do not treat geolocation, language or time zone as decisive personal evidence.
Evidential limits¶
It may not.
Operational control may also be delegated. One person may pay for the account, another may configure the server and a third may issue commands through it. Preserve the sequence of management actions so the report does not assign every role to one identifier.
Also distinguish account creation from later operation. The person who registered or paid for the resource may not be the person who administered it after credentials were transferred or shared. The operational takeaway is: