How should attacker infrastructure be reported?¶
Attacker infrastructure should be reported by separating technical role, provider account, operational control and personal attribution.
Evidential caution: that listing malicious IP addresses and domains explains who carried out the incident.
What this means¶
A defensible report should identify:
the infrastructure item;
its role;
the relevant time period;
the provider;
the account or resource identifier;
how it connected to victim activity;
who managed it;
what payment or registration evidence exists;
whether it was shared, rented or compromised;
what attribution level is supported.
“The domain delivered the payload” is different from “the registrant created the malware.”
“The server account was paid using…” is different from “the payer personally operated the attack.”
“The IP address hosted command-and-control traffic” is different from “the subscriber was the offender.”
Explain historical changes, relays, cloud services, shared hosting and account compromise.
Where several infrastructure items are linked, explain the basis of the link. Shared certificates, accounts, access sources, malware configuration or payment may carry different weight. Similar naming or nearby IP addresses alone may be too weak to support common control.
State whether each item is confirmed malicious, associated by intelligence, merely suspicious or simply part of the connection path. This prevents infrastructure lists from overstating evidential certainty.
Where attribution remains uncertain, report the supported alternatives. The same infrastructure may have been controlled by the offender, rented from a service, compromised from an innocent user or shared with unrelated customers. The operational takeaway is:
Report infrastructure as linked technical and provider layers, and state clearly what is proved about role, control and personal identity.
================================================================================
What to check or do next¶
- Use precise language.
Evidential limits¶
It does not.