Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is a proxy or relay used by an offender?

A proxy or relay forwards traffic between a controller, target or infrastructure component. The visible source address may be one intermediate hop rather than the offender's device or location.

Determine the role of each hop

Establish whether the intermediary originated, forwarded or terminated the connection, the precise time, port and provider account, and any upstream source. Commercial VPNs, cloud hosts, compromised routers, remote desktops and anonymity services create different evidential layers.

For multi-hop chains, preserve sequence and time correlation rather than collapsing all relays into one source.

Treat ownership as context

Shared services place many users behind one address, while a compromised relay may belong to an innocent party. Subscriber or owner data therefore does not identify the controller alone.

Where a provider keeps no useful logs, record the gap and compare preceding and following hops, device records and account access. Absence at one relay is not proof that the chain ended there.

Key takeaway

Treat visible network sources as possible intermediaries and reconstruct each hop through time, provider account and upstream access before attribution.

Reference: CIM-248Cyber Incidents & Offender Methods