What is a proxy or relay used by an offender?¶
A proxy or relay forwards traffic between a controller, target or infrastructure component. The visible source address may be one intermediate hop rather than the offender's device or location.
Determine the role of each hop¶
Establish whether the intermediary originated, forwarded or terminated the connection, the precise time, port and provider account, and any upstream source. Commercial VPNs, cloud hosts, compromised routers, remote desktops and anonymity services create different evidential layers.
For multi-hop chains, preserve sequence and time correlation rather than collapsing all relays into one source.
Treat ownership as context¶
Shared services place many users behind one address, while a compromised relay may belong to an innocent party. Subscriber or owner data therefore does not identify the controller alone.
Where a provider keeps no useful logs, record the gap and compare preceding and following hops, device records and account access. Absence at one relay is not proof that the chain ended there.
Key takeaway
Treat visible network sources as possible intermediaries and reconstruct each hop through time, provider account and upstream access before attribution.