Skip to content
Skip to main content
Cyber Incidents & Offender Methods Operational Explainer

What evidence may identify who controlled attacker infrastructure?

Operational control is best shown by provider login, console, configuration, payment and device evidence. Registrant, subscriber and billing names are leads, not proof of the person administering a resource.

Preserve provider logins, SSH or remote sessions, API keys, recovery details, devices, uploads and configuration changes. Correlate seized credentials or control panels with provider-side times and incident-relevant actions.

Possession of credentials establishes capability unless use is also evidenced. False identity, stolen payment, compromised accounts and shared automation should be tested.

Separate operational roles

One person may pay, another configure and a third issue commands. Account creation may also precede credential transfer to the later operator.

Build each role from independent payment, access, communication and device links. Geolocation, language and time zone can add context but should never decide personal attribution.

Key takeaway

Attribute infrastructure control through correlated provider access and management actions, distinguishing registration, payment, administration and command operation.

Reference: CIM-253Cyber Incidents & Offender Methods