What evidence may identify who controlled attacker infrastructure?¶
Operational control is best shown by provider login, console, configuration, payment and device evidence. Registrant, subscriber and billing names are leads, not proof of the person administering a resource.
Link management actions to access¶
Preserve provider logins, SSH or remote sessions, API keys, recovery details, devices, uploads and configuration changes. Correlate seized credentials or control panels with provider-side times and incident-relevant actions.
Possession of credentials establishes capability unless use is also evidenced. False identity, stolen payment, compromised accounts and shared automation should be tested.
Separate operational roles¶
One person may pay, another configure and a third issue commands. Account creation may also precede credential transfer to the later operator.
Build each role from independent payment, access, communication and device links. Geolocation, language and time zone can add context but should never decide personal attribution.
Key takeaway
Attribute infrastructure control through correlated provider access and management actions, distinguishing registration, payment, administration and command operation.