Skip to content
Skip to main content
Cyber Incidents & Offender Methods Operational Explainer

How should attacker infrastructure be reported?

Report infrastructure by technical role, time period, provider resource, operational control and personal attribution. A list of domains and addresses does not explain who carried out an incident.

State role and evidential status

For each item, identify how it connected to victim activity, provider and account ID, relevant history, management evidence and whether it was shared, rented or compromised. Mark it confirmed malicious, intelligence-associated, suspicious or merely part of a connection path.

Explain links between components using accounts, access sources, certificates, configuration or payment. Similar naming and address proximity are often weak.

Use precise attribution language

A domain can deliver a payload without its registrant creating malware; a paid server account does not prove the payer operated it; a subscriber is not automatically the offender.

Where control remains uncertain, report alternatives such as offender-owned, rented, compromised or shared. Keep technical function and human identity as separate conclusions.

Key takeaway

Report infrastructure as linked time-bound technical and provider layers, stating exactly what is proved about role, control and personal identity.

Reference: CIM-254Cyber Incidents & Offender Methods