NODE · LON-01|LONDON --:--:--
DAC | Digital Asset Claims
Infrastructure Intelligence

Digital Asset Claims Infrastructure & IP Intelligence

Infrastructure & IP Intelligence examines legitimately obtained IP and infrastructure data — network ownership, ASN information, approximate geographic indicators, hosting infrastructure, proxy or VPN indicators, domains and timestamps — to build a documented picture of the infrastructure behind observed activity.

Domain, DNS, certificate and hosting records assembled into an infrastructure timeline

Why Infrastructure Tells A Story The Front End Hides

A website can be rebuilt overnight under a new name. The infrastructure beneath it — hosting, name servers, certificates, registration patterns — changes far more slowly, and it frequently links a new front end to an older one.

Infrastructure analysis is therefore less about a single IP address and more about the pattern: what else sits on the same host, what the certificate history shows, and when each element was created relative to the events in question.

Scope Of Infrastructure Intelligence

This service focuses on Infrastructure Intelligence: reading network-level data that is lawfully available (from client-supplied logs, public registries and lawful platform records) to establish what infrastructure sits behind a domain, an IP address or a piece of observed activity.

It covers resolution of IP addresses to their network ranges, allocations and ASN (autonomous system) ownership; identification of hosting providers and server locations associated with a domain or platform; and recognition of indicators consistent with proxy, VPN or other traffic-masking services.

ASN and Network Ownership

Each IP address examined is resolved to its allocated range and the organisation registered as controlling that range, using publicly available registry data (such as regional internet registry records), and that resolution is recorded alongside the address it applies to.

Proxy, VPN and Masking Indicators

Ranges and hosting characteristics consistent with commercial proxy, VPN or hosting-as-relay services are flagged explicitly, so that an address is not mistaken for a genuine originating point when the available data suggests otherwise.

Identifiers Needed For Infrastructure Work

IP addresses, domains or hosting references, typically drawn from logs, headers or platform exports the client is lawfully entitled to hold. No interception or monitoring of live traffic is performed as part of this service.

How Infrastructure Records Are Assembled

Each address or domain in scope is checked against public registry and hosting data, correlated against any other addresses or domains in the same engagement to look for shared infrastructure, and the approximate geographic indicators available (which describe the registered location of an allocation, not a precise physical location) are recorded with the caveats that apply to them.

What Infrastructure Work Produces

An infrastructure profile documenting each address and domain examined, its resolved ownership and hosting characteristics, and any shared infrastructure identified across multiple items in scope.

What Infrastructure Records Do Not Prove

IP and infrastructure data describes a network position, not a person. It does not on its own establish who was using a given connection at a given time, and geographic indicators derived from IP allocation are approximate rather than precise. Any conclusion linking infrastructure to a specific individual requires independent corroboration, which is stated explicitly where it exists and where it does not.

Technology

Technology Applied To Infrastructure Analysis

  • Passive DNS history

    Historic resolution records show where a domain pointed over time, not just where it points today.

  • Certificate transparency search

    Public certificate logs reveal issuance history, hostnames and creation dates.

  • Hosting and ASN attribution

    Addresses are resolved to hosting providers and autonomous systems using public routing data.

  • Co-hosting correlation

    Other hostnames served from the same infrastructure are identified and assessed for relevance.

Data

Data Examined In Infrastructure Analysis

  • Domain registration dates, registrars and historic registration records
  • Passive DNS resolution history and name server changes
  • Public certificate transparency log entries
  • IP address allocation, hosting provider and autonomous system records
  • Co-hosted hostnames and shared infrastructure indicators
  • Publicly observable mail and subdomain configuration
  • Client-supplied header or log material the client lawfully holds

How Infrastructure Analysis Runs

  1. Step 01

    Enumerate the identifiers

    Domains, hostnames and addresses in scope are listed and confirmed.

  2. Step 02

    Pull historic records

    Registration, DNS and certificate history is retrieved for each identifier.

  3. Step 03

    Resolve the hosting picture

    Addresses are attributed to providers and networks using public routing data.

  4. Step 04

    Identify shared infrastructure

    Other properties on the same infrastructure are identified and assessed.

  5. Step 05

    Build the creation timeline

    Each element is dated so infrastructure age can be compared against the events at issue.

  6. Step 06

    State the confidence limits

    Shared hosting and proxy services are flagged where they weaken an inference.

  7. Step 07

    Document the findings

    The infrastructure picture is written up with every record cited to its source.

Deliverables

Output 01

IP Resolution Sheet

Each address examined, with range, allocation and hosting characteristics.

Output 02

Infrastructure Profile

Hosting providers, server locations and shared infrastructure identified across the engagement.

Output 03

Masking Indicator Log

Addresses and ranges consistent with proxy, VPN or relay services.

Output 04

Reliability Note

Written statement of what each address can and cannot support as evidence.

Evidence Confidence Classification

Every finding is graded so that what is established, what is indicative and what remains unresolved are never presented as the same thing.

Verified
Independently confirmed by two or more unrelated sources.
Strongly Supported
Consistent with multiple sources, with no material contradiction observed.
Partially Supported
Consistent with at least one source, but corroboration is incomplete.
Unverified
Recorded as observed, but no independent corroborating source has been located.
Conflicting
Sources disagree, and the conflict is documented rather than resolved by assumption.
Insufficient Evidence
Available material does not support a finding in either direction.

Limitations of This Service

Findings are bounded by the material that is lawfully available at the time of the engagement. Digital Asset Claims does not access private accounts, credentials or systems, does not perform any unauthorised or intrusive technical activity, and does not guarantee that a given question can be answered. Where the evidence does not support a conclusion, the report says so rather than inferring one. Geographic indicators derived from network allocation data are approximate and describe a registered range, not a precise physical location; no interception or monitoring of live network traffic is performed.

Questions

Can an IP address identify exactly who was online?

No. It identifies a network position at a point in time. Attribution to a specific person requires independent corroborating evidence.

How is a VPN or proxy identified?

Through publicly documented characteristics of the hosting range or provider concerned, which are recorded as indicators rather than certainties.

Where do the underlying logs come from?

From records the client already holds or is lawfully entitled to obtain, such as headers or platform exports. No live traffic is intercepted.

Need to know what sits behind a domain or platform?

Give us the domains or hostnames involved and we will set out what the public infrastructure record supports.

Request An Infrastructure Review