Imagine you’re leading a digital investigation.
Case #1.
You have the suspect’s IP address.
Browser fingerprint.
GPS coordinates.
Device identifiers.
Network logs.
Everything appears complete.
Case #2.
Nothing.
No IP address.
No GPS.
No browser fingerprint.
No cookies.
No device telemetry.
No phishing link.
No malware.
No compromised infrastructure.
Which case would you rather investigate?
Most investigators would choose the first one without hesitation.
And that’s exactly why I believe we’re asking the wrong question.
We’ve Been Chasing Infrastructure
For decades, digital investigations have been built around one assumption:
If you can identify the infrastructure, you can identify the person.
It made perfect sense.
The internet was simpler.
Attackers were less sophisticated.
Digital identities were relatively stable.
Today, that assumption is becoming increasingly fragile.
Changing an IP address takes seconds.
Creating a new online identity takes minutes.
A new virtual machine can be deployed almost instantly.
VPNs, proxies, residential networks, cloud infrastructure, temporary devices, disposable email addresses…
None of these represent a human being.
They represent technology.
Technology changes.
Humans don’t change nearly as fast.
The Real Target Was Never the Device
Think about the last time you met someone in person.
You didn’t recognize them because of the phone in their pocket.
Or the car they drove.
Or the street they walked on.
You recognized them because of their behavior.
The way they spoke.
The words they preferred.
The rhythm of the conversation.
Their reactions.
Their habits.
Their personality.
Now ask yourself a simple question.
Why should digital investigations work differently?
A Different Investigation Begins with a Different Question
Traditional investigations often ask:
Which IP generated this activity?
Which device performed this action?
Which account was responsible?
Behavioral investigations begin somewhere else.
They ask:
Does this activity reflect the same human being?
That single change in perspective opens investigative opportunities that technical evidence alone may never reveal.
Not because behavioral evidence is perfect.
But because people unconsciously leave patterns wherever they interact.
Three Situations Every Investigator Will Eventually Face
Scenario One — The Professional Threat Actor
A threat actor rotates infrastructure every few days.
New VPN.
New operating system.
New accounts.
New devices.
From a technical perspective, everything changes.
Yet over months of activity, subtle consistencies begin to emerge.
Writing style.
Decision-making habits.
Preferred operating hours.
Recurring interaction patterns.
None of these observations identifies the individual by itself.
Together, however, they may deserve further investigation.
Scenario Two — Coordinated Influence Operations
Twenty social media accounts appear completely unrelated.
Different countries.
Different devices.
Different technical artifacts.
Yet they consistently amplify the same narratives.
Publish at remarkably similar times.
Respond using comparable linguistic structures.
Interact according to recurring behavioral routines.
The infrastructure appears independent.
The behavior suggests coordination.
Scenario Three — Estimating Geographic Origin
This is one of the questions I am asked most often.
Can someone’s probable geographic profile be explored…
without an IP address?
Without GPS coordinates?
Without hidden metadata?
Without phishing?
Without compromising a device?
The answer may surprise many investigators.
Perhaps location is not always hidden inside infrastructure.
Perhaps parts of it are reflected in long-term human behavior.
This research direction is currently being explored within the AnubisX Attribution Framework through behavioral geographic estimation.
The implementation itself remains proprietary.
Not because secrecy is the objective.
But because protecting the underlying methodology allows the research to mature responsibly while preserving its intellectual property.
The Bigger Picture
Behavioral geographic estimation is only one research direction.
The broader objective behind AnubisX is considerably larger.
The framework explores how persistent human behavior may complement traditional digital investigations across multiple domains, including:
- Behavioral Digital Attribution
- Digital Forensics
- Cyber Threat Intelligence
- Cross-Platform Identity Correlation
- Behavioral Fingerprinting
- Stylometric Analysis
- OSINT Investigations
- Fraud Analysis
- Insider Threat Detection
- Influence Operations Research
- Long-Term Behavioral Consistency Analysis
The goal has never been to replace traditional forensic techniques.
Instead, AnubisX explores how behavioral intelligence can strengthen investigations when technical indicators become incomplete, intentionally manipulated, or disappear entirely.
The Future May Belong to Hybrid Attribution
For years, digital attribution has been dominated by infrastructure.
Tomorrow, I believe the strongest investigations will combine multiple independent perspectives.
Technical evidence.
Behavioral evidence.
Digital forensics.
Machine learning.
Artificial intelligence.
Human expertise.
Not because any single method is sufficient.
But because stronger conclusions emerge when independent forms of evidence consistently point toward the same hypothesis.
Perhaps the future of attribution is not choosing between infrastructure and behavior.
Perhaps it is learning how to combine both.
An Invitation to Challenge This Research
Research should never remain confined to papers, repositories, or conference presentations.
Its real value begins when independent organizations attempt to validate it under operational conditions.
That is why I am actively seeking collaboration with:
- Government agencies
- Law enforcement organizations
- National CERTs
- Cyber Threat Intelligence teams
- Digital forensic laboratories
- Cybersecurity companies
- Universities and research institutions
to conduct independent pilot studies, collaborative research, and operational evaluations of the AnubisX Attribution Framework.
I am not looking for organizations that simply agree with the idea.
I am looking for organizations willing to test it, challenge it, validate it, and help determine where behavioral attribution can genuinely contribute to modern investigations.
If your organization believes the next generation of digital attribution should evolve beyond infrastructure alone, I would welcome the opportunity to collaborate.
Because the future of attribution should not be decided by one researcher.
It should be validated by an entire community.
Learn More
🌐 AnubisX Framework
https://anubisxframework.github.io
📖 Book
You Can Hide Your Name… Not Your Mind: How Artificial Intelligence Reveals the Human Behind Digital Identities — Introducing the AnubisX Attribution Framework
https://www.amazon.com/dp/B0H8LCTTWW
📑 Research Figure
https://figshare.com/articles/figure/AnubisX_A_Formal_Framework_for_Behavioral_Digital_Attribution/33028817?file=66775178