Templates Cybercrime Investigation
The Vault · Cybercrime Investigation

Case Workflow &
Data Model Reference

A complete operational reference for digital crime units and enterprise security teams — how Hubstream structures a cybercrime investigation from incident intake through attribution, prosecution referral, and intelligence retention.

Template type Starter Template
Use case Cybercrime Investigation
Workflow stages 6 stages
Entity types 10 core entities
How It Works · 01–06

Case Workflow

Every cybercrime investigation moves through six stages — from initial incident report through attribution, legal action, and intelligence retention. Here's how Hubstream structures that journey for digital crime units.

01
Stage 1 · Intake & Triage

Incident Intake & Classification

A new investigation opens when an incident is reported — from a victim organization, an internal security team, a law enforcement referral, a CISA or IC3 report, or proactive threat monitoring. Each intake channel captures the incident type, affected systems, observed indicators, and initial impact assessment. The incident is classified by cyber crime category and a case record is created with a priority score.

Victim Organization Report IC3 / CISA Referral Internal Security Escalation NCMEC CyberTipline Threat Intelligence Alert Partner Agency Referral
02
Stage 2 · Digital Evidence Collection

Evidence Preservation & Legal Process

Investigators secure and collect digital evidence before it can be altered or destroyed — network logs, system images, malware samples, email headers, device data, and financial transaction records. Legal process is initiated in parallel: subpoenas to ISPs, cloud providers, and payment platforms for subscriber records, account activity, and IP logs. All evidence is logged with chain-of-custody tracking from the moment of collection.

Log & Network Capture Device Imaging Malware Sample Collection ISP / Platform Subpoena Financial Record Request Chain-of-Custody Logging
03
Stage 3 · Forensic Analysis

Forensic Analysis & Attack Timeline Reconstruction

Digital forensic analysis reconstructs exactly what happened — attack vector, tools and malware used, compromised systems, data accessed or exfiltrated, and attacker persistence mechanisms. IP addresses, domains, email accounts, cryptocurrency wallets, and device identifiers are analyzed and enriched using threat intelligence feeds. The attack timeline is built from log correlation, identifying initial access, lateral movement, and exfiltration events. Indicators of Compromise (IOCs) are extracted and linked to known threat actor profiles.

Malware Analysis Log Correlation IOC Extraction Threat Intelligence Enrichment Attack Timeline Cryptocurrency Tracing TTP Profiling (MITRE ATT&CK)
04
Stage 4 · Attribution & Intelligence Development

Threat Actor Attribution & Network Mapping

Investigators build a threat actor profile from infrastructure, TTPs, and online identities discovered during forensic analysis. OSINT research and dark web monitoring surface aliases, forums, marketplaces, and communication channels linked to the suspect. Link analysis connects the threat actor to prior incidents, known associates, criminal infrastructure (bulletproof hosting, C2 servers, crypto wallets), and victim organizations across unrelated cases. Related investigations are merged or cross-referenced to build a complete picture of threat actor activity.

Threat Actor Profiling OSINT Research Dark Web Monitoring Infrastructure Mapping Link Analysis Cross-Case Intelligence Alias & Identity Resolution
05
Stage 5 · Legal Action & Prosecution Referral

Warrants, Takedowns & Prosecution Package

With a suspect attributed, legal action proceeds — search warrants for devices and accounts, asset freezes on cryptocurrency wallets, domain seizures, and international legal assistance requests (MLATs). Hubstream tracks all legal authorities and their status. When an arrest is made or a prosecution referral is submitted, the system auto-generates the case package: incident timeline, evidence inventory, forensic analysis summary, and victim impact statement — formatted for the prosecutor, DOJ, or international law enforcement partner.

Search & Seizure Warrants Asset Freeze Domain Seizure MLAT / International Coordination Prosecution Package DOJ / FBI Referral
06
Stage 6 · Closure & Intelligence Retention

Case Outcome & Persistent Intelligence

When a case closes, the outcome is logged — conviction, plea, extradition, case referred to another jurisdiction, or investigation suspended. Threat actor profiles, infrastructure records, and IOCs are retained in the system and remain searchable across future investigations. Analytics dashboards track case outcomes by cybercrime type, investigator caseload, and geographic patterns of victim targeting. Intelligence generated during the investigation feeds the organization's persistent threat picture.

Case Disposition Threat Actor Retention IOC Repository Outcome Analytics Future Investigation Linkage Executive Reporting
Connects with
OSINT Platforms Dark Web Monitors Threat Intelligence Feeds VirusTotal / Shodan Digital Forensic Tools NCMEC CyberTipline Cryptocurrency Tracing IC3 / CISA Social Media Capture
Data Model · 10 Entity Types

What Gets Captured

Every entity in Hubstream's Cybercrime Investigation template — what it represents, what fields it holds, and how it connects to the broader case record.

📁

Case / Incident

The central record every other entity links to. Tracks the lifecycle of a cybercrime investigation from initial report to case disposition.

Case Number · auto-generated Cybercrime Type · phishing / ransomware / fraud / CSAM / etc. Status · open / active / suspended / closed Priority · scored + supervisor override Assigned Investigator(s) Jurisdiction · federal / state / international Disposition · conviction / referral / suspended / declined Date Opened / Closed
🎯

Threat Actor / Suspect

An individual or group responsible for or suspected of the cybercrime. May begin as an anonymous actor and be de-anonymized through attribution analysis.

Real Identity · if known Aliases / Handles Known Infrastructure · IPs, domains, C2 TTP Profile · MITRE ATT&CK mapping Nationality / Location · if known Prior Incidents Status · unknown / identified / arrested / charged
🌐

Digital Artifact

Any digital indicator connected to the crime — an IP address, domain, URL, email address, file hash, or cryptocurrency wallet. The primary entity for link analysis and threat intelligence enrichment.

Artifact Type · IP / domain / URL / email / hash / wallet Value First Seen / Last Seen Threat Intel Enrichment · VirusTotal / Shodan / Recorded Future Registrant Info · WHOIS / subpoena result Linked Cases Attribution Confidence
👤

Online Profile

A social media account, forum profile, marketplace listing, or dark web identity linked to the investigation — as a victim account, suspect alias, or infrastructure pivot point.

Platform · social / forum / marketplace / dark web Username / Handle Profile URL Role · suspect / victim / witness Account Status · active / suspended / deleted Linked Artifacts Captured Evidence
💻

Device

A computer, mobile device, server, or other piece of hardware involved in or affected by the crime — seized as evidence, identified from logs, or flagged as attacker infrastructure.

Device Type · laptop / mobile / server / IoT Make / Model / OS MAC Address / Serial Associated IP Addresses Role · victim / attacker / C2 / relay Forensic Image · status / hash Chain of Custody
🏢

Victim / Target Organization

An individual or organization that suffered harm from the cybercrime — financial loss, data breach, service disruption, or reputational damage.

Name Organization Type · individual / company / government Industry / Sector Impact Type · financial / data / operational Estimated Loss Contact / POC Prior Incidents
🗂️

Digital Evidence

Any file, log, capture, or extracted artifact collected as evidence during the investigation. Maintains chain of custody and forensic integrity documentation.

Evidence Type · log / screenshot / malware / document / recording File Hash · MD5 / SHA-256 Collection Date Collected By Source · device / ISP / platform / dark web Chain of Custody Log Forensic Lab Status
💰

Financial Transaction

A financial record tied to the crime — a fraudulent transfer, ransom payment, cryptocurrency transaction, or proceeds of crime. Enables follow-the-money analysis across victim accounts and threat actor wallets.

Transaction Type · wire / crypto / payment card / ACH Amount / Currency Date / Time Sender Account / Wallet Recipient Account / Wallet Exchange / Platform Linked Threat Actor / Victim
📡

Communication Record

A captured communication between parties — phishing email, ransom demand, extortion message, or chat log from a dark web forum. Preserved as evidence and linked to sender/recipient profiles.

Channel · email / SMS / encrypted app / forum Sender Recipient Date / Time Content Summary Raw File · preserved attachment Linked Case / Threat Actor
🔎

Intelligence Report

A structured intelligence product produced from the investigation — a threat actor profile, IOC report, or tactical brief shared with partner agencies or prosecutors.

Report Type · IOC / TTP / threat actor / incident summary Classification Author / Unit Distribution · internal / partner agency / prosecutor Date Published Linked Cases / Threat Actors
Link Analysis · Key Relationships

How the Entities Connect

The relationship paths that surface attribution patterns and connect threat actor infrastructure across investigations — turning isolated incidents into a complete intelligence picture.

Threat Actor Digital Infrastructure

IP addresses, domains, email accounts, and cryptocurrency wallets are linked to the threat actor record — building a persistent infrastructure profile that survives case closure and surfaces when the same infrastructure appears in a new incident.

Digital Artifact Multiple Cases

When an IP address, domain, or wallet appears in a new case, Hubstream automatically surfaces every prior case involving that artifact — connecting incidents that were never linked at the time of investigation.

Online Profile Threat Actor Identity

Forum handles, social media accounts, and dark web identities are linked to the threat actor profile — building an identity graph that connects aliases across platforms and helps de-anonymize unknown suspects.

Financial Transaction Wallet / Account

Ransom payments and fraudulent transfers are traced through linked wallet and account records — following the money across exchanges and jurisdictions to identify where proceeds ultimately flow and who controls them.

Victim Prior Incidents

When a victim organization or individual appears in a new report, prior incidents involving them are surfaced — identifying repeat targeting patterns, previously compromised credentials, or ongoing threat actor access that pre-dates the new report.

Case Related Cases (TTPs / Infrastructure)

Cases involving the same malware family, attack infrastructure, or tactical patterns are linked automatically — helping investigators identify campaign-level activity and attribute multiple incidents to the same threat actor or group.

Device Threat Actor / Victim

A device seized as evidence or identified in network logs is linked to both the victim organization and any identified threat actor infrastructure — anchoring the forensic chain between attacker tooling and victim impact.

Communication Record Online Profile

Phishing emails, ransom demands, and dark web messages are linked to the sender's online profile and digital artifacts — turning individual communications into attribution data that connects the threat actor across channels.

Ready to build on this?

See the Template
Live in Hubstream

Request a demo and we'll walk you through how this workflow and data model work inside a real Hubstream environment — configured for your team's cyber crime types, jurisdictions, and investigative process.

Request a Demo → Back to All Templates