MALTEGO
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
Maltego is a powerful OSINT and graphical link analysis tool for gathering and connecting information. It provides a GUI for investigating relationships between people, companies, domains, IP addresses, infrastructure, and more.
EDITIONS#
# Maltego CE (Community Edition) - Free, limited transforms # Maltego Classic - Commercial, full transforms # Maltego XL - Large-scale investigations # CaseFile - Offline analysis only
CORE CONCEPTS#
# Entity - A node (domain, IP, person, email, etc.) # Transform - An action that queries data and creates new entities # Graph - Visual representation of entities and relationships # Machine - Automated sequence of transforms
COMMON ENTITIES#
# Infrastructure: # - Domain, DNS Name, IP Address, Netblock # - NS Record, MX Record, Website, URL # Personal: # - Person, Email Address, Phone Number # - Alias, Social Media Profile # Organization: # - Company, Organization, Location # Technical: # - Technology, Banner, Port, Service # - Hash, Document, Image
ESSENTIAL TRANSFORMS#
# Domain transforms: # Domain → DNS Names (subdomains) # Domain → MX Records # Domain → NS Records # Domain → IP Address # Domain → WHOIS info # Domain → Website Technologies # IP Address transforms: # IP → Reverse DNS # IP → Geolocation # IP → Netblock # IP → ASN/BGP # IP → Open Ports # Email transforms: # Email → Person # Email → Domain # Email → Social Media profiles # Email → Breach data # Person transforms: # Person → Email addresses # Person → Phone numbers # Person → Social media # Person → Companies
MACHINES (AUTOMATED)#
# Built-in machines: # Company Stalker - Find emails, then check social media # Footprint L1 - Basic domain footprint # Footprint L2 - Medium domain footprint # Footprint L3 - Deep domain footprint # Person - Email - Find email from person info # Twitter Digger - Twitter account analysis
KEYBOARD SHORTCUTS#
# Ctrl+T - Run transform # Ctrl+R - Run machine # Ctrl+A - Select all entities # Ctrl+F - Find entity in graph # Ctrl+L - Change layout # Ctrl+S - Save graph # Delete - Remove selected entity
GRAPH LAYOUTS#
# Block Layout - Grid arrangement # Hierarchical Layout - Tree structure # Circular Layout - Radial arrangement # Organic Layout - Force-directed graph # Interactive Layout - Manual positioning
WORKFLOW EXAMPLE#
# 1. Create new graph # 2. Drag target entity (domain) onto canvas # 3. Right-click → Run transform → DNS enumeration # 4. Select discovered entities # 5. Run additional transforms (IP lookup, whois, etc.) # 6. Analyze relationships in the graph # 7. Export results
TRANSFORM HUBS#
# Shodan - Internet-connected device search # VirusTotal - Malware and URL analysis # Have I Been Pwned - Breach data # PassiveTotal - Passive DNS and WHOIS # Censys - Internet scan data # Social Links - Social media OSINT # ThreatCrowd - Threat intelligence
EXPORT OPTIONS#
# File → Export → CSV # File → Export → XLS # File → Export → PDF (graph image) # File → Export → GraphML # Copy → Entity list to clipboard
TIPS#
# - Start simple, expand gradually # - Use "Select by type" to manage large graphs # - Set transform limits to avoid overwhelming graphs # - Use notes on entities for documentation # - Color-code entities for visual organization # - Save regularly - large graphs can be resource-intensive # - Use bookmarks for important entities
NOTES#
- Java-based application (cross-platform) - Community Edition has transform limits - API keys required for many transform hubs - Can generate large amounts of data quickly - Respect API rate limits of transform providers - Results should be verified through additional sources - Useful for both offensive recon and defensive threat intel