01
What it is
Maltego is a link-analysis platform that represents an investigation as a graph of entities, such as domains, people, email addresses and companies, connected by transforms that query external data sources and add new linked entities automatically. It answers how disparate pieces of evidence relate to each other visually, rather than requiring an investigator to hold every connection in their head.
Where most OSINT tools return a list of results, Maltego builds those results as nodes on a graph and draws edges between them, letting an investigator see a network of relationships form as each transform runs. A domain entity can transform into its DNS records, which transform into hosting infrastructure, which transforms into other domains on the same server, all visible on one canvas.
Investigators use Maltego to map corporate structures, infrastructure relationships and social networks where the value lies in seeing the connections, not just the individual data points. The free Community Edition covers a substantial working set of transforms sufficient for most independent investigations.
When to use this guide
- Mapping relationships between domains, IP infrastructure and organisations visually
- Building a corporate structure graph from company registry and ownership data
- Visualising a social network from email addresses, usernames and associated accounts
- Presenting a complex investigation to stakeholders who need to see connections, not just a list of findings
- Running the same transform set repeatedly across multiple targets to standardise a workflow
02
How do you build an investigation graph in Maltego?
Seed the graph with a known entity, run transforms to expand it, and read the resulting network for meaningful clusters.
Free before paid. The Community Edition covers the workflow in this guide; the commercial tiers add transform volume limits removal and additional data integrations.
Maltego Community Edition: Free with registration. The desktop application used throughout this guide, with a working transform set covering DNS, WHOIS, social media and company data, subject to a per-transform results cap and a monthly credit allowance on the free Basic plan.
Maltego Transform Hub: Free and paid entries. A directory of additional transform integrations, some free with their own account and API key, others requiring a paid subscription to the underlying data provider.
Gephi: Free and open source. A complementary graph-visualisation tool for cases where a Maltego graph needs to be exported and re-analysed with different layout algorithms or for a larger node count than Maltego's interface comfortably handles.
Before you begin
Stop at the login
Maltego Community Edition requires free registration with an email address before the desktop application can be activated. Some individual transforms in the Transform Hub require their own separate account and API key with the underlying data provider; the graph will show which transforms are unavailable until configured.
Legal considerations
Maltego only aggregates and visualises data its transforms retrieve from otherwise public or authorised sources; it does not itself bypass access controls. Some paid transform integrations query commercial data brokers whose own terms of use and jurisdictional restrictions apply independently of Maltego's licence, so check the source of any transform before relying on its output in a jurisdiction with strict data protection rules.
The method
01
Install Maltego CE and register for a free account
Goal · Get the desktop application activated before building any graph
Download the Community Edition installer, create a free account through Maltego's registration page, and activate the application. This step-by-step activation is required before any transform will run.
02
Seed the graph with a known starting entity
Goal · Establish the anchor point the rest of the investigation expands from
Create an entity for your starting point, such as a domain, person or email address, dragging the appropriate entity type onto the canvas and entering the known value.
03
Run relevant transforms on the seed entity
Goal · Expand the graph with the first layer of connected data
Right-click the entity and select from the available transforms, such as "To DNS Name" for a domain or "To Email Address" for a person. Each transform run adds new connected entities to the canvas as nodes.
04
Expand promising nodes iteratively
Goal · Follow the graph outward from the most relevant new entities
Rather than running every transform on every node, prioritise expanding entities that appear central or unusual. Maltego's free tier caps results per transform, so scope expansion deliberately rather than running broad transforms on every node at once.
05
Identify clusters and central nodes
Goal · Read the graph for structurally significant relationships
Use Maltego's layout views to identify nodes with unusually high connectivity, which often represent shared infrastructure, a central individual, or a hub organisation worth investigating further outside the graph itself.
06
Export the graph and underlying data
Goal · Preserve the investigation output independent of the live application session
Export the graph as an image for reporting and as a structured file (such as CSV of entities) for further analysis, since a Maltego project file alone is not easily reviewable without the application installed.
03
What false positives affect Maltego investigations?
Graph-based analysis introduces its own reading errors distinct from single-tool lookups.
Shared infrastructure is not shared ownership: A transform showing two domains on the same IP or hosting provider frequently reflects nothing more than both using a large shared hosting service, not a meaningful relationship between the domain owners.
Verifying check: Check whether the shared IP belongs to a known large-scale hosting or CDN provider before treating co-location as evidence of a connection.
Transform data source freshness varies widely: Different transforms query data of very different ages, from real-time DNS lookups to WHOIS records that may reflect a registration from years earlier and no longer be current.
Verifying check: Check each transform's documented data source and, where possible, the record's own timestamp before treating all nodes on a graph as equally current.
Visual centrality is not the same as investigative significance: A node with many connections can simply be a common, low-significance entity, such as a widely used free email provider's domain, rather than a meaningful hub.
Verifying check: Manually assess whether a highly connected node is generic and expected (a major email provider, a popular CMS) before treating its centrality as a significant finding.
Free-tier result caps truncate the picture silently: The Community Edition limits results per transform run, meaning a domain with hundreds of subdomains may show only the capped subset with no clear indication more exist.
Verifying check: Check the transform's documented result limit and, for high-value targets, supplement with a dedicated tool that has no such cap, such as a direct DNS enumeration tool, to confirm the graph is not truncated.
Chain of custody: A Maltego graph reflects live queries at the time each transform ran, and the underlying data sources can change independently. Document the graph state and export it promptly rather than treating the live application session as a permanent record.
Export the completed graph as both an image and a structured data file (CSV or GraphML).
Record which transforms were run and the date and time each ran.
Note the Maltego edition and transform data sources used, since paid Transform Hub integrations may not be reproducible by a reviewer without the same subscriptions.
Independently archive the primary source behind any high-value node, rather than citing the graph node alone as evidence.
Save the Maltego project file alongside the exports for full reproducibility.
04
Go deeper
Reference cards, structured tutorials and tools for practitioners who want to build on this guide.
CARD · DIG-001
WHOIS investigation: domain name to attribution chain.
ViewDNS, SecurityTrails and crt.sh. Registrant email pivots that map infrastructure and hosting networks.
CARD · OPS-001
OPSEC for investigators: eight-step baseline.
Signal, Mullvad and ProtonMail. Device separation and session documentation to chain-of-custody standard.
Evidentiary standard
Signal & Shadow operates to the LST-001 evidentiary standard. All claims are graded against the LST-001 v1.0.3 confidence tiers (Confirmed, Corroborated, Reported, Alleged) per the canonical voice and structural specification.
About Signal & Shadow
Signal & Shadow is an independent forensic investigation and methodology practice publishing tutorials, reference cards, and forensic dossiers for working practitioners. Founded by Derek Bowler.




