Skip to content

Maltego Framework

Maltego is a powerful tool for link analysis and OSINT data visualization, enabling analysts to map relationships between entities such as people, organizations, and digital footprints. Its framework combines graph-based visualization, data transformation rules, and integration with external data sources to uncover hidden connections in complex datasets. This section provides hands-on guidance on leveraging Maltego’s framework and data mapping capabilities for offensive security research and defensive analysis.


Framework Components and Core Functionality

Maltego’s architecture revolves around three core components:
1. Graph Interface: A visual representation of entities (nodes) and their relationships (edges).
2. Data Sources: External APIs or databases that provide structured data (e.g., Twitter, WHOIS, Shodan).
3. Transformation Rules: Scripts that process raw data into nodes and edges.

To begin, configure data sources and define transformations to automate data ingestion. For example, to add a data source:

# Example: Add a Twitter data source (requires API credentials)  
Add Data Source Twitter  


Data Mapping and Transformation Logic

Data mapping in Maltego involves converting raw data into actionable graph nodes. This is achieved through transformation rules, which are written in a domain-specific language (DSL) and executed via .xsl files or inline scripts.

Example: Mapping a Domain to Subdomains

  1. Use the "Domain" data source to collect subdomains.
  2. Apply a transformation rule to extract and visualize subdomains:
    <Transformation name="Extract Subdomains" from="Domain" to="Subdomain">  
      <Input>  
        <Field name="domain" type="string" />  
      </Input>  
      <Output>  
        <Field name="subdomain" type="string" />  
      </Output>  
      <Script>  
        // Pseudocode: Extract subdomains from a domain  
        subdomains = parse_subdomains(domain)  
        for subdomain in subdomains:  
            add_node(subdomain)  
      </Script>  
    </Transformation>  
    

This process allows analysts to map a single domain to its subdomains, revealing potential attack surfaces or network structures.


  1. Collect Data: Use Maltego’s built-in data sources (e.g., Twitter, LinkedIn) to gather public information.
  2. Transform Data: Apply transformations to convert raw data into nodes (e.g., users, IP addresses).
  3. Analyze Relationships: Use the graph interface to identify clusters, anomalies, or indirect connections.
  4. Export Results: Save the graph or export data for further analysis.

Example Workflow:

# Step 1: Start with a target domain  
Start New Case  
Add Data Source Domain  
Enter domain: example.com  

# Step 2: Transform domain to subdomains  
Transform Domain -> Subdomain  

# Step 3: Export subdomains to a CSV file  
Export Data -> CSV  

This workflow demonstrates how Maltego can automate the discovery of networked assets and relationships.


Key Takeaways

  • Maltego’s graph-based interface simplifies the visualization of complex OSINT data.
  • Data mapping relies on transformation rules to convert raw data into actionable insights.
  • Integration with external data sources enables scalable link analysis for offensive and defensive research.
  • Always ensure legal compliance and authorization when collecting and analyzing data.
  • Custom transformations and automation are critical for handling large-scale datasets efficiently.