GO KALI FREE
IntermediateOSINT

Link Analysis Fundamentals: Mapping Relationships in OSINT

Understand the fundamentals of link analysis for OSINT investigations. Learn graph theory basics, node and edge types, pattern recognition, and investigative techniques using Maltego.

#link-analysis#graph-theory#pattern-recognition#maltego#investigation#network-analysis

# Link Analysis Fundamentals: Mapping Relationships in OSINT

Link analysis is the process of identifying and visualizing relationships between entities. In OSINT, link analysis transforms scattered data points into coherent intelligence pictures. What follows examines the theoretical foundations and practical applications of link analysis, with focus on how [Maltego](/tools/maltego) implements these concepts.

Relationship Intelligence

Link analysis is a methodology for extracting intelligence from the connections between entities. Every relationship — between people, domains, IP addresses, organizations — creates a data point that can be analyzed for patterns. This graph-based approach transforms scattered data into structured intelligence by revealing hidden connections, hubs, and clusters that define how a target network operates.

Graph Theory Basics

Understanding basic graph theory concepts enhances your link analysis capabilities.

Types of Graphs

Undirected Graphs

Connections have no direction — if A is connected to B, B is also connected to A.

Example: Social friendships (if you are my friend, I am your friend)

Directed Graphs

Connections have direction — A connecting to B does not mean B connects to A.

Example: Email communication (if I emailed you, you did not necessarily email me)

Weighted Graphs

Connections have associated values indicating strength or importance.

Example: Communication frequency (how often two people interact)

Labeled Graphs

Both entities and connections have descriptive labels.

Example: Organizational charts (person > "reports to" > manager)

Graph Properties

| Property | Description | Investigation Use |

|----------|-------------|-------------------|

| Density | Ratio of actual to possible connections | Network tightness |

| Diameter | Longest shortest path between any two nodes | Network reach |

| Clustering Coefficient | Tendency of nodes to form clusters | Community detection |

| Degree Distribution | Distribution of connection counts | Hub identification |

| Connected Components | Isolated subgraphs | Separate investigations |

Centrality Measures

Centrality measures identify the most important nodes in a network.

Degree Centrality

The number of direct connections a node has.

Formula: C_D(v) = deg(v) / (n-1)

Interpretation: High degree = many direct connections = potentially important hub

Use case: Identifying key communicators, popular services, central infrastructure

Betweenness Centrality

How often a node appears on shortest paths between other nodes.

Formula: C_B(v) = sum of sigma_st(v) / sigma_st

Interpretation: High betweenness = controls information flow = bridge or gatekeeper

Use case: Identifying intermediaries, bottlenecks, critical infrastructure

Closeness Centrality

The average distance from a node to all other nodes.

Formula: C_C(v) = (n-1) / sum of d(v,u)

Interpretation: High closeness = can reach everyone quickly = central position

Use case: Identifying central services, key people in organizations

Eigenvector Centrality

How connected a node is to other well-connected nodes.

Interpretation: High eigenvector = connected to other important nodes = influential

Use case: Identifying influential people, critical infrastructure

Network Patterns

| Pattern | Appearance | Interpretation |

|---------|------------|----------------|

| Star | One hub, many spokes | Central service or person |

| Chain | Linear sequence | Process or hierarchy |

| Cluster | Dense group | Related entities |

| Bridge | Single connection between groups | Intermediary |

| Ring | Closed loop | Circular dependency |

| Tree | Branching hierarchy | Organizational structure |

Node Types in OSINT

Different entity types serve different analytical purposes.

Person Nodes

| Entity | Properties | Investigation Value |

|--------|------------|---------------------|

| Person | Name, aliases, DOB | Identity verification |

| Email | Address, domain | Communication mapping |

| Phone | Number, carrier | Identity linkage |

| Username | Platform, handle | Cross-platform mapping |

| Social Profile | Platform, URL | Social network mapping |

Infrastructure Nodes

| Entity | Properties | Investigation Value |

|--------|------------|---------------------|

| Domain | Name, registrar | Ownership identification |

| IP Address | Address, geolocation | Infrastructure mapping |

| Netblock | CIDR, ASN | Network ownership |

| Service | Port, protocol, banner | Capability assessment |

| Certificate | Issuer, SAN | Identity and hosting |

Organization Nodes

| Entity | Properties | Investigation Value |

|--------|------------|---------------------|

| Company | Name, jurisdiction | Corporate structure |

| ASN | Number, organization | Network ownership |

| Certificate Authority | Name, trust level | Identity verification |

Content Nodes

| Entity | Properties | Investigation Value |

|--------|------------|---------------------|

| Website | URL, technology | Web presence mapping |

| Document | Title, content | Information discovery |

| Image | Source, metadata | Attribution analysis |

Edge Types in OSINT

Edges represent the nature of relationships between entities.

Relationship Categories

| Relationship | Example | Investigation Value |

|-------------|---------|---------------------|

| Ownership | Person > owns > Domain | Attribution |

| Hosting | Domain > hosted on > IP | Infrastructure |

| Resolution | Domain > resolves to > IP | Technical mapping |

| Communication | Person > emails > Person | Social mapping |

| Membership | Person > member of > Group | Association |

| Employment | Person > works for > Company | Professional mapping |

| Creation | Person > created > Document | Attribution |

Edge Properties

Edges can carry additional information:

  • **Weight**: Strength of relationship (e.g., communication frequency)
  • **Type**: Nature of connection (e.g., "reports to", "owns")
  • **Direction**: One-way or bidirectional
  • **Timestamp**: When the relationship was established
  • **Confidence**: Reliability of the relationship data
  • Edge Analysis Techniques

  • **Path Analysis**: Find all paths between two entities
  • **Shortest Path**: Identify the most direct connection
  • **Path Counting**: Count the number of paths between entities
  • **Flow Analysis**: Track how information flows through the network
  • **Cut Analysis**: Identify critical connections whose removal would disconnect the graph
  • Maltego's Approach to Link Analysis

    Maltego implements link analysis through its visual graph interface and transform system.

    Entity Representation

    In Maltego, entities appear as nodes with:

  • **Icon**: Visual representation of entity type
  • **Label**: Primary value (e.g., domain name)
  • **Properties**: Additional attributes
  • **Color**: User-defined or type-based coloring
  • **Size**: Can be adjusted for emphasis
  • Relationship Representation

    Edges in Maltego show:

  • **Line**: Connection between entities
  • **Arrow**: Direction of relationship (when applicable)
  • **Label**: Relationship type (e.g., "resolves to")
  • **Style**: Solid, dashed, or colored based on relationship type
  • Transform-Based Discovery

    Maltego discovers relationships through transforms:

  • You provide an input entity
  • A transform queries data sources
  • Related entities are returned as output
  • Edges are automatically created between input and output
  • Graph Layouts for Link Analysis

    | Layout | Best For | Analysis Type |

    |--------|----------|---------------|

    | Organic | Natural clustering | General analysis |

    | Hierarchical | Parent-child relationships | Structure analysis |

    | Circular | Complete relationship view | Network analysis |

    | Tree | Hierarchical structures | Taxonomy analysis |

    Pattern Recognition Techniques

    Recognizing patterns in link analysis graphs is a critical skill.

    Structural Patterns

    Hub Detection

    Identify nodes with unusually high degree centrality.

    In Maltego: Look for nodes with many connections radiating outward.

    Significance: May indicate critical infrastructure, key people, or shared services.

    Bridge Detection

    Find nodes that connect otherwise separate clusters.

    In Maltego: Look for single nodes linking different graph regions.

    Significance: May indicate intermediaries, shared resources, or connection points.

    Cluster Detection

    Identify tightly connected groups of entities.

    In Maltego: Look for dense groups with many internal connections.

    Significance: May indicate related organizations, social groups, or infrastructure.

    Chain Detection

    Find linear sequences of connected entities.

    In Maltego: Look for node > node > node sequences.

    Significance: May indicate processes, hierarchies, or resolution chains.

    Attribute Patterns

    Shared Attributes

    Multiple entities sharing common properties.

    Example: Multiple domains sharing the same WHOIS registrant.

    Significance: Indicates common ownership or coordination.

    Unique Attributes

    Entities with distinctive properties.

    Example: A domain with an unusual TLD or registration pattern.

    Significance: May indicate special purpose or anomaly.

    Temporal Patterns

    Changes or patterns over time.

    Example: Domains registered in quick succession.

    Significance: May indicate coordinated activity or planning.

    Behavioral Patterns

    Communication Patterns

    Who communicates with whom, how often, and when.

    Significance: Reveals social structure, influence patterns, and relationships.

    Activity Patterns

    When and how entities are active.

    Significance: Reveals operational patterns, time zones, and routines.

    Growth Patterns

    How the network changes over time.

    Significance: Reveals expansion, contraction, and evolution.

    Investigative Techniques

    Seed and Expand

    Start with a known entity and expand outward:

  • **Seed**: Place a known entity on the graph
  • **Expand**: Run transforms to discover related entities
  • **Analyze**: Identify patterns and key nodes
  • **Repeat**: Use new findings as seeds for further expansion
  • Link Tracing

    Follow specific relationship types through the graph:

  • **Forward Tracing**: Follow edges from source to destination
  • **Backward Tracing**: Follow edges from destination to source
  • **Bidirectional Tracing**: Follow edges in both directions
  • **Filtered Tracing**: Follow only specific relationship types
  • Cluster Analysis

    Examine groups of related entities:

  • **Identify Clusters**: Find naturally occurring groups
  • **Analyze Internal Structure**: How are cluster members connected?
  • **Examine External Connections**: How does the cluster connect to other clusters?
  • **Compare Clusters**: What similarities and differences exist?
  • Path Analysis

    Find and analyze paths between entities:

  • **Shortest Path**: Most direct connection between two entities
  • **All Paths**: Every possible route between two entities
  • **Critical Paths**: Paths that are the only connection between regions
  • **Weighted Paths**: Paths based on relationship strength
  • Temporal Analysis

    Analyze how relationships change over time:

  • **Timeline Construction**: Build a timeline of entity appearances
  • **Change Detection**: Identify when relationships form or break
  • **Pattern Recognition**: Find temporal patterns in activity
  • **Forecasting**: Predict future changes based on patterns
  • Advanced Link Analysis

    Community Detection

    Algorithms that identify naturally occurring communities in graphs:

  • **Modularity Optimization**: Find communities that maximize modularity
  • **Label Propagation**: Propagate labels to identify communities
  • **Girvan-Newman**: Edge betweenness-based community detection
  • **Louvain Method**: Greedy optimization for community detection
  • Network Metrics

    Calculate advanced metrics for deeper analysis:

  • **Clustering Coefficient**: Tendency of nodes to cluster
  • **Assortativity**: Preference for nodes to connect to similar nodes
  • **Transitivity**: Probability that connected nodes share connections
  • **Reciprocity**: Tendency for bidirectional relationships
  • Dynamic Analysis

    Analyze how networks change over time:

  • **Snapshot Analysis**: Compare graphs at different time points
  • **Edge Dynamics**: Track when edges appear and disappear
  • **Node Dynamics**: Track when nodes appear and disappear
  • **Growth Models**: Model how the network evolves
  • Practical Application

    Investigation Workflow

  • **Define Scope**: What entities and relationships are in-scope?
  • **Collect Data**: Gather information from multiple sources
  • **Build Graph**: Import data into Maltego or similar tool
  • **Apply Layout**: Choose appropriate graph layout
  • **Identify Patterns**: Look for structural and behavioral patterns
  • **Analyze Key Nodes**: Examine high-centrality entities
  • **Trace Relationships**: Follow important connection paths
  • **Document Findings**: Record methodology and results
  • **Report**: Present findings with visualizations
  • Quality Criteria

    Evaluate your link analysis using these criteria:

  • **Completeness**: Are all relevant entities included?
  • **Accuracy**: Is the data correct and verified?
  • **Timeliness**: Is the data current and relevant?
  • **Relevance**: Does the analysis address the objectives?
  • **Clarity**: Is the presentation clear and understandable?
  • Conclusion

    Link analysis is a fundamental skill for OSINT investigations. Understanding graph theory basics, node and edge types, pattern recognition, and investigative techniques provides a solid foundation for effective intelligence analysis.

    [Maltego](/tools/maltego) implements these concepts through its visual graph interface and transform system, making link analysis accessible and powerful. Combine theoretical knowledge with practical application to develop your link analysis capabilities.

    For related topics, explore [Maltego Graph Analysis](/learn/maltego-graph-analysis) for Maltego-specific techniques and [Entity Relationship Mapping](/learn/entity-relationship-mapping) for structured relationship analysis.

    Frequently Asked Questions

    What is link analysis in OSINT?

    Link analysis is a data analysis technique that identifies and visualizes relationships between entities by examining their connections. In OSINT, it transforms scattered data points into coherent intelligence pictures using graph theory principles.

    What is the difference between nodes and edges in link analysis?

    Nodes (entities) represent discrete objects being analyzed (people, domains, IPs). Edges (relationships) represent connections between entities (email sent, resolves to, associated with). Together they form a network showing intelligence relationships.

    What is graph theory and how does it apply to OSINT?

    Graph theory is the mathematical study of networks. In OSINT, it provides the foundation for analyzing entity relationships, identifying key nodes, detecting clusters, and finding patterns in complex intelligence data using concepts like centrality and connectivity.

    How does Maltego implement link analysis?

    Maltego provides a visual graph interface where entities appear as nodes and relationships as edges. It uses force-directed layouts to naturally cluster related entities, making patterns and connections visible that would be hidden in tabular data.

    What are the key graph analysis patterns to look for?

    Look for hub nodes (entities with many connections indicating high-value targets), clusters (groups of tightly connected entities), bridges (entities connecting different clusters), and isolated nodes (potential outliers or disconnected infrastructure).

    What is node centrality and why does it matter?

    Node centrality measures how important a node is within a network. High centrality nodes (many connections, central position) are often high-value targets or key infrastructure. It helps prioritize investigation focus on the most significant entities.

    How do you identify clusters in link analysis?

    Clusters are groups of entities with dense internal connections. In Maltego, force-directed layouts naturally group clusters. Look for spatial groupings of same-type entities, repeated relationship patterns, and subgraphs that form distinct communities.

    What is the difference between directed and undirected graphs?

    Directed graphs have one-way connections (A emails B doesn't mean B emails A). Undirected graphs have bidirectional connections (A is friends with B means B is friends with A). The direction affects analysis patterns and path finding.

    How do you handle large link analysis graphs?

    Use entity filtering to focus on relevant types, create separate graphs for different investigation phases, apply graph filters to reduce noise, use hierarchical views, and leverage Maltego's organizational features to manage complexity.

    What tools complement Maltego for link analysis?

    Gephi provides advanced network analysis with statistical metrics, NetworkX offers Python-based graph algorithms, Analyst's Notebook is used in law enforcement, and i2 Analyst's Notebook provides intelligence-focused visualization for complex investigations.