# Getting Started with Maltego: Complete Beginner Guide
Maltego is one of the most powerful open-source intelligence (OSINT) and graphical link analysis tools available today. Whether you are a penetration tester, threat intelligence analyst, law enforcement investigator, or simply someone curious about digital investigations, Maltego provides an intuitive visual interface for mapping relationships between people, companies, domains, IP addresses, and other entities across the internet.
Why Use Maltego for OSINT?
You need to connect the dots between domains, email addresses, IPs, and people � Maltego visualizes those relationships on an interactive graph. Instead of switching between a dozen separate tools, Maltego runs transforms that automatically query data sources and map results as interconnected nodes, turning hours of manual research into minutes of investigation.
Key Concepts
Before diving in, you need to understand several core concepts:
**Entities**: The building blocks of Maltego. Entities represent real-world objects like people, email addresses, phone numbers, domains, IP addresses, companies, and more. Each entity has a unique icon and set of properties.**Transforms**: These are the engines that gather information. A transform takes an input entity and produces related entities as output. For example, a transform might take a domain name and return all associated email addresses.**Graphs**: The visual workspace where entities and their relationships are displayed. Graphs are the primary interface for investigation work.**Machines**: Automated sequences of transforms that can be run without manual intervention, often used for large-scale data collection.Why Use Maltego?
Maltego offers several advantages over manual OSINT gathering:
**Visualization**: Complex relationships become immediately clear when displayed graphically**Automation**: Transforms automate data collection, saving hours of manual research**Integration**: Maltego connects to dozens of data sources through its Transform Hub**Documentation**: Investigations can be saved, exported, and shared with team members**Scalability**: From single-entity lookups to massive infrastructure mappings, Maltego scales to your needsCommon Use Cases
**Penetration Testing**: Mapping target infrastructure before an engagement**Threat Intelligence**: Tracking threat actors and their infrastructure**Fraud Investigation**: Connecting suspicious entities in financial crimes**Brand Protection**: Identifying phishing domains and impersonation attempts**Journalism**: Investigating corporate ownership and connections**Law Enforcement**: Building cases through digital evidence gatheringLaunching Maltego for the First Time
System Requirements
Before installing Maltego, ensure your system meets these requirements:
| Requirement | Minimum | Recommended |
|-------------|---------|-------------|
| RAM | 4 GB | 8 GB+ |
| Disk Space | 2 GB | 10 GB+ |
| Java | JDK 11+ | JDK 17+ |
| OS | Windows 10, macOS 10.14, Ubuntu 18.04 | Latest versions |
| Display | 1280x720 | 1920x1080+ |
First Launch Setup
When you first launch Maltego, you will be guided through a setup wizard:
**Account Creation**: You need a Maltego account to use the Community Edition. Visit [maltego.com](https://www.maltego.com) and create a free account.**Login**: Enter your credentials in the Maltego login screen. The Community Edition is free and provides access to a substantial set of transforms.**Transform Hub**: After logging in, Maltego will prompt you to install transforms from the Transform Hub. Start with the default set, which includes: - Maltego built-in transforms
- Shodan transforms
- VirusTotal transforms
- Have I Been Pwned transforms
**API Keys**: Some transforms require API keys. You can configure these later in the Transform Hub settings.Understanding Basic Entities
Maltego comes with a rich set of built-in entities. Here are the most commonly used ones:
Person Entities
**Person**: Represents an individual. Properties include full name, phone, email, and social media handles.**Social Network Profile**: Links to a person's social media accounts.Network Entities
**Domain**: A fully qualified domain name (e.g., example.com). This is often the starting point for network investigations.**DNS Name**: Subdomains and DNS records associated with a domain.**IPv4 Address**: An individual IP address.**IP Network**: A CIDR range of IP addresses.**MX Record**: Mail exchange records for a domain.**NS Record**: Name server records.Infrastructure Entities
**Web Server**: Identified web servers.**Service**: Open services on a host (e.g., HTTP, SSH, FTP).**Banner**: Service banners captured from open ports.Organization Entities
**Company**: A business entity with associated properties.**Autonomous System**: BGP autonomous system numbers.Email and Communication Entities
**Email Address**: Individual email addresses.**Phone Number**: Phone numbers associated with individuals or organizations.Running Your First Transform
Let's walk through a basic investigation to demonstrate Maltego's core workflow.
Step 1: Create a New Graph
Open MaltegoClick **File > New Graph** or press `Ctrl+N`A blank graph canvas appearsStep 2: Add a Seed Entity
In the Entity Palette (usually on the left side), find the **Domain** entityDrag it onto the graph canvasDouble-click the entity to edit its valueEnter a target domain (e.g., `example.com`)Press Enter to confirmStep 3: Run a Transform
Right-click on the Domain entityYou will see a context menu with available transformsSelect **To DNS Name - Quick** to discover subdomainsMaltego will execute the transform and display results as new entities connected to your seedStep 4: Expand Results
Select one or more of the resulting DNS Name entitiesRight-click and select another transform, such as **To IP Address**Continue expanding results to build a comprehensive mapStep 5: Analyze the Graph
As you run more transforms, the graph grows. Look for:
**Clusters**: Groups of entities that share many connections**Hub Nodes**: Entities with an unusually high number of connections**Outliers**: Entities that are isolated or minimally connected**Patterns**: Regular structures that might indicate organized infrastructurePractical Walkthrough: Investigating a Domain
Let's conduct a more thorough investigation of a domain to see Maltego in action.
Phase 1: Domain Reconnaissance
Starting entity: target-company.com
Transforms to run:
**To DNS Name - Full**: Discovers all subdomains - Result: 15-50 subdomains depending on the target
- Look for: staging, dev, test, admin, mail, vpn, remote
**To MX Record**: Identifies mail infrastructure - Result: Mail server hostnames and their IPs
- Insight: Often reveals cloud email providers (Google Workspace, Microsoft 365)
**To NS Record**: Identifies DNS infrastructure - Result: Name server hostnames
- Insight: May reveal hosting provider or DNS management platform
**To IP Address**: Maps domains to IP addresses - Result: IP addresses for each subdomain
- Insight: Multiple domains on the same IP may indicate shared hosting
Phase 2: Infrastructure Mapping
Take the IP addresses discovered in Phase 1 and run additional transforms:
**To IP Network**: Identifies the CIDR ranges**To ASN**: Maps IPs to autonomous systems**To Open Ports**: Discovers running services (if using Shodan transforms)Phase 3: Person and Email Discovery
If the target has web applications or public-facing services:
**To Email Address**: Discovers email addresses associated with the domain**To Person**: Identifies individuals linked to the domain**To Social Network Profile**: Maps social media presencePhase 4: Analysis
After running transforms, step back and analyze the graph:
**Identify key infrastructure**: Which servers host critical services?**Map relationships**: How are different subdomains connected?**Find weak points**: Are there forgotten or poorly maintained systems?**Document findings**: Use Maltego's notes feature to annotate entitiesNavigating the Graph
Maltego's graph interface provides several navigation tools:
Zoom and Pan
**Scroll wheel**: Zoom in and out**Click and drag**: Pan across the graph**Fit to screen**: Press `Ctrl+F` to fit all entities in viewSelection Tools
**Single click**: Select one entity**Ctrl+click**: Add entity to selection**Click and drag**: Select multiple entities (marquee selection)**Ctrl+A**: Select all entitiesLayout Options
Maltego offers several automatic layout algorithms:
**Hierarchical**: Arranges entities in layers (good for process flows)**Organic**: Spring-based layout that clusters related entities**Circular**: Arranges entities in circles (good for small graphs)**Tree**: Hierarchical tree layout (good for parent-child relationships)Access layouts through View > Layout or the layout toolbar.
Entity Styling
You can customize entity appearance:
Right-click an entitySelect **Set Color** to change its colorSelect **Set Size** to make it more prominentAdd notes by right-clicking and selecting **Edit Notes**Saving Your Work
Saving a Graph
Click **File > Save Graph** or press `Ctrl+S`Choose a location and filenameGraphs are saved as `.mtgx` files (Maltego Graph Exchange format)Creating a Workspace
Workspaces allow you to organize multiple related graphs:
Click **File > New Workspace**Name your workspaceAdd graphs to the workspaceShare workspaces with team members (requires Maltego Team or Enterprise)Exporting Results
Maltego supports several export formats:
| Format | Use Case |
|--------|----------|
| PDF | Reports and presentations |
| CSV | Data analysis in spreadsheets |
| GraphML | Import into other graph analysis tools |
| Image (PNG/SVG) | Documentation and presentations |
| HTML | Interactive reports |
To export: File > Export Graph and select your desired format.
Tips for Beginners
**Start small**: Begin with a single entity and expand methodically**Use bookmarks**: Mark important entities for quick reference**Take notes**: Document your findings as you go**Manage graph size**: Very large graphs can be overwhelming; use filters to focus**Learn transform categories**: Understanding what transforms do helps you plan investigations**Save frequently**: Maltego can crash with very large graphs; save your work often**Use the right entity type**: Choose the most specific entity type for your dataCommon Mistakes to Avoid
**Running too many transforms at once**: This can overwhelm the graph and make analysis difficult**Ignoring entity properties**: Always check entity properties for additional information**Not filtering results**: Use Maltego's filtering options to remove noise**Forgetting passive vs active**: Some transforms actively interact with targets; be aware of your legal boundaries**Not versioning your work**: Save different stages of your investigation as separate graphsNext Steps
Now that you understand the basics, consider exploring:
[Maltego Community Edition Guide](/learn/maltego-community-edition-guide) - Maximize your free toolset[Maltego Graph Analysis](/learn/maltego-graph-analysis) - Advanced graph interpretation techniques[Maltego Transforms Explained](/learn/maltego-transforms-explained) - Deep dive into the transform engine[OSINT Investigation Workflow](/learn/osint-investigation-workflow) - Structured investigation methodology[Passive OSINT Guide](/learn/passive-osint-guide) - Gathering intelligence without detectionConclusion
Maltego is an indispensable tool for anyone working in OSINT, cybersecurity, or investigations. Its visual approach to intelligence gathering makes complex relationships accessible and actionable. By mastering the basics covered in this guide, you have a solid foundation for more advanced investigation techniques.
Remember that effective OSINT is not just about tools, it is about methodology. Combine Maltego's technical capabilities with sound investigative practices, ethical considerations, and critical thinking to produce high-quality intelligence products.
The key to becoming proficient with Maltego is practice. Set up a home lab, investigate your own infrastructure, and gradually work up to more complex targets. Always operate within legal and ethical boundaries, and document your methodology for reproducibility.