GO KALI FREE
IntermediateMaltego

Maltego Graph Analysis: Reading & Interpreting Investigation Graphs

Master the art of reading and interpreting Maltego investigation graphs. Learn graph layouts, entity relationships, pattern recognition, and how to extract actionable intelligence from complex visualizations.

#maltego#graph-analysis#link-analysis#pattern-recognition#visualization#osint

# Maltego Graph Analysis: Reading & Interpreting Investigation Graphs

The power of Maltego lies not just in data collection but in how that data is visualized and analyzed. A well-constructed investigation graph reveals patterns, relationships, and insights that would be invisible in raw data tables. This guide teaches you how to read, interpret, and analyze Maltego graphs to extract maximum value from your investigations.

Understanding Graph Structure

A Maltego graph consists of two fundamental components:

  • **Nodes (Entities)**: Represent real-world objects (people, domains, IPs, etc.)
  • **Edges (Relationships)**: Represent connections between entities
  • Together, nodes and edges form a network that maps the relationships between different pieces of intelligence.

    Node Properties

    Every node in a Maltego graph has:

  • **Type**: The entity type (Domain, IP Address, Person, etc.)
  • **Value**: The primary identifying value (e.g., "example.com")
  • **Properties**: Additional attributes (e.g., registrar, creation date, ports)
  • **Visual Attributes**: Color, size, and icon based on type and configuration
  • **Notes**: User-added annotations
  • Edge Properties

    Edges connecting nodes have:

  • **Type**: The relationship type (e.g., "resolves to", "associated with")
  • **Direction**: Some edges are directed (one-way), others are bidirectional
  • **Weight**: Indicates strength of connection (in some analysis contexts)
  • **Label**: Descriptive text for the relationship
  • Graph Layout Algorithms

    Maltego offers several layout algorithms, each suited to different analysis scenarios.

    Organic Layout

    The default and most commonly used layout. Uses a force-directed algorithm where:

  • Connected nodes attract each other
  • All nodes repel each other
  • The result is a natural-looking cluster
  • Best for:

  • General investigation analysis
  • Identifying natural clusters
  • Presenting findings to non-technical audiences
  • How to apply: View > Layout > Organic (or click the Organic layout button in the toolbar)

    Hierarchical Layout

    Arranges nodes in layers based on their relationships:

  • Top-level entities appear at the top
  • Dependent entities appear below their parents
  • Creates a tree-like structure
  • Best for:

  • Domain hierarchy analysis (domain > subdomain > IP)
  • Organizational structure mapping
  • Process flow visualization
  • How to apply: View > Layout > Hierarchical

    Circular Layout

    Arranges all nodes in a circle:

  • Equal spacing between all nodes
  • Edges shown as lines or curves between nodes
  • Good for seeing all connections simultaneously
  • Best for:

  • Small to medium graphs (under 100 nodes)
  • Identifying highly connected nodes
  • Relationship overview
  • How to apply: View > Layout > Circular

    Tree Layout

    Arranges nodes in a strict tree structure:

  • One root node at the top
  • Children arranged below
  • Strict parent-child relationships
  • Best for:

  • DNS hierarchy visualization
  • Organizational charts
  • Taxonomy mapping
  • How to apply: View > Layout > Tree

    Layout Comparison

    | Layout | Strength | Weakness | Graph Size |

    |--------|----------|----------|------------|

    | Organic | Natural clustering | Can overlap at scale | Any |

    | Hierarchical | Clear parent-child | Forced hierarchy | Medium |

    | Circular | All connections visible | Messy with many edges | Small |

    | Tree | Clean hierarchy | Only works for trees | Small-Medium |

    Entity Types and Their Significance

    Understanding what different entity types represent helps you interpret graphs more effectively.

    Network Entities

    | Entity | Represents | Key Insight |

    |--------|------------|-------------|

    | Domain | A registered domain | Entry point for network investigations |

    | DNS Name | Subdomain | Reveals infrastructure structure |

    | IPv4 Address | Individual IP | Maps to physical/virtual infrastructure |

    | IP Network | CIDR range | Shows network boundaries |

    | MX Record | Mail server | Reveals email infrastructure |

    | NS Record | Name server | Shows DNS management |

    | Website | Web application | Identifies web presence |

    Person Entities

    | Entity | Represents | Key Insight |

    |--------|------------|-------------|

    | Person | Individual | Central figure in people investigations |

    | Email Address | Contact point | Links person to services and accounts |

    | Phone Number | Contact method | Additional linkage to identity |

    | Social Profile | Online presence | Reveals social connections |

    Organization Entities

    | Entity | Represents | Key Insight |

    |--------|------------|-------------|

    | Company | Business entity | Parent organization |

    | ASN | Autonomous system | Network ownership |

    | Certificate | SSL/TLS cert | Infrastructure and identity |

    Pattern Recognition in Graphs

    The true value of graph analysis is recognizing patterns that reveal meaningful information.

    Star Pattern

    A central node connected to many peripheral nodes.

    Appearance: One hub node with spokes radiating outward

    Interpretation:

  • A central server hosting multiple services
  • A key person with many contacts
  • A domain with many subdomains
  • Example: A company domain connected to 50 subdomains indicates extensive infrastructure.

    Chain Pattern

    Nodes connected in a linear sequence.

    Appearance: Node > Node > Node > Node

    Interpretation:

  • DNS resolution chain
  • Proxy or redirect chain
  • Organizational hierarchy
  • Example: Domain > Subdomain > IP > Netblock > ASN shows the full network chain.

    Cluster Pattern

    Dense groups of interconnected nodes.

    Appearance: Tight groups with many internal connections, few external connections

    Interpretation:

  • Related infrastructure (same hosting provider)
  • Social groups (colleagues, friends)
  • Related services (application stack)
  • Example: Multiple domains on the same IP range with shared email addresses may indicate related businesses.

    Bridge Pattern

    A node that connects two otherwise separate clusters.

    Appearance: A single node linking two groups

    Interpretation:

  • Shared infrastructure between organizations
  • Common service provider
  • Key individual linking different groups
  • Example: A shared email address across two domains suggests common ownership.

    Hub-and-Spoke Pattern

    A highly connected central node with many one-hop connections.

    Appearance: Dense center with sparse periphery

    Interpretation:

  • Critical infrastructure component
  • Key person in an organization
  • Primary domain in a portfolio
  • Example: A single IP hosting many domains may be a shared hosting server.

    Ring Pattern

    Nodes connected in a closed loop.

    Appearance: Circular connections with no clear start or end

    Interpretation:

  • Circular dependencies
  • Redundant infrastructure
  • Complex social relationships
  • Example: DNS resolution chains that loop back indicate potential configuration issues.

    Identifying Key Nodes

    Not all nodes in a graph are equally important. Identifying key nodes helps focus your analysis.

    Degree Centrality

    The number of direct connections a node has.

    High degree nodes are likely:

  • Critical infrastructure (main servers, DNS providers)
  • Key individuals (decision makers, administrators)
  • Hub services (shared hosting, email providers)
  • How to find: Visually identify nodes with the most connections

    Betweenness Centrality

    How often a node appears on the shortest path between other nodes.

    High betweenness nodes are likely:

  • Bridge points between organizations
  • Critical infrastructure (routers, proxies)
  • Intermediaries in communication chains
  • How to find: Look for nodes that connect otherwise separate clusters

    Closeness Centrality

    How close a node is to all other nodes in the graph.

    High closeness nodes are likely:

  • Central services that everything depends on
  • Key people who communicate with everyone
  • Core infrastructure components
  • How to find: Nodes that are centrally located in the graph

    Eigenvector Centrality

    How connected a node is to other well-connected nodes.

    High eigenvector nodes are likely:

  • Important within important clusters
  • Key decision-makers in organizations
  • Critical infrastructure in major networks
  • How to find: Nodes that are connected to other highly connected nodes

    Filtering and Focusing

    As graphs grow large, filtering helps focus on relevant subsets.

    Entity Type Filtering

  • Right-click on the graph background
  • Select **Filter Entities**
  • Choose which entity types to show/hide
  • Apply filter
  • Property-Based Filtering

  • Select entities to filter
  • Right-click > **Select Similar**
  • Choose property to match on
  • All entities with matching property values are selected
  • Transform-Based Filtering

  • Select a set of entities
  • Run a transform on the selection
  • Only the results from that selection appear
  • Use this to drill down into specific subsets
  • Manual Filtering

  • Select entities manually (Ctrl+click or marquee select)
  • Right-click > **Remove Unselected**
  • Only selected entities remain
  • Use Ctrl+Z to undo if needed
  • Reading Complex Graphs

    When faced with a large, complex graph, follow this systematic approach.

    Step 1: Get the Big Picture

  • Fit the entire graph to screen (Ctrl+F)
  • Identify major clusters and their sizes
  • Note the overall structure (organic, hierarchical, mixed)
  • Identify the dominant entity types
  • Step 2: Identify Patterns

    Look for the patterns described above:

  • Star patterns (hubs)
  • Chains (sequences)
  • Clusters (groups)
  • Bridges (connections between groups)
  • Step 3: Find Key Nodes

  • Identify nodes with the most connections
  • Look for bridge nodes between clusters
  • Note nodes that appear centrally located
  • Check for nodes with unique properties
  • Step 4: Trace Relationships

  • Follow connections from key nodes
  • Trace chains from start to end
  • Map relationships between clusters
  • Identify shared attributes
  • Step 5: Document Findings

  • Add notes to important entities
  • Color-code nodes by finding or category
  • Export key findings to a report
  • Save intermediate graphs for reference
  • Practical Analysis Examples

    Example 1: Domain Infrastructure Analysis

    Graph: A domain with 20 subdomains, each resolving to IPs, which connect to netblocks and ASNs.

    Analysis steps:

  • Identify the main domain (hub node)
  • Group subdomains by IP address (shared hosting detection)
  • Identify unique IPs (dedicated infrastructure)
  • Map netblocks to ASNs (network ownership)
  • Look for anomalies (unusual IPs, foreign ASNs)
  • Findings to look for:

  • Staging or development subdomains (potential security risks)
  • Third-party services (CDNs, cloud providers)
  • Unusual geographic locations
  • Shared infrastructure with other domains
  • Example 2: Email Investigation

    Graph: An email address connected to domains, social profiles, and person entities.

    Analysis steps:

  • Start with the target email
  • Identify associated domains (personal, work)
  • Map social profiles (LinkedIn, Twitter, GitHub)
  • Find associated person entities
  • Cross-reference with other data sources
  • Findings to look for:

  • Multiple email aliases
  • Professional vs. personal domains
  • Social media presence patterns
  • Associated organizations
  • Example 3: Threat Intelligence

    Graph: An IP address connected to domains, certificates, and malware samples.

    Analysis steps:

  • Start with the suspicious IP
  • Identify hosted domains
  • Check SSL certificates for identity information
  • Look for known malware C2 domains
  • Map the infrastructure to understand the threat actor's setup
  • Findings to look for:

  • Shared hosting with legitimate sites
  • Certificate transparency log entries
  • Historical DNS changes
  • Related infrastructure patterns
  • Graph Comparison and Evolution

    Tracking how a graph changes over time provides additional insights.

    Baseline Comparison

  • Save your initial investigation graph
  • After a period, re-run the same transforms
  • Compare the two graphs
  • Identify new entities and relationships
  • Note removed or changed entities
  • Temporal Analysis

  • Export graph data at regular intervals
  • Import into a timeline visualization
  • Track infrastructure changes
  • Monitor domain registrations
  • Detect emerging patterns
  • Advanced Analysis Techniques

    Cross-Graph Analysis

    When a single graph becomes too large:

  • Split investigation into multiple graphs
  • Export key entities from each graph
  • Import into a spreadsheet
  • Perform cross-referencing in the spreadsheet
  • Import relationships back into Maltego
  • Weighted Analysis

    When entities have numerical properties:

  • Use property values to determine node size
  • Color-code based on property values
  • Filter by value ranges
  • Sort and rank entities by importance
  • Cluster Analysis

    To identify natural groupings:

  • Apply Organic layout
  • Visually identify clusters
  • Select each cluster
  • Run cluster-specific transforms
  • Compare findings across clusters
  • Exporting for External Analysis

    GraphML Export

    For use with other graph analysis tools:

  • File > Export Graph > GraphML
  • Import into Gephi, Cytoscape, or NetworkX
  • Run advanced algorithms (community detection, centrality)
  • CSV Export

    For spreadsheet analysis:

  • File > Export Graph > CSV
  • Open in Excel or Google Sheets
  • Create pivot tables and charts
  • Perform statistical analysis
  • Image Export

    For reports and presentations:

  • File > Export Graph > Image
  • Choose PNG for general use, SVG for scalable
  • Adjust zoom level for clarity
  • Annotate before exporting if needed
  • Best Practices for Graph Analysis

  • **Document your methodology**: Record which transforms you ran and in what order
  • **Use consistent entity naming**: Standardize how you name entities
  • **Color-code systematically**: Develop a color scheme and stick with it
  • **Save intermediate graphs**: Preserve different stages of your investigation
  • **Validate findings**: Cross-reference graph findings with other data sources
  • **Consider context**: A pattern may be normal in one context but suspicious in another
  • **Avoid tunnel vision**: Look at the entire graph, not just the expected patterns
  • Conclusion

    Graph analysis is both an art and a science. The patterns, techniques, and approaches covered in this guide provide a framework for interpreting Maltego graphs effectively. With practice, you will develop an intuition for identifying significant patterns and extracting actionable intelligence from complex visualizations.

    Remember that the graph is a tool for human analysis. Maltego presents data visually, but the interpretation requires your knowledge, context, and critical thinking. Combine graph analysis with domain knowledge and investigative methodology to produce high-quality intelligence products.

    For related topics, explore [Maltego Transforms Explained](/learn/maltego-transforms-explained) to understand how data gets into your graphs, and [Link Analysis Fundamentals](/learn/link-analysis-fundamentals) for deeper theoretical background.

    Frequently Asked Questions

    What is a Maltego graph?

    A Maltego graph is the visual workspace where entities (nodes) and their relationships (edges) are displayed. Graphs are the primary interface for investigation work, allowing analysts to see how different pieces of intelligence connect to each other.

    What graph layout algorithms does Maltego offer?

    Maltego provides Organic (force-directed, best for general analysis), Tree (hierarchical, good for organizational structures), Circular (evenly distributed, good for small datasets), and Horizontal/Vertical Tree layouts. Choose based on your analysis needs.

    How do you identify patterns in a Maltego graph?

    Look for clusters of connected entities (indicating related infrastructure), hub nodes with many connections (high-value targets), isolated nodes (potential outliers), and repeated relationship types that suggest systematic connections between entities.

    What is the difference between nodes and edges?

    Nodes (entities) represent real-world objects like domains, IP addresses, or people. Edges (relationships) represent connections between entities, such as 'resolves to' or 'associated with'. Together they form a network showing intelligence relationships.

    How do you filter results in a Maltego graph?

    Use the Transform Browser to filter by entity type, right-click entities to run specific transforms, use the View menu to show/hide entity types, and apply graph filters to focus on specific relationships or entity categories.

    What makes a good investigation graph?

    A good graph has clear entity separation by type, minimal visual clutter, logical grouping of related entities, consistent color coding, descriptive edge labels, and enough context to understand relationships without reading every property.

    How do you export Maltego graphs?

    Right-click the graph tab and select Export to save as image (PNG, SVG), PDF, or Maltego Graph File (.mtgx). You can also copy entities to clipboard or export data as CSV for further analysis in spreadsheets.

    What is the significance of node size in Maltego?

    Node size can indicate importance or relationship count. Larger nodes typically have more connections, making them potential high-value targets or key infrastructure. Configure size mapping in View settings based on entity properties.

    How do you organize complex Maltego graphs?

    Use multiple graphs for different investigation phases, group related entities spatially, color-code by entity type or discovery source, add notes to key entities, and use the Detail View to document findings on specific nodes.

    What is the Entity Detail View used for?

    The Detail View shows all properties of a selected entity including type, value, additional attributes, notes, and transform history. It is essential for examining specific entity data and documenting investigative findings.