Maltego Graph Analysis: Reading & Interpreting Investigation Graphs
Master the art of reading and interpreting Maltego investigation graphs. Learn graph layouts, entity relationships, pattern recognition, and how to extract actionable intelligence from complex visualizations.
# Maltego Graph Analysis: Reading & Interpreting Investigation Graphs
The power of Maltego lies not just in data collection but in how that data is visualized and analyzed. A well-constructed investigation graph reveals patterns, relationships, and insights that would be invisible in raw data tables. This guide teaches you how to read, interpret, and analyze Maltego graphs to extract maximum value from your investigations.
Understanding Graph Structure
A Maltego graph consists of two fundamental components:
Together, nodes and edges form a network that maps the relationships between different pieces of intelligence.
Node Properties
Every node in a Maltego graph has:
Edge Properties
Edges connecting nodes have:
Graph Layout Algorithms
Maltego offers several layout algorithms, each suited to different analysis scenarios.
Organic Layout
The default and most commonly used layout. Uses a force-directed algorithm where:
Best for:
How to apply: View > Layout > Organic (or click the Organic layout button in the toolbar)
Hierarchical Layout
Arranges nodes in layers based on their relationships:
Best for:
How to apply: View > Layout > Hierarchical
Circular Layout
Arranges all nodes in a circle:
Best for:
How to apply: View > Layout > Circular
Tree Layout
Arranges nodes in a strict tree structure:
Best for:
How to apply: View > Layout > Tree
Layout Comparison
| Layout | Strength | Weakness | Graph Size |
|--------|----------|----------|------------|
| Organic | Natural clustering | Can overlap at scale | Any |
| Hierarchical | Clear parent-child | Forced hierarchy | Medium |
| Circular | All connections visible | Messy with many edges | Small |
| Tree | Clean hierarchy | Only works for trees | Small-Medium |
Entity Types and Their Significance
Understanding what different entity types represent helps you interpret graphs more effectively.
Network Entities
| Entity | Represents | Key Insight |
|--------|------------|-------------|
| Domain | A registered domain | Entry point for network investigations |
| DNS Name | Subdomain | Reveals infrastructure structure |
| IPv4 Address | Individual IP | Maps to physical/virtual infrastructure |
| IP Network | CIDR range | Shows network boundaries |
| MX Record | Mail server | Reveals email infrastructure |
| NS Record | Name server | Shows DNS management |
| Website | Web application | Identifies web presence |
Person Entities
| Entity | Represents | Key Insight |
|--------|------------|-------------|
| Person | Individual | Central figure in people investigations |
| Email Address | Contact point | Links person to services and accounts |
| Phone Number | Contact method | Additional linkage to identity |
| Social Profile | Online presence | Reveals social connections |
Organization Entities
| Entity | Represents | Key Insight |
|--------|------------|-------------|
| Company | Business entity | Parent organization |
| ASN | Autonomous system | Network ownership |
| Certificate | SSL/TLS cert | Infrastructure and identity |
Pattern Recognition in Graphs
The true value of graph analysis is recognizing patterns that reveal meaningful information.
Star Pattern
A central node connected to many peripheral nodes.
Appearance: One hub node with spokes radiating outward
Interpretation:
Example: A company domain connected to 50 subdomains indicates extensive infrastructure.
Chain Pattern
Nodes connected in a linear sequence.
Appearance: Node > Node > Node > Node
Interpretation:
Example: Domain > Subdomain > IP > Netblock > ASN shows the full network chain.
Cluster Pattern
Dense groups of interconnected nodes.
Appearance: Tight groups with many internal connections, few external connections
Interpretation:
Example: Multiple domains on the same IP range with shared email addresses may indicate related businesses.
Bridge Pattern
A node that connects two otherwise separate clusters.
Appearance: A single node linking two groups
Interpretation:
Example: A shared email address across two domains suggests common ownership.
Hub-and-Spoke Pattern
A highly connected central node with many one-hop connections.
Appearance: Dense center with sparse periphery
Interpretation:
Example: A single IP hosting many domains may be a shared hosting server.
Ring Pattern
Nodes connected in a closed loop.
Appearance: Circular connections with no clear start or end
Interpretation:
Example: DNS resolution chains that loop back indicate potential configuration issues.
Identifying Key Nodes
Not all nodes in a graph are equally important. Identifying key nodes helps focus your analysis.
Degree Centrality
The number of direct connections a node has.
High degree nodes are likely:
How to find: Visually identify nodes with the most connections
Betweenness Centrality
How often a node appears on the shortest path between other nodes.
High betweenness nodes are likely:
How to find: Look for nodes that connect otherwise separate clusters
Closeness Centrality
How close a node is to all other nodes in the graph.
High closeness nodes are likely:
How to find: Nodes that are centrally located in the graph
Eigenvector Centrality
How connected a node is to other well-connected nodes.
High eigenvector nodes are likely:
How to find: Nodes that are connected to other highly connected nodes
Filtering and Focusing
As graphs grow large, filtering helps focus on relevant subsets.
Entity Type Filtering
Property-Based Filtering
Transform-Based Filtering
Manual Filtering
Reading Complex Graphs
When faced with a large, complex graph, follow this systematic approach.
Step 1: Get the Big Picture
Step 2: Identify Patterns
Look for the patterns described above:
Step 3: Find Key Nodes
Step 4: Trace Relationships
Step 5: Document Findings
Practical Analysis Examples
Example 1: Domain Infrastructure Analysis
Graph: A domain with 20 subdomains, each resolving to IPs, which connect to netblocks and ASNs.
Analysis steps:
Findings to look for:
Example 2: Email Investigation
Graph: An email address connected to domains, social profiles, and person entities.
Analysis steps:
Findings to look for:
Example 3: Threat Intelligence
Graph: An IP address connected to domains, certificates, and malware samples.
Analysis steps:
Findings to look for:
Graph Comparison and Evolution
Tracking how a graph changes over time provides additional insights.
Baseline Comparison
Temporal Analysis
Advanced Analysis Techniques
Cross-Graph Analysis
When a single graph becomes too large:
Weighted Analysis
When entities have numerical properties:
Cluster Analysis
To identify natural groupings:
Exporting for External Analysis
GraphML Export
For use with other graph analysis tools:
CSV Export
For spreadsheet analysis:
Image Export
For reports and presentations:
Best Practices for Graph Analysis
Conclusion
Graph analysis is both an art and a science. The patterns, techniques, and approaches covered in this guide provide a framework for interpreting Maltego graphs effectively. With practice, you will develop an intuition for identifying significant patterns and extracting actionable intelligence from complex visualizations.
Remember that the graph is a tool for human analysis. Maltego presents data visually, but the interpretation requires your knowledge, context, and critical thinking. Combine graph analysis with domain knowledge and investigative methodology to produce high-quality intelligence products.
For related topics, explore [Maltego Transforms Explained](/learn/maltego-transforms-explained) to understand how data gets into your graphs, and [Link Analysis Fundamentals](/learn/link-analysis-fundamentals) for deeper theoretical background.