Maltego Transforms Explained: How the Transform Engine Works
Deep dive into Maltego's transform engine. Understand transform architecture, categories, chaining, the Transform Hub, TREST API, and how to create custom transforms.
# Maltego Transforms Explained: How the Transform Engine Works
Transforms are the engine that powers Maltego's intelligence gathering capabilities. Understanding how transforms work — their architecture, categories, and how to extend them — is essential for maximizing Maltego's potential. This guide provides a comprehensive explanation of the transform system.
Why Use Transforms?
A transform is a function that takes an input entity and produces one or more output entities. Transforms are the primary mechanism for discovering and mapping relationships between entities in Maltego.
Transform Lifecycle
Transform Anatomy
Every transform has:
Transform Architecture
Maltego supports three types of transform execution.
Local Transforms
Run on your local machine using the Maltego Python library.
Advantages:
Disadvantages:
Example use case: Processing CSV files, parsing local logs, analyzing previously collected data.
Remote Transforms
Run on Maltego's transform servers or third-party servers.
Advantages:
Disadvantages:
Example use case: Shodan lookups, VirusTotal queries, WHOIS lookups.
TREST API Transforms
Maltego's Transform REST API allows you to create and host transforms on your own infrastructure.
Advantages:
Disadvantages:
Example use case: Integrating internal threat intelligence, custom databases, proprietary data sources.
Transform Categories
Transforms are organized into categories based on their function and data source.
DNS and Network Category
| Transform | Input | Output | Description |
|-----------|-------|--------|-------------|
| To DNS Name | Domain | DNS Name | Enumerates subdomains |
| To IP Address | Domain/DNS Name | IPv4 Address | Resolves to IP |
| To MX Record | Domain | MX Record | Finds mail servers |
| To NS Record | Domain | NS Record | Finds name servers |
| To Netblock | IPv4 Address | IP Network | Identifies CIDR range |
| To ASN | IPv4 Address | ASN | Maps to autonomous system |
| To Reverse DNS | IPv4 Address | DNS Name | Reverse DNS lookup |
Person and Email Category
| Transform | Input | Output | Description |
|-----------|-------|--------|-------------|
| To Email Address | Domain/Person | Email Address | Discovers emails |
| To Person | Email Address | Person | Identifies owner |
| To Phone Number | Person | Phone Number | Finds phone numbers |
| To Social Network | Person | Social Profile | Maps social presence |
Website Category
| Transform | Input | Output | Description |
|-----------|-------|--------|-------------|
| To Website | Domain | Website | Identifies web server |
| To Title | Website | Title | Extracts page title |
| To HTML Content | Website | HTML | Fetches page content |
| To Screenshot | Website | Image | Captures page screenshot |
Security and Threat Category
| Transform | Input | Output | Description |
|-----------|-------|--------|-------------|
| Shodan IP | IPv4 Address | Service | Discovers open services |
| VirusTotal Domain | Domain | Report | Reputation check |
| HIBP Email | Email Address | Breach | Checks breach data |
| Certificate | Domain | Certificate | Certificate transparency |
Custom Category
User-defined transforms created through the TREST API or local Python scripts.
The Transform Hub
The Transform Hub is Maltego's marketplace for transforms. It provides a centralized location for discovering, installing, and managing transform sets.
Browsing the Transform Hub
Transform Set Components
Each transform set includes:
Managing Installed Transforms
Free vs. Premium Transforms
| Feature | Free Transforms | Premium Transforms |
|---------|-----------------|-------------------|
| Cost | Free | Paid subscription |
| Data Quality | Good | Often superior |
| Result Limits | May have limits | Higher or no limits |
| Support | Community | Professional |
| Updates | Regular | Frequent |
API Key Configuration
Many transforms require API keys to access data sources.
Configuring API Keys
Common API Keys
| Service | Registration | Free Tier |
|---------|-------------|-----------|
| Shodan | [shodan.io](https://shodan.io) | 1 API credit/month |
| VirusTotal | [virustotal.com](https://www.virustotal.com) | 500 requests/day |
| Have I Been Pwned | [haveibeenpwned.com](https://haveibeenpwned.com/API/Key) | Non-commercial use |
| SecurityTrails | [securitytrails.com](https://www.securitytrails.com) | 50 requests/month |
API Key Best Practices
Chaining Transforms
Transform chaining is the process of running multiple transforms in sequence to build a comprehensive picture.
Manual Chaining
Example chain:
Domain > DNS Names > IP Addresses > Netblocks > ASNs > Company
Automated Chaining with Machines
Maltego Machines allow you to automate transform chains:
Creating a Custom Machine
- Transform 1: Domain to DNS Name
- Transform 2: DNS Name to IP Address
- Transform 3: IP Address to Service
Chaining Best Practices
Creating Custom Transforms
Maltego allows you to create custom transforms using the TREST API or local Python scripts.
Local Python Transforms
Prerequisites
Creating a Simple Transform
from maltego_trx.maltego import MaltegoTransform, MaltegoMsg
from maltego_trx.transform import DiscoverableTransform
class MyCustomTransform(DiscoverableTransform):
@classmethod
def create_entities(cls, request: MaltegoMsg, response: MaltegoTransform):
# Get input entity value
input_value = request.Value
# Process the input (your custom logic here)
results = process_input(input_value)
# Add output entities
for result in results:
entity = response.addEntity("maltego.DNSName", result)
entity.addProperty("value", "value", "loose", result)
def process_input(value):
# Your custom processing logic
# This could query databases, APIs, files, etc.
return [f"sub1.{value}", f"sub2.{value}", f"sub3.{value}"]
Running Local Transforms
- Name
- Input entity type
- Output entity type
- Script path
TREST API Transforms
For server-hosted transforms:
TREST API Endpoint Example
from flask import Flask, request, jsonify
app = Flask(__name__)
@app.route('/transforms/my-transform', methods=['POST'])
def my_transform():
data = request.json
input_value = data['value']
# Process input
results = process_input(input_value)
# Format response
response = {
'entities': [
{
'type': 'maltego.DNSName',
'value': result,
'properties': {'value': result}
}
for result in results
]
}
return jsonify(response)
if __name__ == '__main__':
app.run(host='0.0.0.0', port=5000)
Custom Entity Types
You can define custom entity types for your transforms:
- Entity name
- Display name
- Icon
- Properties
- Color
Transform Performance
Optimizing Transform Execution
Monitoring Transform Performance
Transform Security
Authentication
Data Handling
Network Security
Troubleshooting Transforms
Common Issues
| Issue | Cause | Solution |
|-------|-------|----------|
| Transform not appearing | Not installed | Install from Transform Hub |
| No results returned | API key missing/invalid | Configure API key |
| Timeout error | Server too slow | Check network, retry later |
| Rate limit hit | Too many requests | Wait, reduce frequency |
| Authentication error | Invalid credentials | Reconfigure API key |
Debug Mode
Testing Transforms
Related Resources
Conclusion
Understanding Maltego's transform system is essential for effective OSINT. Transforms are the bridges between raw data and actionable intelligence. By mastering transform categories, chaining, custom development, and best practices, you can build powerful intelligence gathering capabilities tailored to your specific needs.
The transform ecosystem is constantly evolving, with new data sources and capabilities being added regularly. Stay current with the Transform Hub, contribute custom transforms to the community, and continuously refine your transform chains to improve the quality and efficiency of your investigations.