GO KALI FREE
IntermediateMaltego

Maltego Transforms Explained: How the Transform Engine Works

Deep dive into Maltego's transform engine. Understand transform architecture, categories, chaining, the Transform Hub, TREST API, and how to create custom transforms.

#maltego#transforms#trest-api#custom-transforms#transform-hub#api-keys

# Maltego Transforms Explained: How the Transform Engine Works

Transforms are the engine that powers Maltego's intelligence gathering capabilities. Understanding how transforms work — their architecture, categories, and how to extend them — is essential for maximizing Maltego's potential. This guide provides a comprehensive explanation of the transform system.

Why Use Transforms?

A transform is a function that takes an input entity and produces one or more output entities. Transforms are the primary mechanism for discovering and mapping relationships between entities in Maltego.

Transform Lifecycle

  • **Input**: You select one or more entities on a graph
  • **Execution**: Maltego sends the entities to a transform server
  • **Processing**: The transform queries data sources and processes results
  • **Output**: Results are returned as new entities on the graph
  • **Visualization**: New entities appear connected to the input entities
  • Transform Anatomy

    Every transform has:

  • **Name**: A unique identifier (e.g., "To IP Address")
  • **Input Entity Type**: What kind of entity it accepts (e.g., Domain)
  • **Output Entity Types**: What it produces (e.g., IPv4 Address)
  • **Description**: What the transform does
  • **Author**: Who created it
  • **Source**: Where it runs (local, remote, or API)
  • Transform Architecture

    Maltego supports three types of transform execution.

    Local Transforms

    Run on your local machine using the Maltego Python library.

    Advantages:

  • No external API calls
  • Full control over execution
  • Can access local resources
  • No rate limiting
  • Disadvantages:

  • Limited to locally available data
  • Requires Python setup
  • May need custom data sources
  • Example use case: Processing CSV files, parsing local logs, analyzing previously collected data.

    Remote Transforms

    Run on Maltego's transform servers or third-party servers.

    Advantages:

  • Access to cloud-hosted data sources
  • No local setup required
  • Regular updates from the provider
  • Scalable processing
  • Disadvantages:

  • Requires internet connection
  • Subject to rate limiting
  • Data leaves your machine
  • Dependency on external service
  • Example use case: Shodan lookups, VirusTotal queries, WHOIS lookups.

    TREST API Transforms

    Maltego's Transform REST API allows you to create and host transforms on your own infrastructure.

    Advantages:

  • Complete control over data sources
  • Custom processing logic
  • Enterprise integration
  • Scalable hosting
  • Disadvantages:

  • Requires server infrastructure
  • More complex setup
  • Maintenance responsibility
  • Security considerations
  • Example use case: Integrating internal threat intelligence, custom databases, proprietary data sources.

    Transform Categories

    Transforms are organized into categories based on their function and data source.

    DNS and Network Category

    | Transform | Input | Output | Description |

    |-----------|-------|--------|-------------|

    | To DNS Name | Domain | DNS Name | Enumerates subdomains |

    | To IP Address | Domain/DNS Name | IPv4 Address | Resolves to IP |

    | To MX Record | Domain | MX Record | Finds mail servers |

    | To NS Record | Domain | NS Record | Finds name servers |

    | To Netblock | IPv4 Address | IP Network | Identifies CIDR range |

    | To ASN | IPv4 Address | ASN | Maps to autonomous system |

    | To Reverse DNS | IPv4 Address | DNS Name | Reverse DNS lookup |

    Person and Email Category

    | Transform | Input | Output | Description |

    |-----------|-------|--------|-------------|

    | To Email Address | Domain/Person | Email Address | Discovers emails |

    | To Person | Email Address | Person | Identifies owner |

    | To Phone Number | Person | Phone Number | Finds phone numbers |

    | To Social Network | Person | Social Profile | Maps social presence |

    Website Category

    | Transform | Input | Output | Description |

    |-----------|-------|--------|-------------|

    | To Website | Domain | Website | Identifies web server |

    | To Title | Website | Title | Extracts page title |

    | To HTML Content | Website | HTML | Fetches page content |

    | To Screenshot | Website | Image | Captures page screenshot |

    Security and Threat Category

    | Transform | Input | Output | Description |

    |-----------|-------|--------|-------------|

    | Shodan IP | IPv4 Address | Service | Discovers open services |

    | VirusTotal Domain | Domain | Report | Reputation check |

    | HIBP Email | Email Address | Breach | Checks breach data |

    | Certificate | Domain | Certificate | Certificate transparency |

    Custom Category

    User-defined transforms created through the TREST API or local Python scripts.

    The Transform Hub

    The Transform Hub is Maltego's marketplace for transforms. It provides a centralized location for discovering, installing, and managing transform sets.

    Browsing the Transform Hub

  • Open Maltego
  • Click **Transform Hub** in the menu bar
  • Browse categories or search for specific transforms
  • Click on a transform set to view details
  • Click **Install** to add it to your Maltego
  • Transform Set Components

    Each transform set includes:

  • **Transforms**: The actual data-gathering functions
  • **Entities**: Custom entity types used by the transforms
  • **Configuration**: API key and parameter settings
  • **Documentation**: Usage instructions and examples
  • Managing Installed Transforms

  • Open Transform Hub
  • Click **Installed** tab
  • View all installed transform sets
  • Click **Configure** to update API keys
  • Click **Update** to get the latest version
  • Click **Remove** to uninstall
  • Free vs. Premium Transforms

    | Feature | Free Transforms | Premium Transforms |

    |---------|-----------------|-------------------|

    | Cost | Free | Paid subscription |

    | Data Quality | Good | Often superior |

    | Result Limits | May have limits | Higher or no limits |

    | Support | Community | Professional |

    | Updates | Regular | Frequent |

    API Key Configuration

    Many transforms require API keys to access data sources.

    Configuring API Keys

  • Open **Transform Hub**
  • Find the transform set requiring configuration
  • Click **Configure**
  • Enter your API key
  • Click **Save**
  • Test with a simple transform
  • Common API Keys

    | Service | Registration | Free Tier |

    |---------|-------------|-----------|

    | Shodan | [shodan.io](https://shodan.io) | 1 API credit/month |

    | VirusTotal | [virustotal.com](https://www.virustotal.com) | 500 requests/day |

    | Have I Been Pwned | [haveibeenpwned.com](https://haveibeenpwned.com/API/Key) | Non-commercial use |

    | SecurityTrails | [securitytrails.com](https://www.securitytrails.com) | 50 requests/month |

    API Key Best Practices

  • **Never commit keys to code**: Store keys in configuration files, not source code
  • **Use environment variables**: For custom transforms, read keys from environment
  • **Rotate keys periodically**: Change keys every 90 days
  • **Monitor usage**: Track API consumption to avoid hitting limits
  • **Use separate keys**: Different keys for different environments
  • Chaining Transforms

    Transform chaining is the process of running multiple transforms in sequence to build a comprehensive picture.

    Manual Chaining

  • Run a transform on an entity
  • Select the output entities
  • Run another transform on the results
  • Repeat until you have the desired information
  • Example chain:

    Domain > DNS Names > IP Addresses > Netblocks > ASNs > Company
    

    Automated Chaining with Machines

    Maltego Machines allow you to automate transform chains:

  • Click **View > Machines** to open the Machines panel
  • Select a pre-built machine or create a new one
  • Configure the sequence of transforms
  • Run the machine on selected entities
  • Results are added to the graph automatically
  • Creating a Custom Machine

  • Open the Machines panel
  • Click **New Machine**
  • Add transforms in sequence:
  • - Transform 1: Domain to DNS Name

    - Transform 2: DNS Name to IP Address

    - Transform 3: IP Address to Service

  • Set maximum results per transform
  • Save the machine
  • Run on target entities
  • Chaining Best Practices

  • **Start broad, then narrow**: Begin with wide-enumeration transforms, then filter
  • **Limit results**: Set maximum results to prevent graph overload
  • **Use parallel transforms**: Run independent transforms simultaneously
  • **Document your chain**: Record which transforms you used and why
  • **Test on small samples**: Verify transform chains on single entities before scaling
  • Creating Custom Transforms

    Maltego allows you to create custom transforms using the TREST API or local Python scripts.

    Local Python Transforms

    Prerequisites

  • Python 3.8+ installed
  • Maltego Python library: `pip install maltego-trx`
  • Basic Python knowledge
  • Creating a Simple Transform

    from maltego_trx.maltego import MaltegoTransform, MaltegoMsg
    from maltego_trx.transform import DiscoverableTransform
    
    class MyCustomTransform(DiscoverableTransform):
        @classmethod
        def create_entities(cls, request: MaltegoMsg, response: MaltegoTransform):
            # Get input entity value
            input_value = request.Value
            
            # Process the input (your custom logic here)
            results = process_input(input_value)
            
            # Add output entities
            for result in results:
                entity = response.addEntity("maltego.DNSName", result)
                entity.addProperty("value", "value", "loose", result)
    
    def process_input(value):
        # Your custom processing logic
        # This could query databases, APIs, files, etc.
        return [f"sub1.{value}", f"sub2.{value}", f"sub3.{value}"]
    

    Running Local Transforms

  • Save your transform script
  • In Maltego, go to **Transform Manager**
  • Click **New Local Transform**
  • Configure the transform:
  • - Name

    - Input entity type

    - Output entity type

    - Script path

  • Test the transform
  • Save and use
  • TREST API Transforms

    For server-hosted transforms:

  • Set up a web server (Flask, Django, Express, etc.)
  • Implement the transform endpoint
  • Register the transform in Maltego
  • Configure authentication
  • Test and deploy
  • TREST API Endpoint Example

    from flask import Flask, request, jsonify
    
    app = Flask(__name__)
    
    @app.route('/transforms/my-transform', methods=['POST'])
    def my_transform():
        data = request.json
        input_value = data['value']
        
        # Process input
        results = process_input(input_value)
        
        # Format response
        response = {
            'entities': [
                {
                    'type': 'maltego.DNSName',
                    'value': result,
                    'properties': {'value': result}
                }
                for result in results
            ]
        }
        
        return jsonify(response)
    
    if __name__ == '__main__':
        app.run(host='0.0.0.0', port=5000)
    

    Custom Entity Types

    You can define custom entity types for your transforms:

  • In Maltego, go to **Entity Manager**
  • Click **New Entity**
  • Define:
  • - Entity name

    - Display name

    - Icon

    - Properties

    - Color

  • Save the entity
  • Use it in your transforms
  • Transform Performance

    Optimizing Transform Execution

  • **Batch processing**: Send multiple entities in one request when possible
  • **Caching**: Cache results to avoid repeated API calls
  • **Rate limiting**: Respect API rate limits to avoid bans
  • **Error handling**: Gracefully handle API failures and timeouts
  • **Result limiting**: Return only the most relevant results
  • Monitoring Transform Performance

  • Open **Transform Manager**
  • View execution logs
  • Check response times
  • Identify slow transforms
  • Optimize or replace underperforming transforms
  • Transform Security

    Authentication

  • API keys should be stored securely
  • Never hardcode credentials in transform scripts
  • Use environment variables or encrypted configuration
  • Rotate keys regularly
  • Data Handling

  • Be aware of data privacy regulations
  • Do not store sensitive data unnecessarily
  • Implement proper data retention policies
  • Document data sources and processing methods
  • Network Security

  • Use HTTPS for TREST API endpoints
  • Implement proper authentication and authorization
  • Validate and sanitize all input data
  • Monitor for abuse and anomalous usage
  • Troubleshooting Transforms

    Common Issues

    | Issue | Cause | Solution |

    |-------|-------|----------|

    | Transform not appearing | Not installed | Install from Transform Hub |

    | No results returned | API key missing/invalid | Configure API key |

    | Timeout error | Server too slow | Check network, retry later |

    | Rate limit hit | Too many requests | Wait, reduce frequency |

    | Authentication error | Invalid credentials | Reconfigure API key |

    Debug Mode

  • Open **Transform Manager**
  • Select the problematic transform
  • Click **Debug**
  • View detailed execution logs
  • Identify the failure point
  • Testing Transforms

  • Create a test entity with known value
  • Run the transform on the test entity
  • Verify the output matches expectations
  • Check for any error messages
  • Verify API key configuration
  • Related Resources

  • [Maltego Beginner Guide](/learn/maltego-beginner-guide) - Start with the basics
  • [Maltego Graph Analysis](/learn/maltego-graph-analysis) - Understand your results
  • [Maltego Community Edition Guide](/learn/maltego-community-edition-guide) - Maximize free tools
  • [OSINT Investigation Workflow](/learn/osint-investigation-workflow) - Structured methodology
  • Conclusion

    Understanding Maltego's transform system is essential for effective OSINT. Transforms are the bridges between raw data and actionable intelligence. By mastering transform categories, chaining, custom development, and best practices, you can build powerful intelligence gathering capabilities tailored to your specific needs.

    The transform ecosystem is constantly evolving, with new data sources and capabilities being added regularly. Stay current with the Transform Hub, contribute custom transforms to the community, and continuously refine your transform chains to improve the quality and efficiency of your investigations.

    Frequently Asked Questions

    What is a Maltego transform?

    A transform is a function that takes an input entity, queries a data source, and produces one or more output entities. Transforms are the engine powering Maltego's intelligence gathering, connecting to external APIs and databases to discover relationships.

    What is the difference between local and remote transforms?

    Local transforms run on your machine using the Maltego Python library with no external API calls. Remote transforms execute on Maltego's servers or third-party servers, providing access to more data sources but requiring internet connectivity.

    What is the Transform Hub?

    The Transform Hub is Maltego's marketplace where you browse, install, and manage transforms from various data providers. It includes free and paid transforms from services like Shodan, VirusTotal, and Have I Been Pwned.

    How do I install transforms from the Transform Hub?

    Open Maltego, go to Window > Transform Hub, browse available transforms, and click Install. Some transforms require API keys from the data provider. Configure API keys in Transform Manager after installation.

    What is the TREST API?

    TREST (Transform REST) API allows you to build transforms that access RESTful web services. It provides a framework for creating custom transforms that query external APIs and return results as Maltego entities.

    Can I create custom transforms?

    Yes, Maltego supports custom transforms written in Python using the Maltego Python library. You can create transforms that query your own data sources, process local files, or integrate with internal APIs for organization-specific investigations.

    What are transform chaining and Machinae?

    Transform chaining runs multiple transforms in sequence automatically. Machinae (formerly Paterva's automation tool) chains transforms across different entity types to build comprehensive intelligence profiles without manual intervention.

    How do I manage API keys for transforms?

    Go to Transform Hub, click the gear icon on installed transforms, and enter API keys in the configuration fields. Keys are stored securely in Maltego's configuration. Some transforms work without keys using free data sources.

    What are the most useful free transforms?

    Essential free transforms include DNS (domain resolution), WHOIS (registration data), IP Address (geolocation, ASN), Email Address (verification), and Certificate Transparency (subdomain discovery). These form the core of most OSINT investigations.

    How do transform results appear on the graph?

    Transform results appear as new entities connected to the input entity by relationship edges. Each result node shows the discovered value, and edges label the relationship type (e.g., 'resolves to', 'associated with').