GO KALI FREE
IntermediateOSINT

OSINT Investigation Workflow: From Seed to Complete Profile

A structured methodology for conducting OSINT investigations. Learn how to progress from a single seed entity to a comprehensive intelligence profile using Maltego and complementary tools.

#osint#investigation-workflow#methodology#maltego#reconnaissance#intelligence

# OSINT Investigation Workflow: From Seed to Complete Profile

A structured investigation workflow is the difference between productive OSINT and aimless data collection. This guide presents a complete methodology for progressing from a single seed entity to a comprehensive intelligence profile, integrating [Maltego](/tools/maltego) with other essential OSINT tools.

The OSINT Intelligence Cycle

Every OSINT investigation follows a cyclical process:

  • **Planning**: Define objectives and scope
  • **Collection**: Gather raw data
  • **Processing**: Organize and normalize data
  • **Analysis**: Identify patterns and relationships
  • **Dissemination**: Present findings
  • **Feedback**: Refine based on results
  • This cycle repeats as new information is discovered and objectives evolve.

    Phase 1: Planning and Scoping

    Define Objectives

    Before touching any tool, clearly define what you need to answer:

  • What specific questions need answering?
  • What is the end goal of the investigation?
  • What decisions will be made based on findings?
  • What level of confidence is required?
  • Establish Scope

  • What entities are in-scope?
  • What data sources are authorized?
  • What are the time constraints?
  • What are the legal boundaries?
  • Create an Investigation Plan

  • List primary and secondary objectives
  • Identify known starting entities (seeds)
  • Select tools and data sources
  • Define success criteria
  • Document methodology for reproducibility
  • Document Templates

    Create templates for common investigation types:

    Domain Investigation Template:

  • Objective: Map infrastructure of target domain
  • Seeds: Target domain, known subdomains
  • Tools: Maltego, Amass, Shodan
  • Success criteria: Complete infrastructure map with services identified
  • Person Investigation Template:

  • Objective: Build comprehensive profile of individual
  • Seeds: Name, email, phone number
  • Tools: Maltego, theHarvester, social media tools
  • Success criteria: Complete digital footprint with verified connections
  • Phase 2: Seed Collection

    The seed is your starting point — the initial entity that launches your investigation.

    Types of Seeds

    | Seed Type | Example | Investigation Focus |

    |-----------|---------|---------------------|

    | Domain | example.com | Infrastructure mapping |

    | Email | user@example.com | Person identification |

    | Name | John Doe | Digital footprint |

    | IP Address | 192.168.1.1 | Network investigation |

    | Phone Number | +1-555-0123 | Identity verification |

    | Company | Acme Corp | Organization mapping |

    | Image | logo.png | Source tracing |

    Seed Validation

    Before investing time, validate your seed:

  • **Verify existence**: Does the entity actually exist?
  • **Confirm accuracy**: Is the seed information correct?
  • **Check completeness**: Do you have all known seeds?
  • **Assess viability**: Can you realistically investigate this seed?
  • Multi-Seed Strategy

    Start with multiple seeds when possible:

  • Primary seed: The main entity (e.g., target domain)
  • Secondary seeds: Known related entities (e.g., known subdomains)
  • Cross-reference seeds: Entities that can validate findings
  • Phase 3: Passive Enumeration

    Gather information from passive sources before any active interaction.

    Domain Passive Enumeration

    Tools: [Maltego](/tools/maltego), Amass, crt.sh

    Steps:

  • **Certificate Transparency**:
  • # Query crt.sh for certificates
    curl -s "https://crt.sh/?q=%25.example.com&output=json" | jq '.[].name_value' | sort -u
    
  • **Historical DNS**:
  • - Query SecurityTrails or PassiveTotal for historical records

    - Identify IP address changes and subdomain additions

  • **Web Archives**:
  • - Check Wayback Machine for historical content

    - Identify deprecated subdomains and pages

  • **Search Engine Discovery**:
  • - Google dorking for indexed subdomains

    - Bing and Yahoo for additional coverage

    Person Passive Enumeration

    Tools: theHarvester, Maltego, social media tools

    Steps:

  • **Email Discovery**:
  • # Use theHarvester for email collection
    theHarvester -d example.com -b google,bing,linkedin -f results.html
    
  • **Social Media Search**:
  • - Search for the person across platforms

    - Check professional networks (LinkedIn)

    - Review public profiles (Twitter, GitHub)

  • **Public Records**:
  • - Search business registrations

    - Check court records

    - Review professional licenses

    Infrastructure Passive Enumeration

    Tools: Maltego, Shodan (historical data only)

    Steps:

  • **WHOIS Analysis**:
  • - Query domain registration data

    - Identify registrant information

    - Check name servers and mail servers

  • **ASN and Netblock Mapping**:
  • - Identify autonomous systems

    - Map network ranges

    - Check peering relationships

  • **Technology Fingerprinting**:
  • - Check web archives for technology indicators

    - Review GitHub for technology mentions

    - Analyze cached web pages for signatures

    Phase 4: Active Enumeration (If Authorized)

    When passive sources are insufficient and you have authorization, proceed to active enumeration.

    Network Active Enumeration

    Tools: Nmap, Amass, Maltego

    Steps:

  • **DNS Enumeration**:
  • # Active subdomain enumeration with Amass
    amass enum -active -d example.com -o amass-results.txt
    
  • **Port Scanning**:
  • # Service discovery with Nmap
    nmap -sV -sC -oA nmap-results target-ip
    
  • **Service Enumeration**:
  • - Identify running services

    - Determine software versions

    - Check for default credentials

    Web Active Enumeration

    Tools: Burp Suite, OWASP ZAP, Nikto

    Steps:

  • **Spider and Crawl**:
  • - Map web application structure

    - Identify hidden endpoints

    - Discover parameter names

  • **Technology Detection**:
  • - Identify web frameworks

    - Check for known vulnerabilities

    - Analyze JavaScript libraries

  • **Content Discovery**:
  • - Brute-force directories and files

    - Check for backup files

    - Identify admin interfaces

    Phase 5: Tool Integration

    The most effective investigations integrate multiple tools for comprehensive coverage.

    Maltego + theHarvester Workflow

  • **Collect with theHarvester**:
  • theHarvester -d target.com -b all -c -n -s -t -f harvester-output.html
    
  • **Import into Maltego**:
  • - Create entities for each discovered item

    - Drag entities onto the graph

    - Run Maltego transforms to expand

  • **Expand with Maltego**:
  • - Run DNS transforms on discovered subdomains

    - Query Shodan for service information

    - Check VirusTotal for reputation data

    Maltego + Amass Workflow

  • **Collect with Amass**:
  • amass enum -passive -d target.com -o amass-passive.txt
    amass enum -active -d target.com -o amass-active.txt
    
  • **Merge and Deduplicate**:
  • sort -u amass-passive.txt amass-active.txt > amass-combined.txt
    
  • **Import into Maltego**:
  • - Create DNS Name entities for each subdomain

    - Run IP resolution transforms

    - Map infrastructure relationships

    Maltego + Nmap Workflow

  • **Discover with Nmap**:
  • nmap -sn 192.168.1.0/24 -oG nmap-hosts.txt
    nmap -sV -p- target-ip -oA nmap-services
    
  • **Import into Maltego**:
  • - Create IP Address entities

    - Create Service entities for open ports

    - Connect services to their hosts

  • **Analyze with Maltego**:
  • - Apply graph layout

    - Identify patterns and clusters

    - Export findings for reporting

    Tool Integration Matrix

    | Phase | Primary Tool | Secondary Tool | Integration Method |

    |-------|-------------|----------------|-------------------|

    | Passive Domain | Maltego | Amass | Manual import |

    | Passive Person | theHarvester | Maltego | CSV import |

    | Active Network | Nmap | Maltego | Manual import |

    | Active Web | Burp Suite | Maltego | Manual import |

    | Analysis | Maltego | Excel | CSV export |

    | Reporting | Maltego | Word/PDF | Export and format |

    Phase 6: Analysis and Correlation

    Transform raw data into actionable intelligence.

    Data Normalization

  • **Standardize formats**: Ensure consistent naming and formatting
  • **Remove duplicates**: Eliminate redundant entries
  • **Validate accuracy**: Cross-reference findings
  • **Tag confidence levels**: Rate each finding's reliability
  • Pattern Analysis

    Look for these common patterns:

  • **Infrastructure Patterns**:
  • - Shared hosting across domains

    - Common DNS providers

    - Similar SSL certificate patterns

    - Consistent IP ranges

  • **Person Patterns**:
  • - Email naming conventions

    - Social media connection patterns

    - Professional network clusters

    - Technology skill indicators

  • **Organizational Patterns**:
  • - Department structures

    - Technology stacks

    - Vendor relationships

    - Geographic distribution

    Relationship Mapping

    Use Maltego to visualize and analyze relationships:

  • **Direct Relationships**: Entity A directly connects to Entity B
  • **Indirect Relationships**: Entity A connects to Entity B through intermediary entities
  • **Shared Attributes**: Multiple entities share common properties
  • **Temporal Relationships**: Connections that change over time
  • Analytical Techniques

  • **Link Analysis**: Map connections between entities
  • **Temporal Analysis**: Track changes over time
  • **Geospatial Analysis**: Map geographic distribution
  • **Network Analysis**: Identify network topology and key nodes
  • **Social Network Analysis**: Map human relationships and influence
  • Phase 7: Documentation and Reporting

    Investigation Log

    Maintain a detailed log of all activities:

    | Timestamp | Activity | Tool | Result | Notes |

    |-----------|----------|------|--------|-------|

    | 2026-06-25 10:00 | Certificate transparency query | crt.sh | 45 subdomains | High confidence |

    | 2026-06-25 10:15 | Passive DNS enumeration | SecurityTrails | 12 IPs | Medium confidence |

    | 2026-06-25 10:30 | WHOIS lookup | Maltego | Registrant info | High confidence |

    Finding Documentation

    For each significant finding:

  • **Discovery**: What was found
  • **Source**: Where it was found
  • **Confidence**: How reliable the information is
  • **Context**: How it relates to the investigation
  • **Implications**: What it means for the objectives
  • Report Structure

  • **Executive Summary**: Key findings and recommendations
  • **Methodology**: How the investigation was conducted
  • **Findings**: Detailed results organized by topic
  • **Analysis**: Interpretation and implications
  • **Appendices**: Raw data, tool output, screenshots
  • Visualization

    Include visual elements in your report:

  • **Infrastructure Maps**: Maltego graph exports
  • **Timeline Charts**: Temporal analysis visualization
  • **Network Diagrams**: Infrastructure topology
  • **Relationship Graphs**: Entity connection maps
  • **Data Tables**: Structured findings
  • Phase 8: Iteration and Refinement

    OSINT investigations are iterative processes.

    Review and Refine

  • **Evaluate findings**: Did you answer your objectives?
  • **Identify gaps**: What information is missing?
  • **Refine questions**: What new questions emerged?
  • **Adjust methodology**: What could be improved?
  • **Document lessons**: What did you learn?
  • Expand Scope

    Based on initial findings, consider expanding:

  • **Deepen investigation**: Explore discovered entities in more detail
  • **Widen scope**: Include related entities discovered during investigation
  • **Cross-reference**: Validate findings through additional sources
  • **Temporal extension**: Investigate historical changes
  • **Geographic expansion**: Explore international connections
  • Quality Assurance

    Before finalizing your report:

  • **Verify critical findings**: Double-check the most important discoveries
  • **Cross-reference sources**: Confirm through multiple data sources
  • **Review methodology**: Ensure reproducibility
  • **Check completeness**: Address all objectives
  • **Peer review**: Have someone else review if possible
  • Common Investigation Templates

    Domain Investigation Checklist

  • [ ] Certificate transparency enumeration
  • [ ] Historical DNS analysis
  • [ ] WHOIS data collection
  • [ ] Subdomain discovery (passive)
  • [ ] Subdomain discovery (active, if authorized)
  • [ ] IP address mapping
  • [ ] Network range identification
  • [ ] ASN mapping
  • [ ] Service discovery
  • [ ] Technology fingerprinting
  • [ ] Web application analysis
  • [ ] Email address discovery
  • [ ] Person identification
  • [ ] Social media analysis
  • [ ] Threat intelligence check
  • [ ] Documentation and reporting
  • Person Investigation Checklist

  • [ ] Email address enumeration
  • [ ] Phone number discovery
  • [ ] Social media profile search
  • [ ] Professional network analysis
  • [ ] Public records search
  • [ ] Domain ownership check
  • [ ] Username enumeration
  • [ ] Breach data analysis
  • [ ] Geolocation analysis
  • [ ] Photograph analysis
  • [ ] Writing style analysis
  • [ ] Association mapping
  • [ ] Timeline construction
  • [ ] Documentation and reporting
  • Conclusion

    A structured OSINT investigation workflow transforms raw data collection into actionable intelligence. By following the phases outlined in this guide — from planning through iteration — you can systematically build comprehensive profiles while maintaining legal and ethical standards.

    The key to successful OSINT is methodology. Tools like [Maltego](/tools/maltego) provide the technical capability, but your investigative process determines the quality of the results. Document everything, cross-reference your findings, and continuously refine your approach based on each investigation's outcomes.

    For foundational concepts, see [Passive OSINT Guide](/learn/passive-osint-guide) and [Digital Footprinting Guide](/learn/digital-footprinting-guide).

    Frequently Asked Questions

    What is the OSINT intelligence cycle?

    The OSINT intelligence cycle is a structured process consisting of Planning (define objectives), Collection (gather data), Processing (organize), Analysis (identify patterns), Dissemination (present findings), and Feedback (refine approach). This iterative process ensures thorough and reproducible investigations.

    What is a seed entity in OSINT?

    A seed entity is the starting point for an investigation — a known piece of information like a domain name, email address, or person's name. All subsequent intelligence gathering radiates from this seed using transforms and manual research.

    How do you define investigation objectives?

    Clearly articulate what questions need answering, what decisions will be based on findings, what confidence level is required, and what constitutes success. Document objectives before starting any collection to maintain focus and scope.

    What tools complement Maltego in an OSINT workflow?

    Essential complementary tools include theHarvester for email/subdomain discovery, Shodan for infrastructure scanning, Amass for subdomain enumeration, SpiderFoot for automated reconnaissance, and case management tools like CherryTree for documentation.

    How do you document OSINT findings?

    Use structured templates for each investigation type, record all sources and timestamps, save screenshots of key findings, maintain chain of custody for evidence, and create summary reports with actionable intelligence for stakeholders.

    What is the difference between tactical and strategic OSINT?

    Tactical OSINT focuses on specific technical indicators (IOCs, infrastructure) for immediate threat response. Strategic OSINT analyzes long-term trends, threat actor capabilities, and emerging risks to inform security strategy and resource allocation.

    How do you avoid scope creep in OSINT investigations?

    Document scope boundaries before starting, use investigation templates with predefined objectives, regularly review progress against original questions, and resist following interesting but irrelevant tangents that don't address the core investigation goals.

    What is passive vs active collection in an investigation?

    Passive collection gathers data from public sources without target interaction (safe, undetectable). Active collection directly engages target systems (faster, more detailed, but detectable). Most investigations start passively and escalate to active only when necessary and authorized.

    How do you validate OSINT findings?

    Cross-reference findings across multiple sources, verify data freshness and accuracy, use at least two independent methods to confirm critical findings, and document confidence levels for each piece of intelligence collected.

    What are common OSINT investigation mistakes?

    Common mistakes include undefined objectives, inadequate documentation, confirmation bias, failing to validate sources, not preserving evidence, and ignoring legal boundaries. A structured workflow prevents these issues.