OSINT Investigation Workflow: From Seed to Complete Profile
A structured methodology for conducting OSINT investigations. Learn how to progress from a single seed entity to a comprehensive intelligence profile using Maltego and complementary tools.
# OSINT Investigation Workflow: From Seed to Complete Profile
A structured investigation workflow is the difference between productive OSINT and aimless data collection. This guide presents a complete methodology for progressing from a single seed entity to a comprehensive intelligence profile, integrating [Maltego](/tools/maltego) with other essential OSINT tools.
The OSINT Intelligence Cycle
Every OSINT investigation follows a cyclical process:
This cycle repeats as new information is discovered and objectives evolve.
Phase 1: Planning and Scoping
Define Objectives
Before touching any tool, clearly define what you need to answer:
Establish Scope
Create an Investigation Plan
Document Templates
Create templates for common investigation types:
Domain Investigation Template:
Person Investigation Template:
Phase 2: Seed Collection
The seed is your starting point — the initial entity that launches your investigation.
Types of Seeds
| Seed Type | Example | Investigation Focus |
|-----------|---------|---------------------|
| Domain | example.com | Infrastructure mapping |
| Email | user@example.com | Person identification |
| Name | John Doe | Digital footprint |
| IP Address | 192.168.1.1 | Network investigation |
| Phone Number | +1-555-0123 | Identity verification |
| Company | Acme Corp | Organization mapping |
| Image | logo.png | Source tracing |
Seed Validation
Before investing time, validate your seed:
Multi-Seed Strategy
Start with multiple seeds when possible:
Phase 3: Passive Enumeration
Gather information from passive sources before any active interaction.
Domain Passive Enumeration
Tools: [Maltego](/tools/maltego), Amass, crt.sh
Steps:
# Query crt.sh for certificates
curl -s "https://crt.sh/?q=%25.example.com&output=json" | jq '.[].name_value' | sort -u
- Query SecurityTrails or PassiveTotal for historical records
- Identify IP address changes and subdomain additions
- Check Wayback Machine for historical content
- Identify deprecated subdomains and pages
- Google dorking for indexed subdomains
- Bing and Yahoo for additional coverage
Person Passive Enumeration
Tools: theHarvester, Maltego, social media tools
Steps:
# Use theHarvester for email collection
theHarvester -d example.com -b google,bing,linkedin -f results.html
- Search for the person across platforms
- Check professional networks (LinkedIn)
- Review public profiles (Twitter, GitHub)
- Search business registrations
- Check court records
- Review professional licenses
Infrastructure Passive Enumeration
Tools: Maltego, Shodan (historical data only)
Steps:
- Query domain registration data
- Identify registrant information
- Check name servers and mail servers
- Identify autonomous systems
- Map network ranges
- Check peering relationships
- Check web archives for technology indicators
- Review GitHub for technology mentions
- Analyze cached web pages for signatures
Phase 4: Active Enumeration (If Authorized)
When passive sources are insufficient and you have authorization, proceed to active enumeration.
Network Active Enumeration
Tools: Nmap, Amass, Maltego
Steps:
# Active subdomain enumeration with Amass
amass enum -active -d example.com -o amass-results.txt
# Service discovery with Nmap
nmap -sV -sC -oA nmap-results target-ip
- Identify running services
- Determine software versions
- Check for default credentials
Web Active Enumeration
Tools: Burp Suite, OWASP ZAP, Nikto
Steps:
- Map web application structure
- Identify hidden endpoints
- Discover parameter names
- Identify web frameworks
- Check for known vulnerabilities
- Analyze JavaScript libraries
- Brute-force directories and files
- Check for backup files
- Identify admin interfaces
Phase 5: Tool Integration
The most effective investigations integrate multiple tools for comprehensive coverage.
Maltego + theHarvester Workflow
theHarvester -d target.com -b all -c -n -s -t -f harvester-output.html
- Create entities for each discovered item
- Drag entities onto the graph
- Run Maltego transforms to expand
- Run DNS transforms on discovered subdomains
- Query Shodan for service information
- Check VirusTotal for reputation data
Maltego + Amass Workflow
amass enum -passive -d target.com -o amass-passive.txt
amass enum -active -d target.com -o amass-active.txt
sort -u amass-passive.txt amass-active.txt > amass-combined.txt
- Create DNS Name entities for each subdomain
- Run IP resolution transforms
- Map infrastructure relationships
Maltego + Nmap Workflow
nmap -sn 192.168.1.0/24 -oG nmap-hosts.txt
nmap -sV -p- target-ip -oA nmap-services
- Create IP Address entities
- Create Service entities for open ports
- Connect services to their hosts
- Apply graph layout
- Identify patterns and clusters
- Export findings for reporting
Tool Integration Matrix
| Phase | Primary Tool | Secondary Tool | Integration Method |
|-------|-------------|----------------|-------------------|
| Passive Domain | Maltego | Amass | Manual import |
| Passive Person | theHarvester | Maltego | CSV import |
| Active Network | Nmap | Maltego | Manual import |
| Active Web | Burp Suite | Maltego | Manual import |
| Analysis | Maltego | Excel | CSV export |
| Reporting | Maltego | Word/PDF | Export and format |
Phase 6: Analysis and Correlation
Transform raw data into actionable intelligence.
Data Normalization
Pattern Analysis
Look for these common patterns:
- Shared hosting across domains
- Common DNS providers
- Similar SSL certificate patterns
- Consistent IP ranges
- Email naming conventions
- Social media connection patterns
- Professional network clusters
- Technology skill indicators
- Department structures
- Technology stacks
- Vendor relationships
- Geographic distribution
Relationship Mapping
Use Maltego to visualize and analyze relationships:
Analytical Techniques
Phase 7: Documentation and Reporting
Investigation Log
Maintain a detailed log of all activities:
| Timestamp | Activity | Tool | Result | Notes |
|-----------|----------|------|--------|-------|
| 2026-06-25 10:00 | Certificate transparency query | crt.sh | 45 subdomains | High confidence |
| 2026-06-25 10:15 | Passive DNS enumeration | SecurityTrails | 12 IPs | Medium confidence |
| 2026-06-25 10:30 | WHOIS lookup | Maltego | Registrant info | High confidence |
Finding Documentation
For each significant finding:
Report Structure
Visualization
Include visual elements in your report:
Phase 8: Iteration and Refinement
OSINT investigations are iterative processes.
Review and Refine
Expand Scope
Based on initial findings, consider expanding:
Quality Assurance
Before finalizing your report:
Common Investigation Templates
Domain Investigation Checklist
Person Investigation Checklist
Conclusion
A structured OSINT investigation workflow transforms raw data collection into actionable intelligence. By following the phases outlined in this guide — from planning through iteration — you can systematically build comprehensive profiles while maintaining legal and ethical standards.
The key to successful OSINT is methodology. Tools like [Maltego](/tools/maltego) provide the technical capability, but your investigative process determines the quality of the results. Document everything, cross-reference your findings, and continuously refine your approach based on each investigation's outcomes.
For foundational concepts, see [Passive OSINT Guide](/learn/passive-osint-guide) and [Digital Footprinting Guide](/learn/digital-footprinting-guide).