Maltego is an OSINT and link-analysis tool that visualises relationships between pieces of information as an interactive graph. Starting from an entity such as a domain, email address, person or IP, it runs Transforms that query data sources and pull back related entities, which it plots as connected nodes. Investigators, threat intelligence analysts and pentesters use it to map infrastructure, connections and digital footprints. A free Community Edition exists alongside paid plans.
Last updated: 6 August 2026
Maltego makes hidden connections visible. An analyst investigating a domain drops it on the graph and runs Transforms to reveal its subdomains, DNS records, hosting IPs, associated email addresses and related sites, then pivots outward node by node to build a picture of an organisation's footprint or a threat actor's infrastructure. Reconnaissance for a pentest, brand-abuse and phishing investigations, and threat-intel enrichment are common uses. Because the graph grows from data returned by Transforms, the depth depends on which data sources and Transform packs you have access to.
Windows · Linux · macOS
Commercial; free Community Edition (CE) with limits
Create GraphStart a blank canvas for a new investigation.
Drag an entity (Domain)Place a starting point such as a domain, email or person on the graph.
Run Transform > To DNS NamesQuery a data source to expand the entity into related entities.
Run All TransformsFan out an entity in every available direction at once (use carefully).
Pivot on a returned nodeSelect a new entity and run further Transforms to follow the trail.
Add Transform Hub itemsInstall additional Transform packs/data sources to broaden coverage.
Maltego queries publicly available and licensed data, which is generally lawful to collect, but how you use it matters. Building profiles of individuals can raise privacy and data-protection concerns, and acting on findings, such as accessing systems you have mapped, without authorisation is an offence under the IT Act 2000. Respect data-source terms of service and use collected data only for legitimate, authorised purposes.
Results are only as good as the Transforms and data sources you have; the free Community Edition caps results per Transform and reserves premium data behind paid plans. Returned data can be stale, incomplete or wrong, so findings need verification. Running many Transforms can generate large, noisy graphs and hit API/rate limits.
| Tool | Pick it when |
|---|---|
| SpiderFoot | You want automated, open-source OSINT collection with a web UI. |
| theHarvester | You just need quick command-line gathering of emails, subdomains and hosts. |
| Recon-ng | You want a modular, scriptable recon framework in the terminal. |
| OSINT Framework | You want a curated directory of manual OSINT sources to work through. |
| Shodan | Your focus is specifically internet-exposed devices and services. |
Ethical Hacking Course (6 months) — OSINT and reconnaissance module
We are not affiliated with, endorsed by, or a reseller for the vendors of any tool on this site.
Free counselling call. We will tell you honestly whether a full course is worth it for what you actually want to do.
Call +91 75175 72000