Desktop

Step-by-step workflow guide for investigators

Network Infrastructure Mapping

Starting from a single domain, this guide walks you through mapping an organization's external-facing network — resolving DNS records to IP addresses, tracing them to netblocks, autonomous systems, and their owners, and surfacing exposed services and known vulnerabilities. By the end, you will have a prioritized picture of the target's attack surface: which services are exposed, which CVEs affect them, and which of those have active exploits available.

Before you start:

Identify the starting point

  • Domain to begin with (recommended starting point).
  • Alternate starting points: Website, MX, NS, DNS Name, IPv4 Address, Netblock, or AS Number — pick the earliest you have.


Note: The workflow is designed around a domain input; starting later in the chain means skipping earlier steps.

Access

  • Download and install Graph (Desktop).
  • Install Cyber Threat Intelligence Maltego Data Pass from the Data Hub.

Note: Basic plan users have limitations in access to data providers within the Data Pass modules and the number of Credits available. Check what you have access to in your plan here.

Credit Management

  • Check your organization Credits before starting.
  • Monitor Credit usage in the Output Window after each Transform to stay within limits.

Note: This workflow spans multiple data providers and can consume credits quickly on large targets.

Vulners is credit-heavy — narrow to CVEs that matter before running Search for Exploits.

Resources

This guide assumes basic familiarity with Graph (Desktop). Feature names link to the documentation where needed. It helps to have the following pages open before you start: 


Video Overview

Watch a real network infrastructure mapping workflow demonstration. Then, follow the step-by-step guide below to build your own, or skip the video and jump straight to the steps.

To enlarge, double-click on the video.

Step-by-Step Guide

What's next?

  • Check domains and IP addresses for breach exposure with D4 or Constella.
  • Investigate malware hashes that can threaten your organization's infrastructure.
  • Investigate an identified threat actor.

Give us your Feedback!