Step-by-step workflow guide for investigators
Organizational Risk Assessment
Who is this for?
Assessing your own organisation — establishing whether employee credentials and personal data have leaked, which devices are compromised, and what operational risk that creates. The output drives remediation: forced resets, endpoint investigation, and staff notification.
Assessing another organisation — establishing, before entering into a relationship, whether a prospective partner, supplier, or acquisition target carries exposure that would reach you. The output drives a decision: proceed, proceed with conditions, or decline.
What is on this page?
A step-by-step guide for using Maltego Graph (Desktop) to assess an organisation's existing exposure from its domain alone. The workflow covers searching infostealer logs for stolen employee credentials, extracting the identities and target services behind those records, drilling into a single infected endpoint to establish the full scope of one compromise, pivoting to the individual affected, and checking the domain against broader dark web leak records.
How to use this page?
New to Graph?
A note on results
Data providers used on this page
Darkside D4 — dark web data including infostealer log search. Given a domain, the stealer log search returns records where a login or username contains that domain as an email address, along with the malware family or command-and-control source the record came from. Also returns leaked records associated with a domain.
Access to infostealer log data is restricted to Enterprise plans
If you are on any other plan, start with Step 3.
Before you start:
Identify the starting point
Domain you are trying to investigate.
Access
- Download and install Graph (Desktop).
- Install the Darkweb and Person of Interest Data Pass modules from the Data Hub within Graph (Desktop).
Note: Stealer log data is restricted to Enterprise plans. Basic users have limited access to the data providers used in this workflow more generally — some transforms may be unavailable or return restricted results depending on your plan tier.
Resources
This guide assumes basic familiarity with Graph (Desktop). Feature names link to the documentation where needed. It helps to have the following pages open before you start:
Video Overview
Watch an organizational risk assessment workflow demonstration. Then follow the step-by-step guide below to build your own, or skip the video and jump straight to the steps.
To enlarge, double-click on the video.
Step-by-Step Guide
Step 1: Search stealer logs for stolen credentials
How to:
- Add the Domain Entity to the graph.
- Open the Transform menu by right-clicking on the Entity.
- Navigate to Person of Interest → D4 - Stealer log search (email domain). This Transform looks for stolen records where a login or username contains your domain as an email address.
- Select all or some returned Stealer Credential Entities and run Extract ALL Personally Identifiable Information Transform. You will get the specific stolen credentials and a stealer log.
Please note that stealer logs are only accessible to Enterprise plan users. If you do not see the Transforms mentioned above in your Transform Menu, you might be on a different plan. In that case, jump to Step 3.
The search queries data that has already been stolen or breached and is already circulating in underground markets. Nothing is being accessed, compromised, or exfiltrated by running it.
- The employee's name, attached to the corporate email address in the record.
- The password captured alongside it — check whether it would still work, and whether its pattern suggests others in use.
- The originating IP address of the infected endpoint.
- The service the credentials were used against.
Step 2: Explore a specific endpoint
After you expand the stealer credentials, the graph will populate it with the stealer log Entity. Move the stealer log Entity to a new graph and run Extract ALL Personally Identifiable Information.
Graph will return everything harvested from that specific device that might include:
- social media handles
- personal email addresses
- physical addresses
- phone numbers
- browsing and search history
- financial or banking details.
Step 3: Look for breach data against the domain
How to:
- Open the Transform menu by right-clicking on the Entity.
- Run Person of Interest → Comprehensive Search → [POI] D4 - Leaked Records Search (domain) or [Darkweb] Search Posts by Email Domain [DarkOwl]
- Once breach results appear, select the Compromised Records Entities on your graph. Right-click and run Extract all personally identifiable information to pull structured data out of those records.
What you can find
Leak records referencing the domain, typically surfacing a long list of exposed email addresses.
When to stop?
What's next?
-
Map the online presence of an alias identity.
-
Set up a Threat Actor monitor for tracking the person's social media feed for threatening posts.
-
Investigate the threat actor on Telegram
Other guides you might find useful:
Give us your Feedback!
Copyright © 2026
