Step-by-step workflow guide for investigators
Real-world Identification
Who is this for?
What is on this page?
How to use this page?
Follow the steps in order. This is an iterative workflow — each step may reveal new leads that feed back into earlier steps. The more accounts your subject has, the more corroboration you'll be able to build.
Please note that the data returned by Graph is always live, and the results in the video demonstration might not be reproduced at a later time if they disappeared from the public domain.
New to Graph?
A note on results
Before you start:
Identify the starting point
- Alias of the account you are assessing.
- Optional: Any known context about the subject — platform they're active on, interests, approximate location.
Access
- Open Maltego Graph (Browser) from app.maltego.com .
Note that you need a Maltego ID to log in. - Make sure your plan includes access to the product (not included for Basic plan users).
- Check if your Organization Admin enabled access to the AI Assistant.
Credit Management
- Check your organization Credits before starting.
- This workflow is iterative — if multiple alternate aliases are discovered, each requires its own search run.
- Monitor Credit usage after each Transform to stay within limits.
Resources
This guide assumes basic familiarity with Graph (Browser). Feature names link to the documentation where needed. It helps to have the following pages open before you start:
Related workflows:
- Digital Footprint Mapping — if you want to map the subject's online presence.
- Search: Person of Interest / Identity Resolution — for email address investigations.
Any real-world identity information found through this workflow must be verified against legal or official records before being used in formal proceedings or decisions.
Video Overview
Watch a real-world identification workflow demonstration. Then follow the step-by-step guide below to build your own, or skip the video and jump straight to the steps.
To enlarge, double-click on the video.
Step-by-Step Guide
Step 1: Add Your Starting Alias and Run a Comprehensive Search
How to do it:
- Click "Add Entities".
- Find and select the Alias Entity type — usernames are called aliases in Graph.
- Click on the Entity and change the default text to your target username (e.g., username_example).
- Right-click the Alias Entity to open the Transform menu.
- Navigate to: Comprehensive Search -> Search Online Profiles.
- Set the output size to Large to maximise the number of results returned.
- Click Run.
What you will find:
Your graph will populate with social media profile Entities across platforms. Typical results may include profiles on major social platforms, forums, and content sites. Each Entity will show the platform, the username, and — where publicly available — a display name or bio snippet.
Step 2: Evaluate Returned Profiles and Cross-Check for Consistency
What to look for:
- Bio overlap: Shared interests, phrases, or keywords appearing across multiple profiles — these are strong corroboration signals.
- Language and location indicators: Consistent language use (e.g., same non-English language across bios) or regional flags and references.
- Profile pictures: If a profile displays a photo of the account owner, note it — you'll use it for visual cross-referencing later.
Step 3: Visit Key Profiles Directly on the Platform
What to look for:
- Links to other platforms in the bio.
- Photos and videos where the subject may appear in person.
- New aliases from links to other platforms.
Repeat Step 1 if you discover a new alias in the bio.
Step 4: Run Supplementary Platform-Specific Transforms
If your subject is active on platforms you'd expect to see but haven't found yet, run targeted transforms for those platforms separately. In Graph (Browser), platform-specific Transforms start with "Deep Dive - [Platform Name]".
Some platform-specific transforms search by profile name rather than exact username match:
- Search Profiles Transform returns profiles with similar names. This can return profiles with similar names that don't belong to your subject.
- Get Profile Transform returns the exact username match if one exists.
When a new platform profile is returned, verify it belongs to your subject using the same corroboration signals from Step 2: shared bio content, profile picture consistency, language, and stated interests. A matching profile picture across platforms is a particularly strong indicator.
Step 5: Identify a Real Name and Corroborate Visually
Evaluating a Candidate's name:
- Check whether the name appears on more than one platform. A name that shows up consistently across multiple accounts is a stronger signal than a single occurrence.
- Look at whether the name is plausible in the context of other indicators (e.g., consistent with the language, region, or cultural references you've observed).
- Note the name but treat it as unverified until you have supporting evidence.
Visual Corroboration:
- Compare profile photos across platforms where the subject has uploaded images of themselves.
- Look for consistent physical identifiers: distinctive items of clothing or jewellery, tattoos, or repeated use of the same photograph
- If a profile photo on one platform matches an image on another, that is a meaningful corroboration signal.
What's next?
-
Set up Threat Actor Monitor to keep tabs on the threat actor if you suspect they might present danger.
-
Run a Personal Threat Assessment if the identified individual may pose a risk to a person or organization.
-
Map the threat actor's entire digital presence.
Other guides you might find useful:
Give us your Feedback!
Copyright © 2026
