Desktop

Step-by-step workflow guide for investigators

Threat Actor Telegram Investigation

Starting from a single alias associated with a threat actor group, this guide walks you through recovering the group's historical posting activity on Telegram, extracting the infrastructure they reference, tracing where those references surface across the dark web, and identifying the accounts behind them in Graph (Desktop). By the end, you will have a defensible list of accounts operating the group’s infrastructure. 

Before you start:

Identify the starting point

Alias or channel name of the group you are investigating.

Access

Note: Basic users have limited access to the data providers used in this workflow more generally — some transforms may be unavailable or return restricted results depending on your plan tier.

Resources

This guide assumes basic familiarity with Graph (Desktop). Feature names link to the documentation where needed. It helps to have the following pages open before you start: 


Video Overview

Watch a threat actor tracking workflow demonstration. Then follow the step-by-step guide below to build your own, or skip the video and jump straight to the steps.

To enlarge, double-click on the video.

Step-by-Step Guide

What's next?

  • Map the online presence of an alias identity, you're done after this workflow. 
  • Set up a Threat Actor monitor for tracking the person's social media feed for threatening posts.
  • Check out the guide for Maltego Evidence for collecting and preserving social media posts from the person's of interest account before it disappears,

Give us your Feedback!