Step-by-step workflow guide for investigators

Threat Actor Monitoring

This guide walks you through setting up a dedicated monitor for a known threat actor — tracking their accounts across platforms, applying the right filters to surface threatening or escalating content, and configuring alerts and reports so you stay informed without actively checking. By the end, you will have a live, low-maintenance case that delivers daily visibility into what your subject is posting and flags anything that warrants closer attention.

Before you start:

First Steps

  • Identify the accounts first using Maltego Search, Graph or other monitors such as event or brand reputation monitors. 
  • Keep the case small by limiting to a small cluster of connected accounts of threat actors.
  • Create a new case skipping the Case Wizard.

To enlarge, double-click on the video.

Platform Limits

  • 4 hour-backfill only — when you create a new case, Monitor retrieves posts from the previous four hours only and cannot go further back. 
  • Max 5 languages per search – never leave language blank
  • Filters narrow down your view of already collected messages, they do not affect how much data is pulled in.
  • X, Instagram, Facebook, Snapchat have monthly caps.
  • Cases auto-pause — set to long enough for sufficient intel gathering..

Access

  • Open Maltego Monitor from maltego.monitor.com or app.maltego.com
    Note that you need a Maltego ID to log in.
  • Make sure your plan includes access to Maltego Monitor (only Maltego Enterprise customers have Monitor included in their plans).

Resources

This guide assumes basic familiarity with Monitor. Feature names link to the documentation where needed. It helps to have the following pages open before you start: 


Video Overview

Watch a real threat actor monitoring case being set up in Monitor from scratch — searches, filters, and refinements included. Then follow the step-by-step guide below to build your own, or skip the video and jump straight to the steps.

To enlarge, double-click on the video.

Step-by-Step Guide

1. Set up your Searches

Search Example Query Key Notes
Threat actor account(s)
[Threat Actor A username 1] [Threat Actor B username] [Threat Actor A username 2]
  • Add each account handle as a separate search instead of combining them with AND/OR search operators. Keeping them separate lets you see which networks the account posts on most.  
  • Add up to 5 languages if needed.

2. Analyze 

Once your case has been running for 24-48 hours, you will have enough content to start analyzing what is being captured and analyzing the data. This section explains how you can further analyze the collected data using building blocks, filters, word count, timeline, and sentiment analysis features. 

Please note that customizable building blocks are available only to Full Feature Monitor customers.

Essential steps

Calibrate with building
blocks and filters

Add building blocks as filters to surface threatening content posted by the actor.

A building block is a saved collection of keywords or phrases that you can apply to multiple searches without re-entering them. 
Depending on what threats you are monitoring, helpful building blocks could be:


— Threats
— Right extreme

If you have a Full Feature Monitor variant, you can create your own building blocks.

Filters
hide results. They can help you display only the content that features keywords in the building blocks.

Track the most
used words

Use the word count tool (in the dropdown analysis tools) to see what topics the actor is predominantly posting about. This gives a fast read on their current concerns and rhetoric.

Review the
posting timeline

Review the timeline for when the actor is posting. Times can reveal timezone, daily routines, and whether activity is spiking around specific events.



Sentiment analysis

Access the sentiment analysis tool from the same dropdown as word count and timeline and review specific posts flagged as negative. Note that this feature works only in English, German, and Dutch. 



Optional steps

Give us your Feedback!