Step-by-step workflow guide for investigators
Personal Threat Assessment
Who is this for?
What is on this page?
How to use this page?
The workflow is designed to be completed in under 15 minutes once the data collection transform has finished running. Have the username of the account you're assessing ready before you begin.
Please note that the data returned by Graph is always live, and the results in the video demonstration might not be reproduced at a later time if they disappeared from the public domain.
New to Graph?
A note on results
Before you start:
Identify the starting point
- Alias of the account you are assessing. Graph (Browser) can collect posts from X, Facebook, Instagram, Linkedin, TikTok, and Telegram.
Access
- Open Maltego Graph (Browser) from app.maltego.com .
Note that you need a Maltego ID to log in. - Make sure your plan includes access to the product (not included for Basic plan users).
- Check if your Organization Admin enabled access to the AI Assistant.
Resources
This guide assumes basic familiarity with Graph (Browser). Feature names link to the documentation where needed. It helps to have the following pages open before you start:
If you have not identified a specific account to assess for threats, consider setting up a VIP protection , event monitoring, or brand reputation monitors first to see the actors posting violent or threatening content in relation to a person or an event.
Video Overview
Watch a personal threat assessment workflow demonstration. Then follow the step-by-step guide below to build your own, or skip the video and jump straight to the steps.
To enlarge, double-click on the video.
Step-by-Step Guide
Step 1: Add the Alias Entity
In this demo, we used Br0kenBritain alias, since this is the X username of the account we are assessing.
Step 2: Collect feed messages
Graph (Browser) supports Transforms that let you collect feed messages from social media platforms. Supported platforms for feed message collection include: X, Facebook, Linkedin, TikTok, Telegram, and Instagram.
To run the Transform, open the Deep Dive - [platform name] Transform set and run Get Feed Messages on [platform name]. The Transform will fetch the user profile on the platform and all available posts from their timeline or feed.
Once complete, your graph will populate with Post Entities — one for each post. For example, an active account might return 700+ individual Entities connected to the original alias.
This Transform takes several minutes to complete, especially for accounts with hundreds or thousands of posts. Be patient and let it finish running before proceeding to the next step.
Step 3: Analyze content with AI
With hundreds or thousands of posts collected, manual review is impractical. Use Graph Browser's AI Assistant feature to automatically scan all posts for direct threats, violent language, and concerning rhetoric.
How to do it:
- In the Graph (Browser) interface, locate the AI assistant icon on the left.
- Type your analysis query. For example: "Does this user make any direct threats against individuals in the tweets they post?"
- Press Enter to submit the query.
- The AI will ask for permission to access your graph — this happens every time for privacy protection. Click Allow.
- The AI may confirm: "Do you want to analyze all ~800 Entities?" Confirm Yes.
- Wait for the AI to process all Post Entities. This takes 2-3 minutes depending on volume.
- AI Assistant will provide a summary analysis identifying context, direct threats, quotes, violent rhetoric.
What's next?
-
Set up Threat Actor Monitor to keep tabs on the threat actor if you suspect they might present danger.
-
Map the threat actor's entire digital presence.
-
Preserve social media posts before they disappear.
Other guides you might find useful:
Give us your Feedback!
Copyright © 2026
