Cyber Threat Intelligence

Modified on Wed, 15 Oct at 8:09 AM

Maltego Data Pass supports cyber threat investigations through transforms that enrich IP address information. These transforms enable investigators to attribute infrastructure to threat actors or campaigns, assess the risk level of an IP address, pivot to related domains, hashes, or other indicators of compromise (IOCs), and build a contextual profile of the IP for reporting or escalation. You can try it yourself by following the steps below:

  1. Add an IPv4 Address Entity.
  2. Run Get Details Transform.
  3. Run Get Tags and Indicators Transform.


Results May Include:

  • Geolocation (country, city)
  • ISP and ASN information
  • Hosting provider
  • Network type and assignment
  • Threat tags (e.g., “botnet”, “phishing”, “malware C2”)
  • Risk scores or reputation indicators
  • Related campaign identifiers
  • Historical associations with malicious activity


Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article