Maltego SecurityTrails Transforms
Modified on: Tue, 8 Oct, 2024 at 8:30 AM
Overview
Maltego's SecurityTrails Transforms are provided to Maltego users as part of the Maltego Standard Transforms which any Maltego Graph Client has access to. The Maltego Standard Transforms support a vast variety of investigative tasks, including network footprinting, social media investigations, digital forensics, enriching threat intelligence, analyzing web content and more. They can be used on their own to conduct investigations, or supplement other specialized integrations available in the Data Hub.
For more information about Maltego Standard Transforms click here.
To DNS Name (interesting) [SecurityTrails]
Description
This Transform will search for a set of interesting DNS names in the DNS zone using SecurityTrails.
API Key | string | | True | False | false |
Interesting Sub Domains | string | vpn,webmail,mail,firewall,test,scada,intranet,secure,ssh,database | true | false | false |
Display Name | To DNS Name (interesting) [SecurityTrails] |
Owner | |
Author | Maltego Technologies |
Data Source | SecurityTrails |
Transform Name | DomainToDNSName_DB_interest |
Input Entities | maltego.Domain |
Output Entities | maltego.DNSName |
Short Description | This Transform will search for a set of interesting DNS names in the DNS zone using SecurityTrails. |
To DNS Name [SecurityTrails]
Description
This Transform will search for a given DNS name in the passive DNS database of SecurityTrails.
API Key | string | | True | False | false |
Display Name | To DNS Name [SecurityTrails] |
Owner | |
Author | Maltego Technologies |
Data Source | SecurityTrails |
Transform Name | DomainToDNSName_DB |
Input Entities | maltego.Domain |
Output Entities | maltego.DNSName |
Short Description | This Transform will search for a given DNS name in the passive DNS database of SecurityTrails. |
To DNS Name from passive DNS [SecurityTrails]
API Key | string | | True | False | false |
Display Name | To DNS Name from passive DNS [SecurityTrails] |
Owner | |
Author | Maltego Technologies |
Data Source | SecurityTrails |
Output Entities | maltego.DNSName |
Variants
IPAddressToDNSName_SharedIP | maltego.IPv4Address | This Transform will search for DNS names for a given IPv4 address in the passive DNS database of SecurityTrails. |
IP6AddressToDNSName_SharedIP | maltego.IPv6Address | This Transform will search for DNS names for a given IPv6 address in the passive DNS database of SecurityTrails. |
To DNS Names in Netblock [SecurityTrails]
API Key | string | | True | False | false |
Display Name | To DNS Names in Netblock [SecurityTrails] |
Owner | |
Author | Maltego Technologies |
Data Source | SecurityTrails |
Output Entities | maltego.DNSName |
Variants
NetblockToDNSName_SS | maltego.Netblock | This Transform will search for DNS names in a given IP address range using SecurityTrails passive DNS. |
CIDRToDNSName_SS | maltego.CIDR | This Transform will search for DNS names in a given IP subnet using SecurityTrails passive DNS. |
To Domains [Sharing this MX]
Description
This transform determines which other domains share this MX record by looking at historical/passive DNS
API Key | string | | True | False | false |
Display Name | To Domains [Sharing this MX] |
Owner | |
Author | Maltego Technologies |
Data Source | Sharing this MX |
Transform Name | MXrecordToDomain_SharedMX |
Input Entities | maltego.MXRecord |
Output Entities | maltego.Domain |
Short Description | This transform determines which other domains share this MX record by looking at historical/passive DNS |
To Domains [Sharing this NS]
Description
This transform determines which other domains share this NS record by looking at historical/passive DNS.
API Key | string | | True | False | false |
Display Name | To Domains [Sharing this NS] |
Owner | |
Author | Maltego Technologies |
Data Source | Sharing this NS |
Transform Name | NSrecordToDomain_SharedNS |
Input Entities | maltego.NSRecord |
Output Entities | maltego.Domain |
Short Description | This transform determines which other domains share this NS record by looking at historical/passive DNS. |