Cyber Threat Intelligence

Modified on: Wed, 15 Oct, 2025 at 8:09 AM

Maltego Data Pass supports cyber threat investigations through transforms that enrich IP address information. These transforms enable investigators to attribute infrastructure to threat actors or campaigns, assess the risk level of an IP address, pivot to related domains, hashes, or other indicators of compromise (IOCs), and build a contextual profile of the IP for reporting or escalation. You can try it yourself by following the steps below:

  1. Add an IPv4 Address Entity.
  2. Run Get Details Transform.
  3. Run Get Tags and Indicators Transform.


Results May Include:

  • Geolocation (country, city)
  • ISP and ASN information
  • Hosting provider
  • Network type and assignment
  • Threat tags (e.g., “botnet”, “phishing”, “malware C2”)
  • Risk scores or reputation indicators
  • Related campaign identifiers
  • Historical associations with malicious activity


Did you find it helpful? Yes No

Send feedback
Sorry we couldn't be helpful. Help us improve this article with your feedback.