Skip to content

Maltego: Iris Investigate transforms

Iris Investigate transforms surface the DomainTools Iris Investigate dataset directly inside Maltego. Use them for enrichment (add context to an entity already on the graph) and for pivoting (discover new related entities).

The transforms below are organized by the entity you start from. Each section lists the transform, the input it consumes, the output entities it produces, and a short description.

You can start from any of the following Maltego entity types:

  • Domain (apex or publicly registered domain)
  • Email address
  • IPv4 address (including entities produced by Maltego as Hosting IP, Name Server IP, or Mail Server IP)
  • Name server hostname
  • Mail server hostname
  • Registrant name
  • Registrant organization
  • Registrar
  • SSL organization
  • SSL subject field contents
  • SSL certificate SHA hash
  • Google Adsense code (as a phrase entity)
  • Google Analytics code (as a phrase entity)
  • Iris Search Hash (a phrase entity populated with the Iris Search Export value)
  • Redirect domain
TransformOutputDescription
Domain to Domain ProfileDomain (enriched)Populates the properties view with Alexa rank, create date, expiration date, and DomainTools Risk Score. Adds a link back to the matching Iris search.
Domain to Risk ComponentsDomain (enriched)Populates the properties view with the four component scores that make up the Domain Risk Score: Proximity, Threat Profile, and Threat Profile malware/phishing/spam sub-scores.
Domain to Contact Email AddressesEmail AddressReturns aggregated contact email addresses from the WHOIS record.
Domain to Contact AliasesAliasReturns aggregated contact names (administrative, billing, technical) from the WHOIS record.
Domain to RegistrantDomain RegistrantReturns the registrant name from the WHOIS record.
Domain to Registrant OrganizationOrganizationReturns the registrant organization from the WHOIS record.
Domain to RegistrarRegistrarReturns the registrar that registered the domain.
Domain to IP AddressesIPv4 AddressReturns the IPv4 addresses hosting the domain.
Domain to ASNASReturns the Autonomous System Numbers associated with the domain’s hosting IPs.
Domain to ISPsCompanyReturns the internet service providers hosting the domain.
Domain to NS RecordsNS RecordReturns the nameserver hostnames delegated by the domain.
Domain to MX RecordsMX RecordReturns the mail server hostnames in the domain’s MX record.
Domain to SOA EmailEmail AddressReturns the DNS/SOA email address associated with the domain.
Domain to SSL EmailEmail AddressReturns email addresses extracted from SSL certificates associated with the domain.
Domain to SSL HashHashReturns the SHA hashes of SSL certificates resolving to the domain via SNI.
Domain to SSL OrganizationOrganizationReturns the parsed issuer organization from SSL certificates associated with the domain.
Domain to SSL SubjectsPhraseReturns the subject-field contents from SSL certificates associated with the domain.
Domain to Email DomainsDomainBreaks out the apex domains of every WHOIS/SOA/SSL email address associated with the domain.
Domain to Adsense CodePhraseReturns the Google Adsense code observed in the www. subdomain’s page source.
Domain to Analytics CodePhraseReturns the Google Analytics code observed in the www. subdomain’s page source.
Domain to Redirect DomainDomainReturns the destination domain of any HTTP 301 redirect configured for the domain when DomainTools first observed it.
Domain to Redirect Domain (recursive)DomainFollows a chain of redirects recursively from the domain until no further redirects are found.
TransformOutputDescription
IP to DomainsDomainReturns domains hosted at this IPv4 address (DNS A records).
Name Server IP to Name Server DomainsDomainFrom a name server’s IP, returns the apex domains of every name server hostname that resolves to this IP.
Mail Server IP to Email DomainsDomainFrom a mail server’s IP, returns apex email domains of WHOIS records of domains hosted at this IP.

Returned domain entities are enriched with DomainTools Risk Score, create date, expiration date, and an Iris-search link.

TransformOutputDescription
Email to DomainsDomainReturns every domain with a WHOIS, DNS/SOA, or contact email matching this address.
Email to Domains (SSL)DomainReturns every domain whose SSL certificate contains this email address.
TransformOutputDescription
Registrant to DomainsDomainReturns domains whose WHOIS registrant name matches this value.
Registrant Organization to DomainsDomainReturns domains whose WHOIS registrant organization matches this value.
Registrar to DomainsDomainReturns domains registered by this registrar.
TransformOutputDescription
SSL Organization to DomainsDomainReturns domains whose SSL certificate issuer organization matches this value.
SSL Subject to DomainsDomainReturns domains whose SSL certificate subject field contains this value.
SSL Hash to DomainsDomainReturns domains whose SSL certificate has this SHA hash.
TransformOutputDescription
Name Server to DomainsDomainReturns apex domains using this name server hostname for their DNS NS delegation.
Mail Server to DomainsDomainReturns domains whose MX record is this mail server hostname.
TransformOutputDescription
Adsense Code to DomainsDomainReturns domains observed sharing this Google Adsense code.
Analytics Code to DomainsDomainReturns domains observed sharing this Google Analytics code.
TransformOutputDescription
Iris Search Hash to DomainsDomainReverses an Iris Search Export (search hash phrase) to the list of domains matching that Iris query. Use this to replay Iris UI research inside Maltego.

Many transforms add a DT Count property to result entities. This represents the number of times the attribute co-occurred with the input across DomainTools’ data, and is a useful signal when ranking pivots.

Enriched Domain entities produced by Iris transforms include an IRIS Link in the display-information panel that deep-links to the matching Iris search at research.domaintools.com.