IT Forensics · OSINT

Warum LanCologne auf Maltego setzt

Maltego ist ein etabliertes Werkzeug zur strukturierten Visualisierung von Verknüpfungen zwischen öffentlich zugänglichen Informationen wie Personen, Organisationen, Domains und technischer Infrastruktur.

Enquire without obligation

This point is particularly important in OSINT research, as the scope, quality and reliability of publicly available information can vary greatly depending on the research question, the individual or organisation concerned, and the platform used. Corporate research, an infrastructure analysis and the verification of a single piece of social media content must not be treated in the same way. The source, timeliness, verifiability and legal framework determine which information is reliable and which research method is appropriate.

Wir setzen Maltego gezielt dort ein, wo komplexe Zusammenhänge zwischen mehreren Entitäten grafisch nachvollziehbar dargestellt werden müssen, etwa bei Firmenbeteiligungen oder Angreiferinfrastruktur.

Why LanCologne?

LanCologne does not conduct OSINT investigations according to a standardised, one-size-fits-all approach, but rather on the basis of the specific issue to be proven, the available public sources and the relevant legal framework. Our staff have decades of experience in information technology and many years of practical experience in IT forensics. We assist companies, solicitors and private individuals, as well as regularly supporting courts and public authorities, in the technical investigation of digital matters.

Research is always carried out in a documented and traceable manner. Where technically possible, publicly accessible online content that is found is archived promptly or saved as a screenshot in order to preserve its evidential value, even if the original content is subsequently altered or deleted.

Our working methods and the tools we use

Our OSINT investigation does not begin with an unstructured online search, but rather by contextualising the specific evidential question within the framework of an existing IT forensic, legal or internal corporate case. Only then is it determined which publicly available digital sources may be relevant to the question and in what order they should be examined.

The next step is to define the research strategy. In doing so, we determine whether relevant information can be obtained from social media, public registers, technical infrastructure data or generally accessible web content. The selection of sources is based solely on the specific question to be proven, not on the mere availability of individual tools.

Every step of the research process and every piece of digital evidence found is documented with a timestamp and a reference to the source and, where technically possible, saved in the form of a screenshot or an archived copy. This ensures traceability is maintained even if the original online content has since been altered or deleted.

Maltego setzen wir gezielt zur strukturierten Visualisierung komplexer Verknüpfungen zwischen mehreren Entitäten ein; die inhaltliche Bewertung jeder dargestellten Verbindung erfolgt weiterhin durch manuelle fachliche Prüfung.

For readers unfamiliar with the subject, one point is particularly important: an OSINT tool does not automatically „find" the truth. It aggregates and links publicly available information according to programmed rules, meaning that outdated, incorrect or deliberately misleading online content may be incorporated into a result without being detected. That is why, when dealing with critical findings, we check the source of the information and whether a second, independent source confirms the same facts.

For our OSINT research, we use established tools such as Maltego, SpiderFoot and Shodan, supplemented by structured manual research via search engines, social media and public registers. Our OSINT services are always provided as a complementary component to existing IT forensic, legal or internal corporate enquiries, and not as a standalone people search or investigative activity in the sense of a private detective agency. If a request falls outside this scope, we will make this clear rather than tacitly providing a service that is not covered.

Typical areas of application

Judicial and non-judicial expert reports
Supplementary investigations as part of existing IT forensic investigations
Support for businesses, solicitors, courts and public authorities
Verification of digital traces and online content
Analysis of corporate, infrastructure and threat intelligence from open sources
Investigating incidents of fraud, trademark infringement and cyber security breaches
Cross-checking of automatically generated search results
Documentation and archiving of ephemeral online content
Documentation for courts, solicitors, insurance companies, public authorities and businesses

This is how OSINT research works

1Classification of the question of evidence

First of all, we clarify the IT forensic, legal or internal corporate context of the investigation and the specific question to be answered. This determines the scope and limits of the subsequent investigation.

2Selection of sources

The question of evidence determines which publicly available sources – such as social media, registers, technical infrastructure data or general web content – may be relevant.

3Structured research

The research is carried out using our established tools as well as structured manual checks. Each step is documented to ensure that the process is traceable.

4Archiving and Documentation

Where technically feasible, relevant online content is archived promptly or saved as a timestamped screenshot in order to preserve its evidential value even if it is subsequently altered.

5Multi-stage evaluation

The information found is analysed in a structured manner and, where possible, cross-checked against other independent sources in order to avoid errors arising from reliance on a single source.

6Manual validation

In the case of findings that are particularly relevant to the evidence or unusual, we manually verify the source, context and plausibility in order to rule out automated misinterpretations or deliberate disinformation.

7Report and reference to evidence

At the end, we do not simply list the findings of our research. We explain which source supports each finding, what conclusions can be drawn, and where the limits of our research lie.

Why is this area of investigation relevant to forensics?

Maltego ist ein etabliertes Werkzeug zur strukturierten Visualisierung von Verknüpfungen zwischen öffentlich zugänglichen Informationen wie Personen, Organisationen, Domains und technischer Infrastruktur.

The forensic value lies not solely in the volume of information found, but in its source and reliability. A single social media post, a register entry or a technical infrastructure note can be misleading without context. That is why we document how a piece of information may have come about, what alternative explanations exist and what further sources support the finding.

Wir setzen Maltego gezielt dort ein, wo komplexe Zusammenhänge zwischen mehreren Entitäten grafisch nachvollziehbar dargestellt werden müssen, etwa bei Firmenbeteiligungen oder Angreiferinfrastruktur.

Particularly in the case of OSINT research, attempts at full verification may also reach their limits if online content has been deleted, made private or deliberately designed to be misleading. A lack of verifiability, closed platforms and rapidly changing content highlight why timely documentation and transparent communication of existing limitations are so important prior to the actual analysis. Omissions at this stage cannot always be rectified later on.

Frequently Asked Questions

Was leistet Maltego bei einer OSINT-Recherche?+
Maltego visualisiert strukturiert Verknüpfungen zwischen öffentlich zugänglichen Informationen wie Personen, Organisationen, Domains und technischer Infrastruktur.
Warum ist eine solche Visualisierung forensisch hilfreich?+
Sie macht komplexe Zusammenhänge zwischen mehreren Entitäten nachvollziehbar und erleichtert die Identifikation relevanter Verbindungen.
Werden die von Maltego dargestellten Verknüpfungen ungeprüft übernommen?+
Nein, jede dargestellte Verknüpfung wird vor Übernahme in den Bericht manuell auf Plausibilität geprüft.
Ist Maltego für jede Fragestellung geeignet?+
Nein, der Einsatz richtet sich nach der konkreten Fragestellung; bei einfachen Sachverhalten kann eine gezielte manuelle Recherche ausreichend sein.

LanCologne – IT Forensics OSINT Cologne

Sie benötigen eine professionelle OSINT-Recherche zu „Warum LanCologne auf Maltego setzt"? LanCologne unterstützt Sie bei der strukturierten, dokumentierten Auswertung öffentlich zugänglicher digitaler Quellen im Rahmen bestehender IT-forensischer, rechtlicher oder unternehmensinterner Fragestellungen. Entscheidend ist dabei nicht, möglichst viele Treffer zu erzeugen, sondern technisch belastbare und überprüfbare Informationen zu sichern.

Get in touch now