IT Forensics · OSINT
Warum LanCologne auf Maltego setzt
Maltego ist ein etabliertes Werkzeug zur strukturierten Visualisierung von Verknüpfungen zwischen öffentlich zugänglichen Informationen wie Personen, Organisationen, Domains und technischer Infrastruktur.
This point is particularly important in OSINT research, as the scope, quality and reliability of publicly available information can vary greatly depending on the research question, the individual or organisation concerned, and the platform used. Corporate research, an infrastructure analysis and the verification of a single piece of social media content must not be treated in the same way. The source, timeliness, verifiability and legal framework determine which information is reliable and which research method is appropriate.
Wir setzen Maltego gezielt dort ein, wo komplexe Zusammenhänge zwischen mehreren Entitäten grafisch nachvollziehbar dargestellt werden müssen, etwa bei Firmenbeteiligungen oder Angreiferinfrastruktur.
Why LanCologne?
LanCologne does not conduct OSINT investigations according to a standardised, one-size-fits-all approach, but rather on the basis of the specific issue to be proven, the available public sources and the relevant legal framework. Our staff have decades of experience in information technology and many years of practical experience in IT forensics. We assist companies, solicitors and private individuals, as well as regularly supporting courts and public authorities, in the technical investigation of digital matters.
Research is always carried out in a documented and traceable manner. Where technically possible, publicly accessible online content that is found is archived promptly or saved as a screenshot in order to preserve its evidential value, even if the original content is subsequently altered or deleted.
Our working methods and the tools we use
Our OSINT investigation does not begin with an unstructured online search, but rather by contextualising the specific evidential question within the framework of an existing IT forensic, legal or internal corporate case. Only then is it determined which publicly available digital sources may be relevant to the question and in what order they should be examined.
The next step is to define the research strategy. In doing so, we determine whether relevant information can be obtained from social media, public registers, technical infrastructure data or generally accessible web content. The selection of sources is based solely on the specific question to be proven, not on the mere availability of individual tools.
Every step of the research process and every piece of digital evidence found is documented with a timestamp and a reference to the source and, where technically possible, saved in the form of a screenshot or an archived copy. This ensures traceability is maintained even if the original online content has since been altered or deleted.
Maltego setzen wir gezielt zur strukturierten Visualisierung komplexer Verknüpfungen zwischen mehreren Entitäten ein; die inhaltliche Bewertung jeder dargestellten Verbindung erfolgt weiterhin durch manuelle fachliche Prüfung.
For readers unfamiliar with the subject, one point is particularly important: an OSINT tool does not automatically „find" the truth. It aggregates and links publicly available information according to programmed rules, meaning that outdated, incorrect or deliberately misleading online content may be incorporated into a result without being detected. That is why, when dealing with critical findings, we check the source of the information and whether a second, independent source confirms the same facts.
For our OSINT research, we use established tools such as Maltego, SpiderFoot and Shodan, supplemented by structured manual research via search engines, social media and public registers. Our OSINT services are always provided as a complementary component to existing IT forensic, legal or internal corporate enquiries, and not as a standalone people search or investigative activity in the sense of a private detective agency. If a request falls outside this scope, we will make this clear rather than tacitly providing a service that is not covered.
Typical areas of application
This is how OSINT research works
First of all, we clarify the IT forensic, legal or internal corporate context of the investigation and the specific question to be answered. This determines the scope and limits of the subsequent investigation.
The question of evidence determines which publicly available sources – such as social media, registers, technical infrastructure data or general web content – may be relevant.
The research is carried out using our established tools as well as structured manual checks. Each step is documented to ensure that the process is traceable.
Where technically feasible, relevant online content is archived promptly or saved as a timestamped screenshot in order to preserve its evidential value even if it is subsequently altered.
The information found is analysed in a structured manner and, where possible, cross-checked against other independent sources in order to avoid errors arising from reliance on a single source.
In the case of findings that are particularly relevant to the evidence or unusual, we manually verify the source, context and plausibility in order to rule out automated misinterpretations or deliberate disinformation.
At the end, we do not simply list the findings of our research. We explain which source supports each finding, what conclusions can be drawn, and where the limits of our research lie.
Why is this area of investigation relevant to forensics?
Maltego ist ein etabliertes Werkzeug zur strukturierten Visualisierung von Verknüpfungen zwischen öffentlich zugänglichen Informationen wie Personen, Organisationen, Domains und technischer Infrastruktur.
The forensic value lies not solely in the volume of information found, but in its source and reliability. A single social media post, a register entry or a technical infrastructure note can be misleading without context. That is why we document how a piece of information may have come about, what alternative explanations exist and what further sources support the finding.
Wir setzen Maltego gezielt dort ein, wo komplexe Zusammenhänge zwischen mehreren Entitäten grafisch nachvollziehbar dargestellt werden müssen, etwa bei Firmenbeteiligungen oder Angreiferinfrastruktur.
Particularly in the case of OSINT research, attempts at full verification may also reach their limits if online content has been deleted, made private or deliberately designed to be misleading. A lack of verifiability, closed platforms and rapidly changing content highlight why timely documentation and transparent communication of existing limitations are so important prior to the actual analysis. Omissions at this stage cannot always be rectified later on.
Frequently Asked Questions
LanCologne – IT Forensics OSINT Cologne
Sie benötigen eine professionelle OSINT-Recherche zu „Warum LanCologne auf Maltego setzt"? LanCologne unterstützt Sie bei der strukturierten, dokumentierten Auswertung öffentlich zugänglicher digitaler Quellen im Rahmen bestehender IT-forensischer, rechtlicher oder unternehmensinterner Fragestellungen. Entscheidend ist dabei nicht, möglichst viele Treffer zu erzeugen, sondern technisch belastbare und überprüfbare Informationen zu sichern.