SkillAgentSearch skills...

maltego-mcp

OSINT graphs are point-and-click busywork. maltego-mcp lets an LLM author the .mtgx and run the whois, DNS, ASN, and crt.sh lookups. Works on the Basic plan.

Install / Use

claude mcp add lidless-labs -- npx -y github:lidless-labs/maltego-mcp

If the server publishes to npm under a different name, use that package instead — check the repo README.

About this skill
🔌

MCP Server

Model Context Protocol server

Quality Score

84/100

Supported Platforms

Claude Code
Claude Desktop
<p align="center"> <img src="docs/assets/maltego-mcp-banner.jpg" alt="maltego-mcp banner" width="900"> </p> <p align="center"> <a href="https://lidless.dev"><img src="docs/assets/marks/maltego-mcp-circle.png" width="48" alt="Lidless Labs"></a> </p> <h1 align="center">maltego-mcp</h1> <p align="center"><strong>An MCP server that lets an LLM author Maltego graph files and run primitive OSINT lookups.</strong></p> <p align="center"> <a href="https://lidless.dev/maltego-mcp"><b>Website</b></a> </p> <p align="center"> <img src="https://shieldcn.dev/npm/maltego-mcp.svg" alt="npm version"> <img src="https://shieldcn.dev/github/ci/lidless-labs/maltego-mcp.svg?branch=main&workflow=ci.yml" alt="ci"> <img src="https://shieldcn.dev/badge/MCP-server-8A2BE2.svg" alt="MCP server"> <img src="https://shieldcn.dev/badge/license-MIT-green.svg" alt="license MIT"> </p>

maltego-mcp is a Model Context Protocol (MCP) server that lets an LLM author Maltego .mtgx graph files and run primitive OSINT lookups (whois, DNS, ASN, crt.sh) from inside an agent session. It exists because graph-driven OSINT investigation in Maltego Desktop is normally point-and-click work, and an agent that can already reason over indicators should be able to produce the graph directly instead of dictating clicks to a human. It differs from a Maltego transform pack by living in the agent layer first: the graph is built and saved to disk by tool calls, then opened in Maltego, so it works even on the Basic plan and without paid connectors. A second optional layer (Phase B) does add native right-click transforms inside Maltego Desktop for teams that want that too.

What it does

maltego-mcp is an MCP server for Maltego Desktop OSINT that gives an LLM agent a small, typed toolset for building Maltego graphs and enriching indicators of compromise. An agent calls these tools to create a graph, add entities and links, run whois / DNS / ASN / certificate-transparency lookups, expand an IP or domain into a pivot map, and write the result to a .mtgx file you open in Maltego Graph Desktop. Keywords: Maltego, MCP server, OSINT, threat intelligence, graph, whois, DNS, ASN, crt.sh, indicators of compromise.

It ships as two cooperating layers:

  • Phase A (TypeScript MCP server): lets an LLM author Maltego .mtgx graph files and run primitive OSINT lookups (whois / DNS / ASN / crt.sh). Graphs land on disk and you open them in Maltego Desktop.
  • Phase B (Python TRX transforms in a .mtz): adds right-click pivots into MISP, TheHive, Cortex, and the bundled MITRE ATT&CK dataset directly inside Maltego Desktop. See transforms/README.md.

The two phases share the repo, nothing else. Either layer can be uninstalled without breaking the other.

Install

npm install -g maltego-mcp

Or from source (required for Phase B transforms):

git clone https://github.com/lidless-labs/maltego-mcp.git
cd maltego-mcp
npm install
npm run build

Quickstart

Install globally and register it with an MCP client:

npm install -g maltego-mcp

Add it to your MCP client config (Claude Desktop shown; the same command works in any stdio MCP client):

{
  "mcpServers": {
    "maltego": {
      "command": "maltego-mcp"
    }
  }
}

Restart the client and the maltego_* tools appear. From a source checkout, point the client at the built entrypoint instead:

{
  "mcpServers": {
    "maltego": {
      "command": "node",
      "args": ["/absolute/path/to/maltego-mcp/dist/mcp-server.js"]
    }
  }
}

Status: v0.4.3 is published on npm and GitHub. Phase B transforms require a source checkout. See Install for all client recipes.

Tools (Phase A)

maltego-mcp registers 13 MCP tools, verified against src/tools/index.ts:

Graph authoring

  • maltego_create_graph(name) — returns graphId
  • maltego_add_entity(graphId, type, value, properties?) — returns entityId
  • maltego_add_link(graphId, from, to, label?, properties?) — returns linkId
  • maltego_save_graph(graphId, path, overwrite?) — writes .mtgx
  • maltego_load_graph(path) — parses an existing .mtgx into a new handle

Primitive lookups

  • maltego_whois(domain) — registrar, nameservers, dates
  • maltego_dns(domain) — A/AAAA/MX/NS/TXT
  • maltego_asn(ip) — Team Cymru ASN, prefix, country, org
  • maltego_crtsh(domain) — certificate transparency entries

Convenience expanders

  • maltego_expand_ip(ip, outputPath, overwrite?) — IP + ASN + netblock, saved as .mtgx
  • maltego_expand_domain(domain, outputPath, overwrite?) — domain + whois + DNS + ASN per A record
  • maltego_expand_hash(hash, outputPath, algorithm?, overwrite?) — hash entity (extend in later versions)
  • maltego_build_ioc_graph(ioc, outputPath, ...) — one IOC plus enrichment summaries from other MCPs, saved as .mtgx

Entity types

Standard Maltego ontology: IPv4Address, IPv6Address, Domain, URL, Hash, EmailAddress, Netblock, AS, Website, Company, Person. For concepts without a standard type, use Phrase with a category prefix ([T1566] Phishing, [TheHive] Case #42).

Composing with other MCPs

maltego-mcp does not embed third-party threat-intel clients. For MISP events, ATT&CK techniques, Cortex reports, etc., call the dedicated MCPs (misp-mcp, mitre-mcp, cortex-mcp, etc.) and pipe results into maltego_add_entity / maltego_add_link. Or, for in-Maltego pivots, install Phase B (below).

For the common "one IOC, many enrichments" case, use maltego_build_ioc_graph: call misp-mcp, thehive-mcp, cortex-mcp, and mitre-mcp first, summarize their results into the tool's mispEvents, thehiveCases, cortexReports, and attackTechniques arrays, then save one combined .mtgx. The tool keeps service calls out of this package while still making the graph bridge a single MCP call.

Configuration

Both env vars are optional.

| Variable | Default | Description | |---|---|---| | MALTEGO_MCP_OUTPUT_DIR | ~/MaltegoGraphs | Default output directory for .mtgx files | | MALTEGO_MCP_LOOKUP_TIMEOUT_MS | 30000 | Per-lookup timeout in ms (currently applied to crt.sh only; whois, dns, asn use library defaults) |

Claude Desktop

Add to ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows):

{
  "mcpServers": {
    "maltego": {
      "command": "maltego-mcp"
    }
  }
}

Or, when running from a source checkout instead of the global npm install:

{
  "mcpServers": {
    "maltego": {
      "command": "node",
      "args": ["/absolute/path/to/maltego-mcp/dist/mcp-server.js"]
    }
  }
}

Restart Claude Desktop. The maltego_* tools should appear.

Claude Code

claude mcp add maltego -- maltego-mcp

Or from a source checkout:

claude mcp add maltego -- node /absolute/path/to/maltego-mcp/dist/mcp-server.js

Add --scope user to make it available from any directory instead of only the current project.

OpenClaw

Recommended: install as an OpenClaw plugin via ClawHub.

openclaw plugins install clawhub:maltego
openclaw plugins list   # confirm "maltego" is registered

This installs the same package as a native OpenClaw plugin — tool calls go through the plugin SDK directly instead of spawning a separate stdio MCP process. Configure outputDir and lookupTimeoutMs in OpenClaw's plugin config UI or via the JSON config file. Restart the OpenClaw gateway after installing so the plugin is picked up.

Or, register as a stdio MCP server (manual):

openclaw mcp set maltego '{
  "command": "maltego-mcp"
}'

Or, when running from a source checkout:

openclaw mcp set maltego '{
  "command": "node",
  "args": ["/absolute/path/to/maltego-mcp/dist/mcp-server.js"]
}'

Then restart the OpenClaw gateway so the new server is picked up and confirm registration with openclaw mcp list.

Hermes Agent

Hermes Agent reads MCP config from ~/.hermes/config.yaml under the mcp_servers key. Add an entry:

mcp_servers:
  maltego:
    command: "maltego-mcp"

Or, when running from a source checkout:

mcp_servers:
  maltego:
    command: "node"
    args: ["/absolute/path/to/maltego-mcp/dist/mcp-server.js"]

Then reload MCP from inside a Hermes session:

/reload-mcp

Codex CLI

Codex CLI registers MCP servers via codex mcp add:

codex mcp add maltego -- maltego-mcp

Or from a source checkout:

codex mcp add maltego -- node /absolute/path/to/maltego-mcp/dist/mcp-server.js

Codex writes the entry to ~/.codex/config.toml under [mcp_servers.maltego]. Verify with codex mcp list.

Requirements

  • Node.js 20+
  • Maltego Graph Desktop (Basic, Pro, or Enterprise) for either layer to be useful
  • Phase B only: Python 3.11+ on the Maltego host

Maltego Basic compatibility

The default workflow is Basic-friendly: generate .mtgx files with Phase A, then open or import them in Maltego Graph Desktop. The included demo graph is kept under 24 entities so it stays useful on the Basic plan's per-transform result limit. Local TRX transforms are supported on Basic, but their live results are still subject to your Maltego plan and connector limits. See Maltego's current products and plans and Basic data access notes.

CLI

The same package ships a read-only control CLI, maltegoctl, for shells, cron, and CI. It shares the lookup and graph-reading tools with the MCP server and reads the same env config. It exposes only the read/inspect surface: the OSINT lookups (whois, DNS, ASN, crt.sh) and a .mtgx inspector. Graph authoring, saving, and the .mtgx expanders stay in the MCP/plugin surface, because their primary effect is writing a file to disk.

npx maltego-mcp@latest whois example.com
# or, installed globally:
maltegoctl whois example.com
maltegoctl dns example.com
maltegoctl asn 192.0.2.10
maltegoctl crtsh example.com
maltegoctl inspect graph.mtgx        # parse an existing .mtgx, list entities + links
maltegoctl dns example.com --json    # raw JSON for piping

Run maltegoctl help for the full command and flag list. --json emits raw JSON instead of the concise human-readable summary. inspect reads from inside MALTEGO_MCP_OUTPUT_DIR only and never writes; the lookup tools make outbound queries but mutate nothing. Exit codes: 0 success, 1 runtime error (a lookup failed, the host was unreachable, or the .mtgx could not be read), 2 usage error (unknown command/flag or a missing argument).

Environment:

| Variable | Default | Description | |---|---|---| | MALTEGO_MCP_OUTPUT_DIR | ~/MaltegoGraphs | Base directory inspect paths are confined to | | MALTEGO_MCP_LOOKUP_TIMEOUT_MS | 30000 | Per-lookup timeout in ms (applied to crtsh only) |

Starting the MCP server

maltegoctl mcp (or the back-compat maltego-mcp bin) starts the stdio MCP server. If a launcher referenced the file path dist/mcp-server.js directly, it keeps working; new launchers can point at dist/mcp-bin.js (or dist/cli.js mcp). Launchers that use the maltego-mcp bin name need no change.

Basic-friendly demo graph

Generate a no-network .mtgx demo that shows how an IOC can connect to MISP, TheHive, Cortex, MITRE ATT&CK, and a triage playbook without requiring API keys or paid Maltego connectors:

npm run demo:basic

Output defaults to dist/maltego-mcp-basic-soc-demo.mtgx. Open that file in Maltego Graph Desktop. To choose a different path:

npm run demo:basic -- --ou

Truncated for display — read the full file on GitHub.

Related Skills

View on GitHub
GitHub Stars10
CategoryAI
Updated13d ago
Forks2

Languages

TypeScript

Security Score

97/100

Audited on Aug 23, 2026

1 info