Transforms
This section contains information on the transforms provided by Kaspersky Transforms for Maltego. The transforms can be run on different entities, including IP addresses, hashes, domains, and URLs. The transforms provide information about entities that are contained in Kaspersky Threat Intelligence Portal.
Transforms on a URL entity
The transforms that can be run on a URL
entity and the corresponding result types are provided in the following table.
Transforms that can be run on a URL entity
Transform | Resulting entity | Description |
| A set of | Get the list of files related to this URL. |
| An | Get the IP address of the host. |
| A set of | Get a list of hashes of the files downloaded from this URL. |
| A set of | Get the list of URLs that referred to this URL. |
| A set of | Get the list of URLs this URL referred to. |
| A set of | Get the list of APT Intelligence reports and Financial Threat Intelligence reports this URL is related to. |
| The initial entity enriched with zone info, a set of For information about zones, see section "About zones and statuses" in Kaspersky Threat Intelligence Portal online help. | Get the general information about this URL. |
| A | Get the WHOIS information about the URL. |
| An | Get the information about the DNS resolutions for this URL. |
Transforms on a Domain entity
The transforms that can be run on a Domain
entity and the corresponding result types are provided in the following table.
Transforms that can be run on a Domain entity
Transform | Resulting entity | Description |
| The initial entity enriched with zone info, a set of For information about zones, see section "About zones and statuses" in Kaspersky Threat Intelligence Portal online help. | Get the general information about this domain. |
| A set of | Get the list of APT Intelligence reports and Financial Threat Intelligence reports this domain is related to. |
| An | Get the information about the DNS resolutions for this domain. |
| A set of | Get the list of hashes of the files that access this domain. |
| A set of | Get the list of hashes of the files downloaded from this domain. |
| A set of | Get the list of subdomains. |
| A set of | Get the list of URLs that referred to this domain. |
| A set of | Get the list of URLs this domain referred to. |
| A | Get the WHOIS information about the domain. |
Transforms on a Website entity
The transforms that can be run on a Website
entity and the corresponding result types are provided in the following table.
Transforms that can be run on a Website entity
Transform | Resulting entity | Description |
| The initial entity enriched with zone info, a set of For information about zones, see section "About zones and statuses" in Kaspersky Threat Intelligence Portal online help. | Get the general information about this website. |
| An | Get the information about the DNS resolutions for this website. |
| A set of | Get the list of hashes of the files that access this website. |
| A set of | Get the list of hashes of the files downloaded from this website. |
| A set of | Get the list of subdomains. |
| A | Get the parent domain for the website. |
| A set of | Get the list of URLs that referred to this website. |
| A set of | Get the list of URLs this website referred to. |
| A set of | Get the list of APT Intelligence reports and Financial Threat Intelligence reports this website is related to. |
| A | Get the WHOIS information about the website. |
Transforms on a DNS Name entity
The transforms that can be run on a DNS Name
entity and the corresponding result types are provided in the following table.
Transforms that can be run on a DNS Name entity
Transform | Resulting entity | Description |
| A set of | Get the list of hashes of the files that access the domain with this DNS name. |
| A set of | Get the list of hashes of the files downloaded from the domain with this DNS name. |
| An | Get the information about the DNS resolutions for the domain with this DNS name. |
| A | Get the parent domain for the domain with this DNS name. |
| A set of | Get the list of APT Intelligence reports and Financial Threat Intelligence reports the domain with this DNS name is related to. |
| A set of | Get the list of URLs that referred to the domain with this DNS name. |
| A set of | Get the list of URLs the domain with this DNS name referred to. |
| The initial entity enriched with zone info, For information about zones, see section "About zones and statuses" in Kaspersky Threat Intelligence Portal online help. | Get the general information about the domain with this DNS name. |
| A set of | Get the list of subdomains. |
| A | Get the WHOIS information about the domain with this DNS name. |
Transforms on a Hash entity
The transforms that can be run on a Hash
entity and the corresponding result types are provided in the following table.
Transforms that can be run on a Hash entity
Transform | Resulting entity | Description |
| A set of | Get the list of URLs the file with this hash accessed. |
| A set of | Get the list of files that launched the file with this hash. |
| A set of | Get the list of files that downloaded the file with this hash. |
| A set of | Get the list of signatures the file with this hash was signed with. |
| A set of | Get the list of file names for the file with this hash. |
| A set of | Get the list of paths to the file with this hash. |
| A set of | Get the list of URLs from which the file with this hash was downloaded. |
| A set of | Get the list of files that the file with this hash launched. |
| A set of | Get the list of APT Intelligence reports and Financial Threat Intelligence reports the file with this hash is related to. |
| The initial entity enriched with zone info, For information about zones, see section "About zones and statuses" in Kaspersky Threat Intelligence Portal online help. | Get the general information about the file with this hash. |
| A set of | Get the list of files that the file with this hash downloaded. |
| A set of | Get the list of signatures that the container objects for the file with this hash were signed with. |
Transforms on an IPv4 Address entity
The transforms that can be run on an IPv4 Address
entity and the corresponding result types are provided in the following table.
Transforms that can be run on an IPv4 Address entity
Transform | Resulting entity | Description |
| A | Get the country code for this IP address. |
| A | Get the information about the DNS resolutions for this IP address. |
| A set of | Get the list of hashes of the files downloaded from this IP address. |
| A set of | Get the list of URLs that are related to this IP address. |
| A set of | Get the list of APT Intelligence reports and Financial Threat Intelligence reports this IP address is related to. |
| The initial entity enriched with zone info, For information about zones, see section "About zones and statuses" in Kaspersky Threat Intelligence Portal online help. | Get the general information about this IP address. |
|
| Get the WHOIS information about this IP address. |