Query
Start with one indicator — a domain, IP, hostname, or TLS fingerprint.
Every layer of the internet — DNS and routing to WHOIS, physical infrastructure, and threat intelligence — pre-joined into one live graph.Trace hidden relationships and replay point-in-time BGP & WHOIS history — every verdict sourced.
68/85 IPs in this /24 are flagged — addressing × threat, one query
Run your own →The question is not whether a domain is suspicious. It’s whether you understand everything connected to it.
Watch a single indicator expand into a complete threat infrastructure map — in milliseconds.
Start with one indicator — a domain, IP, hostname, or TLS fingerprint.
One traversal fans out across DNS, hosting, and routing — billions of nodes, sub-millisecond.
Shared registrants, co-hosting, and reused TLS fingerprints surface the hidden links.
An explained verdict, scored against 43 threat feeds — the whole cluster, not one domain.
Run the Indicator Investigation live
Starting points, not a fixed menu — it’s one queryable graph, so you can ask anything of it. Find the domain that matches your work.
Indicator Investigation · Blast Radius
Map a named actor to its ATT&CK techniques · Actor → shared TTPs → other actors
Attack-Surface Mapper · Find Subdomains
Typosquat Scanner · Build the takedown evidence package
Route-Health Checker · Enrich an ASN — routing, RPKI & physical footprint
Grade DNS & email posture · Audit mail-server & MX hygiene
Map an org’s infrastructure concentration risk · Digital Infrastructure Mapping
Map a named actor to its ATT&CK techniques · Ground your AI agent before it acts
Time Machine · Find Subdomains
Browse by roleSOC, DFIR & IRThreat intelligenceAI agents & MCPBrand protectionNetwork & BGPAttack surface & reconInfrastructure, supply-chain & complianceResearch & OSINT
Whisper is built to be queried by machines. Point your AI agents straight at the infrastructure graph over the Model Context Protocol (MCP) and let them run the messy, multi-step relationship investigations for you.
See how AI agents sign up and use Whisper directlyPipe infrastructure context straight into Splunk, Microsoft Sentinel, and the SOAR workflows your team already lives in — no rip-and-replace, no new console to learn.
| dest_ip | whisper_asn_name | whisper_country | whisper_threat_level | whisper_is_tor | whisper_is_c2 |
|---|---|---|---|---|---|
| 1.1.1.1 | CLOUDFLARENET | US | INFO | 0 | 0 |
| 185.220.101.1 | TELNA-UK | DE | INFO | tor | 0 |
| 8.8.8.8 | US | INFO | 0 | 0 | |
| 104.16.132.229 | CLOUDFLARENET | US | INFO | 0 | 0 |
| 93.184.216.34 | SYSAID-ASN | CH | NONE | 0 | 0 |
Raw dest_ip in → ASN ownership, geo, threat level, and Tor/C2 flags out — inline, no leaving Splunk. The Tor exit lights up on its own.
The graph engine behind every answer — built to take in billions of internet-scale events and resolve the hard, cross-layer queries in milliseconds.
We watch the internet’s plumbing around the clock — global DNS, BGP routing, passive SSL, and active scans — so what you query reflects what’s true right now, not last quarter.
How we stay liveOverlapping, contradictory feeds get reconciled into one clean record per thing — every domain, IP, certificate, and ASN, deduplicated and typed so the graph stays trustworthy.
Explore the technologyThen we draw the edges: who hosts whom, who shares a certificate, who routes which prefix. The result is one living map of the internet that re-stitches itself as the wiring changes.
The query languageAsk it anything from the console, the REST API, or an MCP agent and the answer returns in under a millisecond — relationship traversal and risk scoring at graph speed.
On performanceThe scale, speed, and freshness that incident responders and autonomous AI agents actually rely on — all on one pre-joined graph.
Built for where the market is going
Connect Whisper once, and every tool in your stack gets sharper.