Compare,with the sources.

79 endpoint capabilities, three tables, and every cell cites the vendor’s own documentation and the date it was read.

Infrastructure and threat intelligence.

Infrastructure and threat-intelligence tools compared by the layers each one covers
ToolHistorical DNS resolutionsWHOIS historySSL / CTBGP routingRPKI / MOASPhysical infraActors / ATT&CKHow you query itCollectionCommercial use
Whisper Intelligence✓✓✓✓✓✓✓
Passive DNS, WHOIS & domain intelligence
DomainTools✓Farsight DNSDB✓20+ yrs✓–––~Guided pivots and IrisQL (Iris)MixedNot published — public WHOIS lookup is CAPTCHA-gated
Recorded Future✓✓since 2008, via SecurityTrails✓–––✓+ Insikt GroupNL / cards + SecurityTrails APIMixedNot published
Silent Push✓✓✓–––~SPQL · API-onlyActiveCommunity Edition available, feature-limited
Validin✓✓✓–––~framework mappings, not named ATT&CKVQL (filter)MixedCommunity access available, feature-limited
WhoisXML API~✓✓––––REST APIs (32 endpoints)PassiveTrial credits only; no ongoing free access
Spur.us–––asn–––—MixedNo free Context API access — Monocle is the free product
Attack-surface management (active scanning)
Censys~31+ days, not on Free~✓–––~labelsCenQL (Platform product)ActiveCensys Free available, credit-limited
Shodan~history param on /dns/domain–✓asn–––FiltersActiveNot published
Cortex Xpanse––✓––––—ActiveNot published
MS Defender EASM–~registrar + contacts as inventory filters, no history✓––––—ActiveTrial available
Microsoft Threat Intelligence (Defender XDR / Sentinel)✓PassiveTotal heritage✓✓–––✓named actors—MixedIncluded with a Defender XDR or Sentinel licence
Threat-intel link-analysis & aggregation
Maltegoviaviavia–––viaTransformsMixedCommunity Edition available
VirusTotal✓✓✓asn––~needs GTI EnterpriseVT Intelligence searchMixedFree API access, non-commercial use only
Pulsedive~✓✓asn––✓Explore (boolean search)MixedFree access, feature-limited
Team Cymru (Pure Signal Recon)✓✓✓✓NetFlow + ASN––~behavioural tagsScout QLPassiveNot published
ThreatConnectviaviavia–––✓TQLPassiveNot published
OpenCTIWhisper ships an OpenCTI connector — an integration, not a competitor. See the integrations page. See integrations
BGP & routing intelligence
bgp.tools–asnprefix–✓✓~IXP; PeeringDB not referenced–—PassiveFree only for a personal, non-commercial ASN
Kentik–––✓✓flow-based ROV–~flagsAI Advisor (conversational)MixedNot published
ThousandEyes–––✓passive via RIPE RIS✓––—MixedNot published
Qrator.Radar–––✓✓ROA + IRR––—PassiveCommunity access available
RIPEstat–✓–✓✓validity––REST callsPassiveNon-commercial use only; redistribution barred by its terms
Cloudflare Radar––~certificate feed✓✓––REST APIPassiveNon-commercial use only under its published licence

Endpoint detection and response.

How to read this: a checkmark means the capability is there, a tilde means it is there with real limits, a dash means that vendor’s own documentation does not describe it, and a dot means the row does not apply. Every mark links to its source and the date it was read, listed at the foot of the table. Filter by category, and on a phone, pick one vendor to compare against Whisper.

Endpoint detection and response products compared capability by capability, sourced
CapabilityWhisper Graph XDRCrowdStrike
Sensor & Telemetry
Single unified agent (EPP+EDR+XDR in one agent)✓✓
Kernel-independent sensor (user-space / eBPF, no loadable kernel module)✓~
Process-execution telemetry (exec + parent-process graph)~✓
File-system telemetry (create/modify/rename/delete)~✓
Network-connection telemetry (outbound connect)✓✓
DNS-query telemetry (observing qname)✓✓
Registry telemetry (Windows)✓✓
Script / command-line telemetry✓✓
Real-time memory / injection visibility~✓
Measured, calm footprint with a published resource SLA✓~
Offline / disconnected protection✓✓
Tamper protection / anti-uninstall~✓
Detection & ATT&CK
Behavioral ransomware detection (T1486 / T1490)✓✓
Dropper / event-chain correlation (write → exec → connect)✓✓
Process injection detection (T1055)~✓
Driver-blocklist / BYOVD (T1068)✓✓
Sigma detection rules✓–
On-device ML prevention~✓
Cloud ML / large behavioral-analytics stack~✓
Local, zero-network known-good hash allowlist✓~
YARA file / memory scanning~~
JA3 / JA4 TLS client fingerprinting~~
ATT&CK technique mapping (on-host tactics)✓✓
Adversary-infrastructure ATT&CK columns (Reconnaissance TA0043 / Resource Development TA0042) from the attacker’s own domains, IPs and certificates✓~
C2-infrastructure and exfil-destination reputation at the resolution plane (acts before the connection is made)✓~
GenAI SOC assistant (natural-language triage and hunting)–✓
Validated low-alert / signal-to-noise posture~✓
Backend, Analytics & Graph
Cross-customer telemetry graph~✓
Internet-scale naming/routing graph (domains, IPv4/6, ASN, RDAP, certs, passive DNS)✓–
Serves the DNS: graph-first policy resolver the fleet points at✓–
Per-endpoint graph, Cypher/graph-queryable✓~
Graph join depth (process → DNS → peer → ASN → actor, across tenants)✓~
Finished threat-intelligence program (adversary tracking, human research)~✓
Hunting query language✓✓
Data retention (default window; storage economics)✓~
Customer-queryable cross-tenant correlation✓~
Network & Identity
Operates authoritative DNS + reverse-DNS (PTR / ip6.arpa) for agent identities✓–
Blocked at DNS resolution✓–
Verifiable per-agent network identity✓–
Per-sub-agent / nested identity (a distinct routable identity per spawned agent)✓–
Directory identity protection–✓
Per-agent egress / source-bound traffic (agent’s own /128)✓–
Per-agent firewall / byte-metering from the network position✓~
Host firewall management (traditional, on-endpoint)~✓
Network Detection & Response (NDR) sensor tier~~
Reverse-DNS / RDAP attribution of every outbound flow to an identity✓–
Response & Containment
Process kill / terminate✓✓
File quarantine✓✓
On-host network isolation~✓
Off-host containment that holds even when the host OS is owned below the agent✓–
DNS default-deny / resolver-plane containment✓–
/128 revocation / kill-switch on the wire✓–
Remote shell / live response–✓
Ransomware file rollback–~
Bounded, safe-by-design response actions (a fixed action set, every one logged)✓~
SOAR / automation✓✓
Managed detection service–✓
Coverage & Platforms
Windows sensor✓✓
macOS sensor~✓
Linux sensor✓✓
Mobile (iOS / Android)–✓
ChromeOS / agentless ingest–✓
Legacy enterprise UNIX (Solaris / AIX / HP-UX)––
Containers / K8s / cloud workloads~✓
Agent/AI-native: routable identity + governance per spawned AI agent✓~
Deployment & Footprint
Cloud SaaS console~✓
Self-hosted control plane✓–
Air-gapped deployment✓–
MSSP / multi-tenant management~✓
Zero-config / one-command onboarding✓✓
Open-source sensor✓–
Published / transparent pricing–~
Independent Validation & Standing
Gartner Magic Quadrant for EPP standing–✓
Forrester Wave XDR standing–✓
MITRE ATT&CK Evaluation entry–✓
SE Labs / AV-Comparatives / AV-TEST certification–✓
Production scale (deployed endpoints)~✓
Corporate / financial stability~✓
Published engineering rigor (mutation-tested code, durability tests run in CI)✓·
Sources (80)
  1. Whisper's cross-platform telemetry collectors (Whisper’s own claim, not independently verified) — read Aug 2026 (footnote 1)
  2. OS matrix Win/macOS/Linux + Falcon for Mobile (iOS/Android) + Falcon Insight for ChromeOS (agentless, Google event ingest, ChromeOS 113+) — read 2026 (footnote 2)
  3. Defender for Identity (SEPARATE product, E5/add-on): sensors on DC/AD FS/AD CS/Entra Connect; behavioral AD/Entra attack detection, not wire identity — read 2026 (footnote 3)
  4. Single agent Win/macOS/Linux/K8s; Linux eBPF no-kernel-module, macOS kextless; on-device behavioral AI => offline protection — read 2026 (footnote 4)
  5. Cortex Data Lake stitches endpoint+network+cloud+identity; XQL hunting; retention '30-day to unlimited' with 30-day floor, longer sold as capacity — read 2026 (footnote 5)
  6. Broad OS: Win/macOS/Linux + legacy enterprise UNIX (Solaris/AIX/HP-UX) for server/workload (Deep Security lineage); containers/VMs/OpenShift — read 2026 (footnote 6)
  7. Whisper's Windows sensor, measured against a reference technique set (Whisper’s own claim, not independently verified) — read Aug 2026 (footnote 7)
  8. Channel File 291 RCA: kernel-mode Windows sensor logic error BSOD'd ~8.5M hosts Jul 19 2024 (evidence a host-resident kernel-coupled agent is itself an availability/attack surface) — read Aug 2024 (footnote 8)
  9. Defender for Endpoint on Linux: eBPF now default event provider (no kernel module); positioned for SERVER workloads, not desktop parity — read May 2026 (footnote 9)
  10. Full Linux EDR/ELF analysis needs a kernel module (or user-space mode on kernel 5.0+); unsupported kernels drop to asynchronous mode; narrowest module set — read 2026 (footnote 10)
  11. On-agent engines: ML/AI, behavior monitoring, host IPS with virtual patching (ZDI-fed vulnerability shielding), DLP, app control, device control, C&C callback blocking, web reputation — read 2026 (footnote 11)
  12. Storyline correlation; kill/quarantine/remediate/rollback/isolate; Network Quarantine (on-host enforced); RemoteOps remote shell + Forensics — read 2026 (footnote 12)
  13. Whisper's macOS sensor, measured against the same set with noted platform limits (Whisper’s own claim, not independently verified) — read Aug 2026 (footnote 13)
  14. Whisper's DNS resolver and control-plane design (Whisper’s own claim, not independently verified) — read Aug 2026 (footnote 14)
  15. Network Protection / Web Content Filtering: HOST-enforced block of malicious URLs/domains/IPs by MS reputation; contain via neighboring onboarded Windows devices; host-enforced isolation — read 2026 (footnote 15)
  16. Firewall Control: manages the native OS HOST firewall (location-aware); not a network/DNS service — read 2026 (footnote 16)
  17. Network Traffic Analysis via Palo Alto NGFW-as-sensor + Cortex broker/Pathfinder feeding analytics (e.g. tunneled-DNS); depends on PAN network stack — read 2026 (footnote 17)
  18. CrowdStrike-reported 100% detection/protection, zero FP in 2025 MITRE ATT&CK Enterprise eval (vendor framing of un-scored MITRE data) — read Dec 10, 2025 (footnote 18)
  19. MS-reported 100% technique-level detection + zero FP, 2024 MITRE Enterprise (first round with macOS; eBPF Linux sensor) - vendor framing of un-scored data — read Dec 11, 2024 (footnote 19)
  20. S1-reported 100% detection (16/16 steps, 80/80 sub-steps), zero delays, 88% fewer alerts than median - 2024 MITRE Enterprise (vendor framing) — read Dec 2024 (footnote 20)
  21. PAN-reported 100% technique-level detection (no config changes, no delays) + 8/10 protection steps blocked with 0 FP - 2024 MITRE ER6 (vendor framing) — read Dec 2024 (footnote 21)
  22. Whisper's own platform overview (Whisper’s own claim, not independently verified) — read Aug 2026 (footnote 22)
  23. Recurring independent reviews: agent can be resource-heavy on low-spec/loaded hosts (esp. during scans); FP-sensitivity historically; steep learning curve — read 2026 (footnote 23)
  24. Reviewer-cited limitations: performance impact, ~600MB installer hard to push to bandwidth-constrained sites, agent-removal difficulty, FPs/alert volume, credit-model confusion — read 2026 (footnote 24)
  25. Sensor arch: Windows kernel driver, Linux user-space eBPF, macOS Endpoint Security framework — read 2024 (footnote 25)
  26. SaaS + Sovereign/Private Cloud / on-premises incl. air-gapped/offline; fullest capability set is cloud-hosted — read 2026 (footnote 26)
  27. Falcon Complete MDR + network containment/isolation, process kill, IOC block, RTR remote shell, USB device control; host-agent-enforced containment — read 2026 (footnote 27)
  28. Anti-tamper: no uninstall without out-of-band approval — read 2026 (footnote 28)
  29. Endpoint isolation (halts all host traffic except to Cortex), process kill, file quarantine, Live Terminal remote shell - agent-enforced on host — read 2026 (footnote 29)
  30. Automated Investigation & Remediation + attack disruption (block lateral movement + remote encryption); no native ransomware file-rollback — read 2023 (footnote 30)
  31. Signature ransomware rollback via VSS snapshots (default 4-hour cadence) - WINDOWS-only — read 2026 (footnote 31)
  32. Remote Shell Session (CLI, 2h cap/10min idle) + Run Remote Custom Script; ransomware rollback (Apex One lineage) — read 2026 (footnote 32)
  33. Trend-reported 100% analytic coverage of major steps, 100% sub-steps macOS/Linux/server, 99% overall - 2024 MITRE ER6; notes HIGHER alert volume (vendor framing) — read Dec 11, 2024 (footnote 33)
  34. Whisper's Sigma detection-rule engine (Whisper’s own claim, not independently verified) — read Aug 2026 (footnote 34)
  35. Advanced Hunting with KQL; 30-day default raw retention; longer needs Microsoft Sentinel (extra product + cost) — read 2026 (footnote 35)
  36. XQL (Cortex Query Language) over xdr_data; XSOAR for automated playbooks — read 2026 (footnote 36)
  37. Whisper's self-run detection evaluation (not a MITRE-run evaluation) (Whisper’s own claim, not independently verified) — read Aug 2026 (footnote 37)
  38. Whisper's local known-good allowlist (Whisper’s own claim, not independently verified) — read Aug 2026 (footnote 38)
  39. Threat Graph: cross-customer graph of SECURITY TELEMETRY; 40+ PB stored, trillions events/day, ~70M req/sec (not an internet naming/routing graph) — read 2024 (footnote 39)
  40. Microsoft Threat Intelligence: 100T+ signals/day (2025), 1,500+ threat groups incl. 600+ nation-state — read 2025 (footnote 40)
  41. Singularity Data Lake: up to 24-month retention, 365 days EDR data OOB (tier/SKU dependent); Deep Visibility + Power Query hunting — read 2026 (footnote 41)
  42. Smart Protection Network: 250M+ sensors, 5T+ threat queries/yr, 15 research centers; product-telemetry reputation feed, NOT an owned internet naming/routing graph — read 2022 (footnote 42)
  43. Whisper's YARA and TLS-fingerprinting engine (Whisper’s own claim, not independently verified) — read Aug 2026 (footnote 43)
  44. Real NDR tier: XDR for Networks via Deep Discovery Inspector / standalone virtual sensors / TippingPoint IPS; inline blocking + lateral-movement + unmanaged/IoT/IIoT visibility — read 2026 (footnote 44)
  45. Whisper's ATT&CK technique coverage, mapped from its infrastructure graph (Whisper’s own claim, not independently verified) — read Aug 2026 (footnote 45)
  46. Counter Adversary Operations: 250+ named adversaries, 2,300+ intel reports/yr, ATT&CK-mapped profiles (finished intel/reporting, not a live resolution control point) — read 2026 (footnote 46)
  47. Can 'restrict network activity / update bad-domain lists' but ONLY through Palo Alto enforcement points (NGFW / DNS Security service) - not a resolver Cortex operates — read 2026 (footnote 47)
  48. Falcon NG-SIEM/LogScale (Humio): CQL query language, ~7-day default retention extendable to 36 months (paid) — read 2026 (footnote 48)
  49. SE Labs 2025 EPS: 100% Total Accuracy, zero false positives; AV-Comparatives EPR 2024/2025 certified — read 2025 (footnote 49)
  50. Whisper's internet-scale naming and routing graph (Whisper’s own claim, not independently verified) — read Aug 2026 (footnote 50)
  51. XDR Data Explorer/OAT default 30 days, extendable to 90/180/365 with a data-retention license; Workbench alerts 180 days — read 2026 (footnote 51)
  52. Whisper's per-agent network-identity design (Whisper’s own claim, not independently verified) — read Aug 2026 (footnote 52)
  53. Falcon Identity Threat Protection / ITDR: AD/Entra/Okta directory identity, real-time credential-abuse detection, automated containment (MFA/password reset) — read 2026 (footnote 53)
  54. Singularity Identity + Ranger AD (ITDR): real-time AD/Entra attack detection + Hologram deception (directory identity) — read 2026 (footnote 54)
  55. ITDR add-on: directory identity analytics (insider/lateral-movement/credential compromise, AD/Azure AD) - not identity-on-the-wire — read 2026 (footnote 55)
  56. Identity telemetry + ASRM (identity posture / account risk), part of zero-trust story - not a routable per-agent wire identity — read Apr 22, 2024 (footnote 56)
  57. Whisper's per-agent egress design (Whisper’s own claim, not independently verified) — read Aug 2026 (footnote 57)
  58. Falcon Firewall Management: central HOST-firewall policy across Win/macOS/Linux via the agent — read 2026 (footnote 58)
  59. Host Firewall module (inbound/outbound rules pushed to agent) + Disk Encryption mgmt + USB Device Control — read 2026 (footnote 59)
  60. Device discovery driven by onboarded WINDOWS devices; NOT supported from macOS/Linux sensors; multi-tenant via M365 Lighthouse (historically weak) — read 2026 (footnote 60)
  61. Ranger / Network Discovery: passive/active fingerprinting of IP devices on the LOCAL network (customer's own networks, not the internet) — read 2026 (footnote 61)
  62. Whisper's on-host and off-host response design (Whisper’s own claim, not independently verified) — read Aug 2026 (footnote 62)
  63. Endpoint isolation (by IP/hostname) + inline NDR/IPS blocking; host-driven or perimeter-sensor-driven containment — read 2026 (footnote 63)
  64. Vision One for Service Providers: multi-tenant single pane, competitive MSSP pricing — read 2026 (footnote 64)
  65. Cloud SaaS + on-prem/self-managed and air-gapped consoles for regulated/isolated environments; strong MSP/MSSP motion — read 2026 (footnote 65)
  66. Third-party analysis of Cortex XDR's list and consumption-based pricing — read 2026 (footnote 66)
  67. Comparison of Microsoft Defender for Endpoint's published per-user plans — read 2026 (footnote 67)
  68. Third-party analysis of CrowdStrike Falcon's published list-price tiers — read 2026 (footnote 68)
  69. Leader, 2024 Gartner MQ for EPP (5th consecutive); highest Ability to Execute, furthest Completeness of Vision — read Sep 25, 2024 (footnote 69)
  70. Leader, Gartner MQ EPP - seventh consecutive year (through 2026) — read May 29, 2026 (footnote 70)
  71. Leader, Gartner MQ EPP - 6th consecutive year (2026 MQ) — read May 26, 2026 (footnote 71)
  72. Leader, Gartner MQ EPP - 4 consecutive years (2023-2026) — read May 29, 2026 (footnote 72)
  73. Leader, Gartner MQ EPP - 20th consecutive time (longest Leader streak of any EPP vendor); highest in 3 Critical Capabilities use cases — read Jul 17, 2025 (footnote 73)
  74. Leader, Forrester Wave XDR Platforms Q2 2024 (highest scores Vision/Innovation/Roadmap); continued Leader Q2 2026 — read Jun 2024 (footnote 74)
  75. Overall Leader, Forrester Wave XDR Platforms Q2 2024; highest Current Offering/Strategy/Market Presence; 15/22 criteria at highest — read Jun 3, 2024 (footnote 75)
  76. Strong Performer (NOT Leader), Forrester Wave XDR Q2 2024 (Leaders were MS/PAN/CRWD) — read Jun 2024 (footnote 76)
  77. Leader, Forrester Wave XDR Platforms Q2 2024 — read Jun 3, 2024 (footnote 77)
  78. Leader, Forrester Wave Network Analysis & Visibility (highest current-offering score of 12); also XDR Wave Leader — read Oct 22, 2025 (footnote 78)
  79. AV-Comparatives EPR 2025: 99% prevention + 99% response; Strategic Leader multiple years — read 2025 (footnote 79)
  80. Whisper's published test suite and mutation-testing results (Whisper’s own claim, not independently verified) — read Aug 2026 (footnote 80)

What changed: this table carried a 16-row subset from 2026-09-20 until it was replaced with the full matrix on 2026-09-21. The source data was last compiled 2026-08-27.

Machine and AI-agent identity.

Machine- and agent-identity products compared capability by capability
CapabilityWhisperIdiraEntra Agent IDCorshaTeleportOktaAembit
The identity itself
Issues an identity to the workload or agent✓✓✓~✓✓~
Attests what the workload is before issuing·✓–~✓–✓
A distinct identity per sub-agent, with its lineage recorded✓~~·–––
Where the decision is enforced
In the network path, not only at the application✓·~✓~·✓
Revocation that holds when the host is compromised✓~~✓✓~~
What it knows about the other end
The destination's owner, network or jurisdiction✓–~––––
Credential operations
Rotates or injects credentials in the systems you already run·✓––~✓✓
AI agents named in the vendor’s own documentation✓✓✓·~✓✓

Last verified 2026-08-27. Each row is re-checked at least quarterly and the build fails when one goes stale. A dash means the capability is not described in that vendor’s own documentation, which is not the same as testing for its absence.

Reselling Whisper? See the MSSP offer.