Compare
Choosing infrastructure intelligence
Passive-DNS, attack-surface, threat-intel and BGP tools each answer one slice of an investigation, and most answer it well. Whisper joins the slices — DNS, BGP, RPKI, WHOIS, GeoIP, threat intel and the physical internet — into one graph you traverse in Cypher or hand to an AI agent over MCP.
What follows is the honest version: where each tool is genuinely strong, and the three things that still hold up only here.
A graph that is already joined
DNS, WHOIS, SSL/CT, BGP, RPKI, GeoIP, threat feeds and the physical internet sit in one graph with the edges already drawn. A single Cypher traversal walks from a hyperlink down to the submarine cable underneath it. Nothing to export, nothing to stitch.
Passive by design
Whisper observes the internet; it never scans the target you are looking at. Most attack-surface tools — Censys, Shodan, Cortex Xpanse, Defender — and a few DNS tools actively probe. Passive collection means your investigation leaves no packets behind.
Routing and physical layers, as data
BGP prefixes, ASNs, MOAS conflicts and RPKI validity, plus the datacenters, IXPs, cables and CDN PoPs beneath them — all queryable, all fused with the DNS and threat layers. This is the one set of layers no other vendor models as queryable data.
The whole field, one grid
Plenty of tools own a column or two. Watch the pattern rather than the cells: one row stays lit the whole way across, because one graph pre-joins every layer. The rest are honest about where they run deep — and in their home column, most run deeper than we do.
Scroll the table sideways to see every layer →
| Vendor | Passive DNS | WHOIS history | SSL / CT | BGP routing | RPKI / MOAS | Physical infra | Actors / ATT&CK | Query model | AI / MCP | Posture | Free entry |
|---|---|---|---|---|---|---|---|---|---|---|---|
| WhisperGraph | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | Cypher · graph | Native MCP | Passive | Anon + free key |
| Passive DNS · WHOIS · domain & infrastructure intelHistorical DNS/WHOIS/SSL observation and pivoting to find related attacker infrastructure. | |||||||||||
| DomainTools | ✓Farsight | ✓20+ yrs | ✓ | – | – | – | ~ | Guided pivots (Iris) | MCP (Mar 2026) | Passive | WHOIS tool only |
| SecurityTrails (RF) | ✓ | ✓since 2008 | ✓ | – | – | – | – | — | llms.txt | Mixed | API key / commercial |
| Silent Push | ✓ | ~building | ✓ | – | – | – | ~ | SPQL · API-only | Copilot partner | Active | Community Edition |
| Validin | ✓ | ✓ | ✓ | – | – | – | ✓ | VQL (filter) | API (no MCP) | Mixed | Community tier |
| WhoisXML API | ~ | ✓ | ✓ | – | – | – | ~feeds | — | — | Passive | Trial credits |
| Spur.us | – | – | – | ASN | – | – | – | — | — | Mixed | Community (250) |
| Attack-surface management · EASM & internet scanningActive scanning of the IPv4/IPv6 space to inventory exposed assets — the opposite of passive collection. | |||||||||||
| Censys | – | ~ | ✓ | – | – | – | ~labels | CenQL | Query Assist + MCP | Active | Community |
| Shodan | – | – | ✓ | ASN | – | – | – | Filters | — | Active | Free (100 results) |
| Cortex Xpanse | – | – | ✓ | – | – | – | – | — | XSOAR | Active | — |
| MS Defender EASM | – | – | ✓ | – | – | – | – | — | Copilot | Active | — |
| MS Defender TI | ✓PassiveTotal | ✓ | ✓ | – | – | – | ✓named actors | — | Copilot | Mixed | Free MDTI tier |
| Threat-intel link-analysis · graph · aggregationCorrelate IOCs, actors and TTPs — often aggregating other vendors’ data rather than collecting their own. | |||||||||||
| Maltego | via | via | via | – | – | – | via | Transforms | — | Mixed | Community Edition |
| Recorded Future | ✓via ST | ✓ | ✓ | – | – | – | ✓+ Insikt | NL / cards | MCP + RF AI | Passive | Express (extension) |
| VirusTotal | ✓ | ✓ | ✓ | ASN | – | – | ✓ | VT Intel search | Community MCP | Passive | Free API (throttled) |
| Pulsedive | ~ | ✓ | ✓ | ASN | – | – | ✓ | Explore (boolean) | — | Active | Strong free tier |
| Team Cymru | ✓ | ✓ | ✓ | ASNNetFlow | – | – | ~tags | Scout QL | MCP (Apr 2026) | Passive | — |
| ThreatConnect | via | via | via | – | – | – | ✓ | TQL | TQL Gen (no MCP) | Passive | Unverified |
| OpenCTI | via | via | via | – | – | – | ✓ | GraphQL | MCP (native, 2026) | Passive | Free (Apache 2.0) |
| BGP / routing intelligence · network observabilityRouting-security and route-monitoring — almost never fused with DNS, WHOIS or threat layers. | |||||||||||
| bgp.tools | – | ASNprefix | – | ✓ | ✓ | ~IXP/PeeringDB | – | — | — | Active | Free (non-comm.) |
| BGPView | – | ASN | – | ✓lookup | – | – | – | — | — | Passive | Shut down Nov 2025 |
| Kentik | – | – | – | ✓ | ✓+ flow ROV | – | ~flags | AI Advisor | AI Advisor | Mixed | — |
| ThousandEyes | – | – | – | ✓ | ✓ | – | – | — | — | Active | — |
| Qrator.Radar | – | – | – | ✓ | ✓ROA+IRR | – | – | — | — | Passive | Community |
| RIPEstat | – | ✓ | – | ✓ | ✓validity | – | – | REST calls | — | Passive | Free (non-comm.) |
✓ modeled as a queryable layer~ partialASN ASN / prefix context onlyvia through federated connectors / transforms– not modeled
Compiled from each vendor’s own documentation and public announcements; last verified June 2026. This market moves fast — MCP servers and query languages shipped across the field in March–April 2026 — so the grid is dated and re-checked each quarter.
A query language is not the same as graph traversal
Most of these ship one — CenQL, SPQL, VQL, TQL, Explore, Scout QL, or GraphQL on OpenCTI. Nearly all are filters or guided pivots over a single vendor’s dataset; you ask “show me rows where…”. Cypher on WhisperGraph is open graph traversal across pre-joined routing, DNS, WHOIS and physical layers — you follow relationships wherever they lead, in one query. That is the part competitors have not shipped.
Common comparison questions
Is WhisperGraph a passive-DNS replacement?
It covers passive DNS — historical resolutions, nameserver and mail delegation — but it is not only passive DNS. Those records sit in the same graph as BGP routing, RPKI, WHOIS, GeoIP, threat feeds and the physical internet, so a lookalike-domain lead can be walked straight through to the ASN that routes it and the datacenter underneath, in one Cypher query rather than one tool per layer.
How is a pre-joined graph different from a query language?
Most tools in this field now ship a query language, but nearly all of them filter one vendor’s single dataset — you ask for rows that match. WhisperGraph joins DNS, routing, WHOIS, certificate, threat and physical-layer data ahead of time, so Cypher traversal follows relationships across all of them at once. The difference is the joins already being drawn, not the syntax you type.
Does Whisper scan the target like an attack-surface tool?
No. Whisper is passive by design: it observes the internet continuously and never probes the specific asset you are investigating. Active attack-surface tools — Censys, Shodan, Cortex Xpanse, Defender EASM — send packets to the target. Passive collection means your investigation leaves no trace on the infrastructure you are looking at.
Stop comparing, start querying
Run a cross-layer query against the live graph anonymously, or connect your AI agent over MCP — free, no credit card.