Skip to content
Recipes
Skip navigation
View as Markdown

Recipes

The copy-paste Cypher, by job, that you adapt for your indicator — anchoring and fan-out bounds explained, re-run nightly on the live graph.

Published Last updated

In this chapter

On this page (1)

Recipes Documentation

Recipes is the copy-paste Cypher you adapt for your own indicator. Workflows is the same investigations, prepared, that you run in the browser without writing any. Each recipe is built from the smaller, atomic query patterns an investigation is made of — a reconciled-verdict lookup, a BGP chain walk, a WHOIS pivot — written against the HTTP API with the anchoring explained. The queries on these pages are re-run against the live graph every night.

Each recipe page groups the patterns for one job. Where a guided workflow runs the same investigation in the browser, the recipe page links straight to it with a "Run it live" callout.

Zero rows is never a verdict. An empty result means the graph holds no observation for that anchor on that layer; it never means the thing is clean. Every recipe that walks a coverage-scoped layer says what its empty result means, and the coverage contract is the rule behind all of them.

If you are new to the graph, run the single example on Getting Started first. Running these against the live graph needs an account — sign in and send your key in the X-API-Key header.

Where next

For the guided, runnable version of these investigations — with a live result already loaded, a Run button, and an Open-in-Console link — see Workflows, organized by the same jobs. Attack Paths and Tracing a Path are two more recipes here, for the shared-infrastructure and choke-point questions the job-based recipes above don't cover on their own.