Recipes
The copy-paste Cypher, by job, that you adapt for your indicator — anchoring and fan-out bounds explained, re-run nightly on the live graph.
In this chapter
- Indicator Triage (SOC)From a raw IP or domain to a reconciled verdict, its feeds, network attribution, co-hosted blast radius, and a paste-ready evidence chain.
- Campaign PivotingTurn one indicator into the whole campaign: co-tenancy, registrant, nameserver, TLS and CT pivots, and the actor/ATT&CK reference layer.
- External ReconPassive recon: paginated subdomain discovery, IP footprint by prefix/ASN/city, owner attribution, CDN de-cloaking, CT and TLS pivots.
- Lookalike HuntingFind typosquats, lookalike domains, fraudulent registrations, credential-theft infrastructure, and phishing kits reused across domains.
- BGP & RPKIDetect MOAS conflicts and RPKI-invalid routes, read a network's hijack and leak posture, follow its AS paths, and map its peering footprint.
- Posture AuditsCypher for DNS and email posture: nameserver/MX inventory with attribution, SPF trees, DKIM signers, DMARC destinations, scorecards.
- Third-Party & Portfolio PostureCypher for reading a vendor from the outside: cyber-insurance risk scoring and auditor-verifiable compliance evidence, end to end.
- Attribution & Law EnforcementPivot from indicators to operators via WHOIS, registrar ties, hosting providers, routing history, Tor identity and dark-web services.
- Internet MeasurementBulk, aggregate Cypher for internet measurement: schema/feed catalogs, peering topology, RPKI coverage, root-server and cross-layer studies.
- Cross-Layer PatternsPatterns that compose attribution, verdicts, blast radius, history and identity into one investigation, plus batch and automation shapes.
- Attack PathsWhat an external attack path is on this graph, which edges compose one, and how to read a shared node as evidence.
- Tracing a PathFollow one alert from a hostname to a choke point you can act on, in five steps, each with a runnable query.
- Exporting at volumewhisper.export pulls the reconciled threat corpus a page at a time, by label, with a cursor — for training a classifier or seeding a store.
- Standing watcheswhisper.watch subscribes to a change in the graph and tells you when it happens — a graph-delta subscription, not a detection.
On this page (1)
Recipes Documentation
Recipes is the copy-paste Cypher you adapt for your own indicator. Workflows is the same investigations, prepared, that you run in the browser without writing any. Each recipe is built from the smaller, atomic query patterns an investigation is made of — a reconciled-verdict lookup, a BGP chain walk, a WHOIS pivot — written against the HTTP API with the anchoring explained. The queries on these pages are re-run against the live graph every night.
Each recipe page groups the patterns for one job. Where a guided workflow runs the same investigation in the browser, the recipe page links straight to it with a "Run it live" callout.
Zero rows is never a verdict. An empty result means the graph holds no observation for that anchor on that layer; it never means the thing is clean. Every recipe that walks a coverage-scoped layer says what its empty result means, and the coverage contract is the rule behind all of them.
If you are new to the graph, run the single example on Getting Started first. Running these against the live graph needs an account — sign in and send your key in the X-API-Key header.
Where next
For the guided, runnable version of these investigations — with a live result already loaded, a Run button, and an Open-in-Console link — see Workflows, organized by the same jobs. Attack Paths and Tracing a Path are two more recipes here, for the shared-infrastructure and choke-point questions the job-based recipes above don't cover on their own.