Skip to contentSkip navigation

Changelog

Notable changes to WhisperGraph docs, API, MCP server, and Splunk integration.

On this page (3)

Changelog Documentation

A running log of what's new on the public WhisperGraph — new data layers, query capabilities, and agent tools. Everything listed here is live and reproducible at graph.whisper.security.

Key concepts: Certificate Transparency, RPKI / Route Origin Authorization, MITRE ATT&CK.

June 2026

  • Reconciled threat verdict. Every threat-listed indicator now returns a single, blocking-aware verdict — verdictScore, verdictLevel, and verdictBlocking — alongside the raw feed signals, so triage is one read instead of a judgement call. See Graph Schema → Node properties.
  • TLS fingerprints, Tor-exit identity, and vendor egress. Pivot on JA3/JARM TLS fingerprints, attribute Tor exit relays to the IPs that operate them, and see which cloud or SaaS vendor operates a netblock.
  • Certificate Transparency. Discover subdomains and SANs observed in CT logs.
  • Agent tools for AI Context (MCP). The Indenture set — identify (whose infrastructure a host is), assess (a coverage-qualified verdict), and walk (structural neighborhood) — plus CDN-origin de-cloaking. See the Procedure Reference.

May 2026

  • Physical-infrastructure layer. Data-center facilities, internet exchanges, submarine cables and their landing points, CDN points of presence, and cloud regions — the physical internet, joined to routing.
  • RPKI ROA coverage. Check whether a prefix's origin AS is authorized by a published Route Origin Authorization.
  • Threat-actor → MITRE ATT&CK mapping. Named actors linked to the techniques they use.
  • BGP path & adjacency graph. AS-path observations and a single canonical ASN-to-ASN adjacency edge.
  • Typosquat / lookalike generation. whisper.variants (and the domain_variants agent tool) generate registered lookalikes across 14+ mutation methods.

March 2026

  • RDAP registration data. Registrant entities ingested from regional-registry WHOIS/RDAP.

Counts and capabilities are always live — GET /api/query/stats reports current totals.