Skip to content
WhisperGraph
Skip navigation
View as Markdown

WhisperGraph

What the graph contains: every layer of the internet pre-joined into one connected graph, and where to go deeper.

Published Last updated

In this chapter

WhisperGraph Documentation

WhisperGraph models the internet as one connected graph. Naming and DNS, addressing and geography, network and routing, ownership and registration, email security, certificates and TLS, threat intelligence, threat actors, physical infrastructure, company and technology (for accounts with company-data access), and phishing-kit paths each sit as a layer, joined to the next. Anchor on a hostname and one statement walks to its address, the prefix that announces it, the network that routes it, a facility its network is present in, and every feed that lists it.

Which edge carries a query from one layer of the graph into the next?

Planes differ in how much they hold. On a thin one, a zero-row result means Whisper holds no observation of that indicator, never that there is nothing to find.

The chapter map above lists every page here. Start with the Graph Schema if you want the label and edge names, or go straight to Recipes for copy-paste Cypher by job.

A chain that crosses layers needs an API key, passed in the X-API-Key header. Sign in to get one — there is no card to enter.