# WhisperGraph

> WhisperGraph joins naming, routing, ownership, email, certificates, threat and physical data into one graph you query in one pass.

*Source: https://www.whisper.security/docs/whisper-graph*

---
WhisperGraph models the internet as one connected graph. Naming and DNS, addressing and geography, network and routing, ownership and registration, email security, certificates and TLS, threat intelligence, threat actors, physical infrastructure, company and technology (for accounts with company-data access), and phishing-kit paths each sit as a layer, joined to the next. Anchor on a hostname and one statement walks to its address, the prefix that announces it, the network that routes it, a facility its network is present in, and every feed that lists it.

![Diagram: the layers of WhisperGraph and the edges that join them. A HOSTNAME RESOLVES_TO an IPV4 in the addressing layer; the IPV4 is ANNOUNCED_BY an ANNOUNCED_PREFIX in the routing layer, which an ASN ROUTES; the ASN is AS_PRESENT_AT a FACILITY in the physical layer. Side branches run from the same walk: the HOSTNAME DMARC_REPORTS_TO a DMARC_RECIPIENT in the email layer, the IPV4 is LISTED_IN a FEED_SOURCE in the threat layer, and the ASN is REGISTERED_BY an ORGANIZATION in the ownership layer. A bottom row joins three more layers: a HOSTNAME is SEEN_IN_CT a CT_OBSERVATION in the certificates layer, an IPV4 is ATTRIBUTED_TO an ACTOR in the threat actors layer, and a HOSTNAME RUNS_TECHNOLOGY of a TECHNOLOGY in the company layer, for accounts with company-data access.](https://whisper.cdn.prismic.io/whisper/yAqmXdcSlnvHSk1G_whisper-graph-layers.svg "Which edge carries a query from one layer of the graph into the next?")

Planes differ in how much they hold. On a thin one, a zero-row result means Whisper holds no observation of that indicator, never that there is nothing to find.

The chapter map above lists every page here. Start with the [Graph Schema](/docs/whisper-graph/schema) if you want the label and edge names, or go straight to [Recipes](/docs/recipes) for copy-paste Cypher by job.

A chain that crosses layers needs an API key, passed in the `X-API-Key` header. [Sign in](https://console.whisper.security/sign-in?redirect_url=https%3A%2F%2Fwww.whisper.security%2Fdocs%2Fwhisper-graph) to get one — there is no card to enter.
