Skip to content
Workflows
Skip navigation
View as Markdown

Workflows

Prepared investigations you run in the browser against the live graph, grouped by job, each with its Cypher visible and a recipe to paste.

Published Last updated

Every workflow14 prepared investigations, grouped by the job they do

Threat investigation

Faster in Whisper

Threat Investigation

The deep-dive you run when something looks bad and you need the full story. Give it one indicator and it works outward across its whole footprint — the related domains, the real servers behind any CDN, the neighbouring infrastructure — and checks each piece for known abuse. You get one coherent read on how dangerous it is and why, with safe next steps to pivot on. Reach for it when a quick check says 'look closer.'

  • Indicator
SOC, DFIR & IRRun it
Only in Whisper

Threat Actor Attribution

Reads the threat-attribution layer (actors, MITRE ATT&CK techniques and tactics, threat tags) straight off the graph. From an indicator: its threat tags (a lead) and any direct actor attribution (evidence, via the graph’s ATTRIBUTED_TO edge), the attributed actor’s techniques/tactics, and other indicators sharing a tag. From an actor name or alias: exact-name then alias resolution, similarly-named candidates, the actor’s techniques/tactics, and every indicator this graph directly attributes to them, bounded and threat-checked.

  • Indicator or actor name
Threat intelligenceRun it

Attack surface & recon

Faster in Whisper

Attack-Surface Mapper

See your organisation the way an attacker does. Give it a domain and it maps the full external footprint — every subdomain, the name and mail servers, who registered it, the third-party services it leans on, and the wider web of sites it connects to — and scores the exposure. The starting point for shrinking what's reachable from the outside.

  • Domain
Attack surface & reconRun it
Only in Whisper

Subdomain Takeover Detection

A dangling subdomain — one still pointing at a service you've since torn down — is an open door: anyone can re-register that service and speak as you. This walks a domain's subdomains and flags the ones aiming at deprovisioned targets, so you can reclaim or remove them before someone else does.

  • Domain
Attack surface & reconRun it

Brand protection

Faster in Whisper

Takedown Evidence Package

When you've found a malicious domain, the next hurdle is proving it. This assembles a one-pass takedown package — the reputation verdict, who owns it, the abuse lists naming it, and the infrastructure around it — laid out ready to hand to a registrar or hosting provider so the takedown actually sticks.

  • Domain
Brand protectionRun it
Only in Whisper

Typosquat & Brand-Impersonation Scanner

Someone registering a look-alike of your domain usually isn't doing it for fun. This finds the registered impersonations of a brand — across misspellings and risky extensions — checks whether each is yours or a stranger's, and flags the ones that are freshly registered, hidden behind privacy, or already flagged for abuse. The brand-protection sweep that turns look-alikes into a prioritised list.

  • Brand domain
Brand protectionRun it

Network & routing

Only in Whisper

BGP Hijack & Routing-Hygiene Audit

Routing security you can act on. This grades a network on the conflicts and gaps that make route hijacking possible, then traces any conflict to the specific domains and organisations exposed on the affected blocks. An adversarial audit — not just a profile — for finding where a hijack could hurt and who it would hit.

  • ASN
Network & BGPRun it
Only in Whisper

Network & Routing Report

The full picture of how a network is put together and reaches the internet. Give it a network or address block and get a health card: what it announces, who it peers and buys transit from, whether it leans dangerously on a single upstream, and how well its routes are protected. The one-look report for network engineers assessing reach and resilience.

  • Prefix or ASN
Network & BGPRun it

DNS & email security

Only in Whisper

Indicator Enrichment

Everything worth knowing about one indicator, on a single card. Give it a domain or an address and it fills in the picture: who registered it, where it's hosted and in which country, its mail and name servers, the network behind it, and a reputation read. The fast way to go from a bare indicator to real context before you decide what to do with it.

  • Indicator
DNS & email securityRun it
Only in Whisper

Nameserver & DNS Delegation Audit

Your name servers decide where your domain points — and a broken or inconsistent setup is a hijacking opportunity. This audits a domain's delegation, flags stale or mismatched name servers, sizes how much each provider actually handles, and surfaces registry facts — so you can catch delegation weakness before it's exploited.

  • Domain
DNS & email securityRun it
Only in Whisper

Email Security Posture

Reads a domain’s SPF, DKIM, DMARC, MX and DNSSEC records straight off the graph and grades each on presence and hygiene: whether the control is configured, whether the SPF chain stays inside the ten-lookup limit, whether an SPF_IP authorization is unusually wide, whether a DKIM signer has no matching SPF authorization, and whether a mail-exchange address carries a threat verdict. Never grades enforcement strength — SPF’s -all qualifier and DMARC’s p= policy tag are not yet imported into the graph (whisper-dbj-ng#1865).

  • Domain
DNS & email securityRun it

Infrastructure & supply chain

Only in Whisper

Anycast DNS-Root Sovereignty

Could a country still resolve names if it were isolated? This assesses a nation's DNS-root resilience — how many of the core root servers have a copy inside its borders, and who operates them — the sovereignty read for national-resilience and policy analysis.

  • Country code
Infrastructure, supply-chain & complianceRun it
Only in Whisper

Digital Infrastructure Mapping

Map the digital estate an indicator belongs to. Starting from any domain, IP, ASN or prefix, this works out the true owner — even behind privacy WHOIS and CDNs — via the atlas operator, the canonical registrant organization and the registrant email, then enumerates everything that owner owns: the subdomain namespace, the rest of its domain estate, the networks and prefixes that host it, and the facilities it physically sits at. Assets run by someone else (CDN, managed DNS, cloud) are marked as the vendor border, not owned.

  • Domain, IP, ASN or prefix
Infrastructure, supply-chain & complianceRun it
Only in Whisper

Supply-Chain Dependency Mapping

Maps every external provider a domain depends on — nameservers, mail exchangers, third-party email senders (SPF), CDN and hosting networks, registrar and DKIM vendors — by reading each layer of the graph and keeping only providers whose registrable apex differs from the target’s own. Each dependency is grouped by function and the flow flags single-vendor concentration: one DNS operator, one mail provider or one hosting network is a single point of failure whose outage takes the whole function down. The mirror of Digital Infrastructure Mapping: that flow maps what an entity owns, this maps what it depends on.

  • Domain
Infrastructure, supply-chain & complianceRun it
On this page (7)

Workflows Documentation

A workflow is a prepared investigation: one question, a fixed sequence of steps, and a real Cypher query behind each step, executed against the live graph. You supply the seed — a domain, an IP, an ASN, a prefix, a country code — and read the result.

Which workflows exist is the registry's decision, not this page's, so the cards above are the current set. The headings below say what each job is for.

How to run one

A workflow page opens with a result already on it, and every step shows the Cypher it executes, editable in place: change the seed and re-run. Running against the live graph needs an account — Getting Started covers signing in. To write the queries yourself, each workflow links its Recipes sibling; an agent reaches the same set over MCP through the Workflow gallery.

Which edge does each family of workflows start from?

Threat Investigation

Triage in one query instead of half a dozen consoles: the verdict, the network that routes the asset, the feeds that list it (134 feeds across 32 categories), and everything co-hosted beside it. By hand: Indicator Triage.

Read coverage before band. Only known-clean — coverage: known-clean. In coverage, no malicious evidence. licenses the word "clean"; no-data — coverage: no-data. Not in coverage. This is not a verdict — nothing was looked at. means unknown, which is a different thing again; malicious-evidenced — coverage: malicious-evidenced. In coverage, with positive evidence of malice. and ambiguous — coverage: ambiguous. In coverage, and the evidence points both ways. mean there is evidence, whatever the band says. Full contract: Coverage — what we looked at.

Attack Surface & Recon

An org's external footprint, read out of the index of public DNS, BGP, WHOIS, Certificate Transparency and TLS-fingerprint data: no lookup hits their nameservers and no port is scanned. The Cypher is on External Recon.

Brand Protection

Telling a parked typosquat from one wired into live phishing infrastructure: generate the lookalikes, resolve the registered ones, read the threat verdict off their hosting. Lookalike Hunting has the queries.

Network & Routing

Live announcements, BGP adjacency, MOAS conflicts, RPKI ROAs and threat verdicts on one graph, out to the buildings and cable landings the network sits in. See BGP & RPKI.

DNS & Email Security

SPF, DMARC, DNSSEC and mail routing crossed with the live infrastructure behind the records, so a valid SPF include that authorises infrastructure you would not trust reads as a risk. Posture Audits has the queries.

Infrastructure & Supply Chain

From a vendor domain out to the datacenters, exchanges and submarine cables under it, and the concentration no questionnaire surfaces: two critical vendors in one facility or on one cable. The Cypher is on Third-Party & Portfolio Posture and Cross-Layer Patterns.