Workflows

Prepared investigations you run in the browser against the live graph, grouped by the job they do, each with its Cypher visible and a recipe sibling to paste.

Workflows Documentation

A workflow is a prepared investigation: one question, a fixed sequence of steps, and a real Cypher query behind each step, executed against the live graph while you watch. You supply the seed — a domain, an IP, an ASN, a prefix, a country code — and read the result. You write nothing.

Which workflows exist is not this page's decision: the set comes from the console's workflow registry and renders here, so one added or retired there appears or disappears without an edit to the docs. Each lives at /docs/workflows/<slug>. The groupings below are the jobs they serve, and a workflow serving more than one appears under each.

How to run one

A workflow page loads with a result already on it, so you can read the shape of the answer before you spend an indicator on it. Every step shows the Cypher it executes, and that Cypher is editable: change the seed, re-run the step, or lift the query into your own tooling. An Open-in-Console link carries the run into the console. Running against the live graph needs an account — Getting Started covers signing in and getting a key.

To write the queries yourself, every workflow links its Recipes sibling in a fixed position. An agent reaches the same set over MCP through list_workflows and run_workflow (Workflow gallery).

One indicator fanning out into the campaign, routing, brand, email-posture, physical and adversary pivots on the same pre-joined graph

Threat Investigation

Triage is the same job every time: gather context from half a dozen consoles before you can say whether the alert matters. The graph pre-joins those sources, so one query returns the verdict, the network that routes the asset, the feeds that list it (76 feeds across 31 categories), and everything co-hosted beside it. Every pivot after that stays on the same graph — out to the adversary infrastructure around the indicator through a shared registrant, nameserver or announcing ASN, and on into the blast radius.

Verdicts carry their evidence. explain() returns the score with the factors and the exact feeds behind it, weights and first/last-seen timestamps included. What it does not return is its own coverage; whisper.assess() does, and it is the only surface on which "we have nothing on this host" is distinguishable from "we looked and it is clean".

Read coverage before band. Only known-clean licenses the word "clean"; no-data means unknown, which is a different thing again; malicious-evidenced and ambiguous mean there is evidence, whatever the band says. whisper.explain does not return coverage at all. Full contract: Coverage — what we looked at.

Threat Investigation is the deep dive from one indicator; Subdomain Takeover Detection and the Attack-Surface Mapper are tagged here too, because a footprint is where an investigation goes next. By hand: Indicator Triage, Campaign Pivoting, Attack Paths. The Actor & ATT&CK layer returns technique and tactic rollups, not a name on the infrastructure.

Attack Surface & Recon

De-cloaking an origin behind a CDN or enumerating an org's footprint normally means active scanning, and an active scan leaks your intent and trips defences. This reads Whisper's index of public DNS, BGP, WHOIS, Certificate Transparency and TLS-fingerprint data instead: no lookup hits their nameservers, no port is scanned, nothing lands in their logs. Those sources arrive already joined, which no reverse-IP lookup or subdomain brute-force does on its own, so one query expands a domain into its whole footprint and keeps going where scanners stop — into the hosting diversity that signals shadow IT, and the origin hiding behind a proxy.

Attack-Surface Mapper is the full sweep: subdomains, nameservers, mail and SPF senders, registrant, the SaaS and CNAME supply chain, real origins behind a CDN, serving IPs and their threat posture, scored. Subdomain Takeover Detection flags the dangling CNAMEs pointing at deprovisioned services an attacker could re-register. The Cypher is on External Recon; for an agent that walks the surface itself, Agents & MCP.

Brand Protection

Generating typosquats is easy. Telling a parked squat from one wired into live phishing infrastructure is the hard part, and a lookalike list is noise until you know which entries resolve, where they host, and whether that hosting already appears in phishing feeds. The whole loop runs on one graph: whisper.variants() generates the lookalikes and keeps the registered ones, one traversal resolves them and reads the threat verdict off the hosting, explain() turns a hit into an evidence chain a registrar will act on, and co-hosting, registrant and nameserver pivots expand one confirmed domain into the rest of the kit.

Typosquat & Brand-Impersonation Scanner checks each registered lookalike for ownership — yours or a third party's — and enriches it with a verdict, hosting and registration age, plus a risky-TLD sweep and a check for fresh, privacy-protected registrations. Takedown Evidence Package assembles the dossier a registrar acts on. Lookalike Hunting has the Cypher for the full loop.

Network & Routing

BGP tooling tells you a prefix has two origins. It does not tell you whether either is authorised, or whether the announcing network has a history; RPKI checkers validate routes in isolation, and reputation data lives somewhere else entirely. Live announcements, BGP adjacency, MOAS conflicts, RPKI ROAs and threat verdicts sit on the same graph, so one query returns a prefix's origin conflicts, its ROA coverage, and the standing of every network involved. The physical layer behind the routing table is here too: a profile runs from announced prefixes to BGP peers to the buildings, exchanges and cable landings the network sits in, without leaving the query.

Network & Routing Report turns a prefix or ASN into a health card: conflicts, ROA coverage, announcement status, peers, upstream-transit dependency, physical presence. BGP Hijack & Routing-Hygiene Audit grades the same network on route-origin conflicts and RPKI gaps, flags ROAs nearing expiry or carrying over-permissive maxLength, and names the hostnames and orgs exposed on those prefixes. The queries are on BGP & RPKI; the labels and edges are in the Graph Schema.

DNS & Email Security

SPF, DMARC, DNSSEC and mail routing each live in a different checker, and none of them is crossed with the live infrastructure behind the records. Both layers are on one graph here: SPF mechanisms as typed edges, DMARC reporting recipients, DKIM signing vendors, MX and nameserver delegation, and beside them the resolution, routing, WHOIS and threat-verdict data for every host those records point at. That join changes what an audit can see: a syntactically valid SPF include is still a risk if it authorises infrastructure you would not trust, and a checker that stops at the record cannot tell you so. And because DNS is on the same graph, nameserver drift and lame delegation surface as query results before they become a hijack.

Nameserver & DNS Delegation Audit flags exactly that drift. Indicator Enrichment flattens one domain into a record card: registrar, registrant, nameservers, mail servers, resolved IPs and ASN, threat verdict, SPF includes, CT observations. Posture Audits is the copy-paste companion. Subdomain discovery belongs to Attack Surface & Recon.

Infrastructure & Supply Chain

Third-party risk assessment usually stops at the contract. The layers that decide whether a vendor is actually resilient — which networks announce its prefixes, which facilities those routes pass through, which cable systems carry the traffic — sit in datasets never built to join, let alone to join a sanctions list or a jurisdiction map. Here they are one connected graph, so a single traversal walks from a vendor domain to the datacenters, exchanges and submarine cables under it, and produces the evidence NIS2, DORA and ISO 27001 ask for. Concentration no questionnaire surfaces — two critical vendors in the same facility, or on the same cable — becomes a result you hand to an auditor, and mapping the countries the infrastructure sits in puts jurisdiction review on observed rather than declared hosting.

Supply-Chain Dependency Mapping groups every external provider by function — DNS, mail, email delivery, hosting, physical — with the dependency chains and concentration signals. Digital Infrastructure Mapping attributes an indicator to its true operator and enumerates the estate it owns — where M&A diligence or a sanctions screen starts. Anycast DNS-Root Sovereignty asks whether a country could still resolve names if it were cut off — read the note first.

The root-instance plane is seed-stage, and unjoinable today. DNS_ROOT_INSTANCE holds 1,534 nodes and no edge of any type touches them, measured on production 2026-08-09. You can list the instances; you cannot traverse from a country or an ASN to one, so the steps that do return nothing for a structural reason. A zero-row result here is the shape of the data, not a finding about the country.

Routing-side dependency work sits under Network & Routing; the compliance and underwriting Cypher is on Third-Party & Portfolio Posture, the reusable pivots on Cross-Layer Patterns, and the physical layer itself on WhisperGraph.