Workflows
Prepared investigations you run in the browser against the live graph, grouped by job, each with its Cypher visible and a recipe to paste.
Every workflow14 prepared investigations, grouped by the job they do
Threat investigation
Threat Investigation
The deep-dive you run when something looks bad and you need the full story. Give it one indicator and it works outward across its whole footprint — the related domains, the real servers behind any CDN, the neighbouring infrastructure — and checks each piece for known abuse. You get one coherent read on how dangerous it is and why, with safe next steps to pivot on. Reach for it when a quick check says 'look closer.'
- Indicator
Threat Actor Attribution
Reads the threat-attribution layer (actors, MITRE ATT&CK techniques and tactics, threat tags) straight off the graph. From an indicator: its threat tags (a lead) and any direct actor attribution (evidence, via the graph’s ATTRIBUTED_TO edge), the attributed actor’s techniques/tactics, and other indicators sharing a tag. From an actor name or alias: exact-name then alias resolution, similarly-named candidates, the actor’s techniques/tactics, and every indicator this graph directly attributes to them, bounded and threat-checked.
- Indicator or actor name
Attack surface & recon
Attack-Surface Mapper
See your organisation the way an attacker does. Give it a domain and it maps the full external footprint — every subdomain, the name and mail servers, who registered it, the third-party services it leans on, and the wider web of sites it connects to — and scores the exposure. The starting point for shrinking what's reachable from the outside.
- Domain
Subdomain Takeover Detection
A dangling subdomain — one still pointing at a service you've since torn down — is an open door: anyone can re-register that service and speak as you. This walks a domain's subdomains and flags the ones aiming at deprovisioned targets, so you can reclaim or remove them before someone else does.
- Domain
Brand protection
Takedown Evidence Package
When you've found a malicious domain, the next hurdle is proving it. This assembles a one-pass takedown package — the reputation verdict, who owns it, the abuse lists naming it, and the infrastructure around it — laid out ready to hand to a registrar or hosting provider so the takedown actually sticks.
- Domain
Typosquat & Brand-Impersonation Scanner
Someone registering a look-alike of your domain usually isn't doing it for fun. This finds the registered impersonations of a brand — across misspellings and risky extensions — checks whether each is yours or a stranger's, and flags the ones that are freshly registered, hidden behind privacy, or already flagged for abuse. The brand-protection sweep that turns look-alikes into a prioritised list.
- Brand domain
Network & routing
BGP Hijack & Routing-Hygiene Audit
Routing security you can act on. This grades a network on the conflicts and gaps that make route hijacking possible, then traces any conflict to the specific domains and organisations exposed on the affected blocks. An adversarial audit — not just a profile — for finding where a hijack could hurt and who it would hit.
- ASN
Network & Routing Report
The full picture of how a network is put together and reaches the internet. Give it a network or address block and get a health card: what it announces, who it peers and buys transit from, whether it leans dangerously on a single upstream, and how well its routes are protected. The one-look report for network engineers assessing reach and resilience.
- Prefix or ASN
DNS & email security
Indicator Enrichment
Everything worth knowing about one indicator, on a single card. Give it a domain or an address and it fills in the picture: who registered it, where it's hosted and in which country, its mail and name servers, the network behind it, and a reputation read. The fast way to go from a bare indicator to real context before you decide what to do with it.
- Indicator
Nameserver & DNS Delegation Audit
Your name servers decide where your domain points — and a broken or inconsistent setup is a hijacking opportunity. This audits a domain's delegation, flags stale or mismatched name servers, sizes how much each provider actually handles, and surfaces registry facts — so you can catch delegation weakness before it's exploited.
- Domain
Email Security Posture
Reads a domain’s SPF, DKIM, DMARC, MX and DNSSEC records straight off the graph and grades each on presence and hygiene: whether the control is configured, whether the SPF chain stays inside the ten-lookup limit, whether an SPF_IP authorization is unusually wide, whether a DKIM signer has no matching SPF authorization, and whether a mail-exchange address carries a threat verdict. Never grades enforcement strength — SPF’s -all qualifier and DMARC’s p= policy tag are not yet imported into the graph (whisper-dbj-ng#1865).
- Domain
Infrastructure & supply chain
Anycast DNS-Root Sovereignty
Could a country still resolve names if it were isolated? This assesses a nation's DNS-root resilience — how many of the core root servers have a copy inside its borders, and who operates them — the sovereignty read for national-resilience and policy analysis.
- Country code
Digital Infrastructure Mapping
Map the digital estate an indicator belongs to. Starting from any domain, IP, ASN or prefix, this works out the true owner — even behind privacy WHOIS and CDNs — via the atlas operator, the canonical registrant organization and the registrant email, then enumerates everything that owner owns: the subdomain namespace, the rest of its domain estate, the networks and prefixes that host it, and the facilities it physically sits at. Assets run by someone else (CDN, managed DNS, cloud) are marked as the vendor border, not owned.
- Domain, IP, ASN or prefix
Supply-Chain Dependency Mapping
Maps every external provider a domain depends on — nameservers, mail exchangers, third-party email senders (SPF), CDN and hosting networks, registrar and DKIM vendors — by reading each layer of the graph and keeping only providers whose registrable apex differs from the target’s own. Each dependency is grouped by function and the flow flags single-vendor concentration: one DNS operator, one mail provider or one hosting network is a single point of failure whose outage takes the whole function down. The mirror of Digital Infrastructure Mapping: that flow maps what an entity owns, this maps what it depends on.
- Domain
On this page (7)
Workflows Documentation
A workflow is a prepared investigation: one question, a fixed sequence of steps, and a real Cypher query behind each step, executed against the live graph. You supply the seed — a domain, an IP, an ASN, a prefix, a country code — and read the result.
Which workflows exist is the registry's decision, not this page's, so the cards above are the current set. The headings below say what each job is for.
How to run one
A workflow page opens with a result already on it, and every step shows the Cypher it executes, editable in place: change the seed and re-run. Running against the live graph needs an account — Getting Started covers signing in. To write the queries yourself, each workflow links its Recipes sibling; an agent reaches the same set over MCP through the Workflow gallery.
Threat Investigation
Triage in one query instead of half a dozen consoles: the verdict, the network that routes the asset, the feeds that list it (134 feeds across 32 categories), and everything co-hosted beside it. By hand: Indicator Triage.
Read
coveragebeforeband. Only known-clean — coverage: known-clean. In coverage, no malicious evidence. licenses the word "clean"; no-data — coverage: no-data. Not in coverage. This is not a verdict — nothing was looked at. means unknown, which is a different thing again; malicious-evidenced — coverage: malicious-evidenced. In coverage, with positive evidence of malice. and ambiguous — coverage: ambiguous. In coverage, and the evidence points both ways. mean there is evidence, whatever the band says. Full contract: Coverage — what we looked at.
Attack Surface & Recon
An org's external footprint, read out of the index of public DNS, BGP, WHOIS, Certificate Transparency and TLS-fingerprint data: no lookup hits their nameservers and no port is scanned. The Cypher is on External Recon.
Brand Protection
Telling a parked typosquat from one wired into live phishing infrastructure: generate the lookalikes, resolve the registered ones, read the threat verdict off their hosting. Lookalike Hunting has the queries.
Network & Routing
Live announcements, BGP adjacency, MOAS conflicts, RPKI ROAs and threat verdicts on one graph, out to the buildings and cable landings the network sits in. See BGP & RPKI.
DNS & Email Security
SPF, DMARC, DNSSEC and mail routing crossed with the live infrastructure behind the records, so a valid SPF include that authorises infrastructure you would not trust reads as a risk. Posture Audits has the queries.
Infrastructure & Supply Chain
From a vendor domain out to the datacenters, exchanges and submarine cables under it, and the concentration no questionnaire surfaces: two critical vendors in one facility or on one cable. The Cypher is on Third-Party & Portfolio Posture and Cross-Layer Patterns.