Whisper Intelligence

A list tells you it is bad.
A graph tells you why.

Whisper Intelligence sits under whichever feed you already buy and answers what a list cannot: who owns this, what else do they own, where is it routed, what changed recently, and what else goes dark when you block it.

console.whisper.security
One question against the graph: a hostname resolved to its address, prefix and operating ASN, with the answer returned as rows

Lists have no edges.

Every intelligence vendor sells the same shape of thing: indicators with a number beside each. The number tells you what somebody else already found.

It cannot tell you about the domain the same registrant bought yesterday, the seventeen thousand names sharing the address, the certificate reused across the campaign, or the network routing all of it that has two peers and a Seychelles registration.

That is not a gap in the data. It is a gap in the shape of it.

Six questions, answered in one query each.

RDAP registrant0.31BGP origin0.27certificate chain0.24passive DNS0.18verdictowner resolved

Who owns this, really

Ownership, network, geography, email posture, certificate history and threat context, with the evidence that produced the verdict.

OPERATORfront: CDN provideroperator: AS204601method: cert and passive DNSevery field above is a queryable graph edge, not a score

Who runs the host

Attribution that survives a CDN. The organisation behind the host, not the proxy in front of it.

host12 co-hosted domains3 sibling prefixesshared certificatesame registrantwhat else does this operator run

What else do they run

One seed expands to the estate: shared certificates, co-hosting, registrant, nameserver, network.

2024-11AS133352025-03AS133352025-07AS204601nowAS204601what changed, and exactly when

What changed

WHOIS and BGP history. A prefix that changed origin five times in fifteen months, or a domain registered fifty days before it was used.

subwatch set+6dno change+13dorigin moved+13ddeliveredyou are told when it changes, not asked to poll

Tell me when it changes

Subscribe to an indicator or a pattern, get a webhook when its label, routing or freshness moves.

27of 1,842 hosts actually reachable and affectednot exposedreachableexploitable

Am I actually exposed

Package inventory mapped to CVEs, so the question is which of your hosts are affected rather than which CVEs exist.

Thirty five procedures in total, reachable from Cypher, REST or MCP. All read only.

We will show you the arithmetic.

A score you cannot audit is a score you cannot defend to a regulator, a customer or a board. Every verdict returns its sources, their weights, and how network containment, neighbourhood density and recency moved the number.

Network reputation works the same way. Threat density, topology, historical behaviour and prefix age, each weighted and shown. Scored from what a network does, not from whether anyone has blocklisted it yet.

RDAP registrant0.31BGP origin (RIS)0.27certificate chain0.24passive DNS0.18feed: abuse.ch0.14ASN reputation0.09verdictmalicious 0.91

Catching infrastructure while it is still being built.

SignalWhat it catches
Toxic neighbourhoodAn address that is clean, in a block that is not
Infrastructure stagingDomains and certificates stood up before they are used
Coordinated campaignClusters moving together across registrant, certificate and hosting
Prefix ageNewly routed space behaving like established space
ASN death spiralA network shedding peers while gaining abuse

Enrichment belongs where the alert already is.

SplunkMicrosoft SentinelOpenCTIWazuhClaudeOpenAICursor
See all integrations

Bring the indicator
your stack got wrong.