Forty alerts.One of them matters.

The alert arrives with an address and nothing else, and the interesting one looks exactly like the other thirty nine.

console.whisper.security
The console query editor: one Cypher query against WhisperGraph, a hostname resolved to its address, prefix and network, with the answer as rows.

Five tools, one address, no time.

The five things you need to know about that address live in five products that do not know about each other.

So the analyst does the join by hand. Then does it thirty nine more times. The interesting one looks like the boring ones until somebody happens to look closely.

Hunting has the same shape. Take down one phishing domain and nineteen more appear next week, registered together to be burned in sequence. Your blocklist sees them one at a time, as they burn.

What it costs a shift.

Time

Tens of minutes for every indicator that deserves a real look.

Inconsistency

Two analysts, two verdicts, and no audit trail for either.

False positives

Nothing in the stack can clear a host. It can only fail to flag it.

Missed pivots

Related infrastructure never gets looked at, because looking costs too much.

The context arrives with the alert.

One query does the join the analyst used to do by hand.

  1. Enrichment in place

    One search command in Splunk, or a connector in Sentinel or OpenCTI. No new tab for anyone to remember.

    See integrations

  2. One pivot to the cluster

    When it is real, one query returns the shared certificates, co-hosted domains, registrant and neighbours.

  3. Clear it or escalate it

    Known-good allowlists and ownership let you clear a host outright. That is where fewer false positives come from.

A verdict you can check.

Every verdict comes back with its sources, their weights and the sum. Two analysts reach the same answer, and either one can show why.

  • Every layer at once

    Certificate, co-hosting, registrant, nameserver, prefix, network and TLS fingerprint, in one traversal.

  • Attribution past the CDN

    Who really runs the host behind the proxy, and what their network usually hosts.

  • Export where it lives

    STIX 2.1 and MISP out, so the finding lands in the platform you already run.

RDAP registrant0.31BGP origin (RIS)0.27certificate chain0.24passive DNS0.18feed: abuse.ch0.14ASN reputation0.09verdictmalicious 0.91
134
intelligence feeds, joined in one graph
47.2B
data points behind every verdict
<10ms
anchored query, server-side

Measured

The workflows that do this job.

Each one starts from a single indicator and returns its evidence with it.

Hunts a blocklist could not run.

  • Eight seconds against forty five minutes

    Three addresses classified with a full evidence trail in eight seconds. The same three took forty five minutes by hand.

  • Clean on every feed

    Three addresses scored zero on every feed. One network sat behind all three, and one of the addresses answered for tens of thousands of domains.

  • One domain becomes a campaign

    A single phishing domain expanded to nineteen related domains. They went live four to five days later.

  • The pivot no feed had

    One anonymising address led to a cluster of certificates reusing the same issuer and subject on unrelated hosts. None of it was in the commercial feeds already in place.

Bring the indicator that went nowhere.

The best first hunt is the one your tooling closed as inconclusive.