Use casesThreat investigation
Only in WhisperSOC, DFIR & IR

Attack Path Analysis

From one foothold, the structure an attacker would lean on. The run finds the DNS and registrant choke points whose compromise reaches the furthest, the pivots that cluster its infrastructure even after IPs rotate (a shared registrant email, a shared TLS fingerprint), whether it is provably linked to a second asset, and how close it already sits to known-bad.

LayersDNSWHOISTLSBGPthreat-intel
0/ 100Clean
Verdict
  • 2 threat-listed domain(s) on the foothold's IPs — near known-bad
  • Provably linked to the second asset via shared registrant (hostmaster@ebay.com, hostmaster@paypal.com, service@sintl-paypal.com)
  • Shares 3 IP(s) with the second asset
  • Shares nameserver(s) with the second asset
  • DNS choke point pdns100.ultradns.com carries 581 dependent domain(s)

40 nodes · 50 edges

  • DNS choke point: pdns100.ultradns.com serves 581 domain(s) — its compromise severs DNS for all of themDNS
  • Registrant pivot: 1,000 domain(s) share hostmaster@ebay.com — a pivot that survives IP/NS churnWHOIS
  • Hidden link confirmed — the foothold is provably linked to the second asset via registrant hostmaster@ebay.com, hostmaster@paypal.com, service@sintl-paypal.com; 3 shared IP(s); shared nameserver(s)DNS
  • 2 threat-listed domain(s) are co-tenanted on the foothold's serving IPs — the path to known-bad is shortthreat-intel
DNS choke point4 rows
nameserverdependentssample
pdns100.ultradns.com581paypal.aihellenicbank.apppaypal.com.armcgraw-hill.asiavitaminworld.asiapaypal.at
ns2-pchnet.paypal.com254paypal.aipaypal.com.arpaypal.atpaypal.com.aupaypal-australia.com.aupaypal-business.com.au
ns1-pchnet.paypal.com254paypal.aipaypal.com.arpaypal.atpaypal.com.aupaypal-australia.com.aupaypal-business.com.au
ppdns.paypal.com155paypal.atpaypal.com.aupaypal-education.com.aupaypal-opladen.bepaypal-recharger.bepaypal-topup.be
Registrant estate3 rows
registrant emailestatesample
hostmaster@ebay.com10003pm.aimarktplaats.amsterdamstubhub.amsterdambitbay.appcatch.appdeepcommerce.app+2 more
hostmaster@paypal.com1000venmo.aipayp.asiapypl.asiabill-safe.atbill-save.atbraintree.co.at+2 more
service@sintl-paypal.com56paypalgiftcards.bizpaypalsmartpaymentbuttons.bizpaypalsmartpayments.bizvenmogoods.bizcashify.comloanbuilder.com+2 more
Hidden link1 row
shared ipsshared nameserversshared registrant
151.101.195.1151.101.3.1162.159.141.96ns1-pchnet.paypal.comns2-pchnet.paypal.comppdns.paypal.compdns100.ultradns.comns1.p57.dynect.nethostmaster@ebay.comhostmaster@paypal.comservice@sintl-paypal.com
Direct radius3 rows
ipcotenant countsample
151.101.3.1192paypal.aipaypal.com.arwww.paypal.com.arpaypal.atwww.paypal.atpaypal.com.au+4 more
151.101.195.1113paypal.aiwww.paypal.com.arwww.paypal.atwww.paypal.com.auwww.paypal-australia.com.auwww.paypal-business.com.au+4 more
162.159.141.9684paypal.com.arpaypal.atpaypal.com.aupaypal-australia.com.aupaypal-business.com.aupaypal.be+4 more
Network reach2 rows
asnpeer countfacilitiesfacility sample
AS5411379897NIKHEF AmsterdamCoreSite - San Jose (SV1)CoreSite - Los Angeles (LA1) One WilshireDigital Realty SFO (365 Main)Digital Realty NYC (60 Hudson)
AS1333512211488Equinix SV8 - Silicon Valley, Palo AltoEquinix SV1/SV5/SV10 - Silicon Valley, San JoseEquinix DA1 - DallasEquinix DC1-DC15,DC21-DC22 - AshburnDigital Realty SFO (200 Paul)
Proximity to known-bad2 rows
ipthreat neighborssample
151.101.3.12paypal.nopaypal.com.ve
162.159.141.962paypal.nopaypal.com.ve
The one query behind this
CALL explain($value)

Snapshot from a max-depth run on Jun 26, 2026. Run it again for live data. attack-path

Try this in Console

Free tier — no credit card. Runs up to 3 hops deep; Pro goes to 5.

What it solves

Internal attack-path tools stop at your perimeter. This traces the external structure an adversary would actually use, and the pivots that persist even when the obvious indicators change.

The run finds the DNS and registrant choke points whose compromise reaches furthest, the pivots that keep clustering the infrastructure after IPs rotate (a shared registrant email, a shared TLS fingerprint), whether the asset is provably linked to a second one, and how near it already sits to known-bad.

The old way4 tools / tabs40 min

Reconstruct the external graph by hand, pivot by pivot.

  • passive DNS
  • WHOIS pivoting
  • TLS fingerprinting
  • threat feeds

What this means

  • A choke point with thousands of dependents is the single node whose compromise reaches the furthest. It is the highest-leverage target, and the biggest blind spot.
  • A shared registrant email or TLS fingerprint is a persistent pivot. It links infrastructure even after IPs and nameservers rotate.
  • Threat-listed neighbours on the foothold’s own IPs measure how short the path to known-bad already is — distance to danger, not mere association.

Dig deeper

Read the how-to

The documentation for this flow — the queries explained, with variants you can adapt.

Open the documentation →