Use casesThreat investigation
Faster in WhisperSOC, DFIR & IR

Indicator Investigation

Paste a domain, IP, ASN or prefix → a sourced threat verdict with evidence, enriched as deep as you choose (owning network, GeoIP, feeds, co-hosts, RPKI, history). Batch-assess a whole list in one pass.

Layersthreat-intelDNSBGPGeoIPRPKIhistorical
0/ 100Clean
Verdict
  • Listed in 0 source(s) with combined weight 0.00
  • Base score: 0.00 × log₂(0 + 1) = 0.00
  • Recency boost: ×1.1 (last seen 2 days ago)
  • Age boost: ×1.02 (on lists for 1 day)
  • Final score: 0.00 × 1.1 × 1.02 = 0.00

26 nodes · 25 edges

  • google.com is listed in 0 threat feed(s). Score 0.0 (No threat detected).whisper.explain
Serving infrastructure25 rows
ipip.isThreatip.threatScoreip.threatLevelip.isTorip.isC2ip.isMalware
142.250.154.100true0.8LOWfalsefalsefalse
142.250.154.139true0.8LOWfalsefalsefalse
142.250.191.14false0falsefalsefalse
142.251.110.100true0.8LOWfalsefalsefalse
142.251.110.102true0.8LOWfalsefalsefalse
142.251.13.100true2.535MEDIUMfalsefalsefalse
+19 more in the full run
TLS / JARM fingerprints1 row
fingerprints
The one query behind this
CALL explain($indicator)

Snapshot from a max-depth run on Jun 26, 2026. Run it again for live data. indicator

Try this in Console

Free tier — no credit card. Runs up to 3 hops deep; Pro goes to 5.

What it solves

Alert triage usually means pasting the same indicator into five tabs and copying scraps back into the ticket. This answers "is it bad, and why" in one pass, so the analyst spends the time deciding instead of gathering.

One run pulls the threat verdict, the network that announces the indicator, where it sits geographically, which feeds flag it, what else is co-hosted with it, and how its registration has changed over time. You decide how deep to go, and you can hand it a whole list to triage at once.

The old way5 tools / tabs15 min

Five lookups per indicator, then stitch the answers together by hand.

  • VirusTotal
  • Shodan
  • whois
  • a BGP looking glass
  • a spreadsheet

Dig deeper

Read the how-to

The documentation for this flow — the queries explained, with variants you can adapt.

Open the documentation →

Related flows

All use cases →
Only in Whisper

Typosquat Scanner

Give it your brand domain and it returns the registered look-alikes, each one checked for who owns it and whether it is wired into anything malicious.

Faster in Whisper

Blast Radius

Pick one piece of infrastructure and see what breaks if it disappears, from the domains it serves to the owner and datacenter behind it.

Only in Whisper

Route-Health Checker

Hand it a prefix or ASN and get a routing-integrity card: MOAS conflicts, RPKI coverage, prefix status, and footprint.

Faster in Whisper

Attack-Surface Mapper

Point it at a domain and get the full external footprint, scored: subdomains, nameservers, mail senders, the origins behind any CDN, and the posture of everything that serves it.

Only in Whisper

Time Machine

Give it an indicator and see exactly what changed between its two most recent WHOIS and BGP snapshots.

Faster in Whisper

Build the takedown evidence package

Assemble a one-pass dossier for a phishing or scam domain: the verdict, the owner, every feed that flags it, and the infrastructure around it.

Only in Whisper

Threat-hunting candidate sweep

A corpus-level hunt with no seed required: surface the apexes and IPs the graph itself already flags.

Only in Whisper

Actor → shared TTPs → other actors

From a named threat actor, list its ATT&CK techniques, then pivot through them to every other actor that shares the same tradecraft.

Only in Whisper

Find the real infrastructure behind the CDN

One passive call reconstructs the likely true origin IPs behind a CDN, with a confidence score for each candidate.

Only in Whisper

Ground your AI agent before it acts

A coverage-qualified read that tells 'known clean' apart from 'no data', the grounding primitive for MCP-native SOCs.

Only in Whisper

Enrich an ASN — routing, RPKI & physical footprint

One ASN in, and you get its announced prefixes, RPKI coverage, BGP peers, and the facilities and exchanges where it physically sits.

Only in Whisper

Attack Path Analysis

From one foothold, the structure an attacker would lean on: the choke points, the pivots that survive IP rotation, and how close it sits to known-bad.