Only in WhisperInfrastructure, supply-chain & compliance

Digital Infrastructure Mapping

Trace one indicator to its true owner and full estate, even behind privacy screens and CDNs.

Try:
Try this in Console

Free tier — no credit card. Runs up to 3 hops deep; Pro goes to 5.

Dig deeper

Read the how-to

What this workflow does and how it uses the graph, plus the copy-paste recipes it's built from.

Open the documentation →

Related flows

All use cases →
Only in Whisper

Attack Path & Connection Finder

Think like the adversary. From a starting foothold, this finds the shared dependencies whose compromise would reach the furthest across a target — the pivot points worth defending first. And for any two indicators, it traces how they're actually connected, so you can explain the link behind a hunch.

Faster in Whisper

Attack-Surface Mapper

See your organisation the way an attacker does. Give it a domain and it maps the full external footprint — every subdomain, the name and mail servers, who registered it, the third-party services it leans on, and the wider web of sites it connects to — and scores the exposure. The starting point for shrinking what's reachable from the outside.

Faster in Whisper

Dependency Blast Radius

Understand the fallout before it happens. Choose any asset and this maps dependencies in both directions: everything that would break if it went down (your single points of failure), and everything it quietly relies on to work (its own supply chain of DNS, mail, hosting, and networks). The resilience view that turns 'what if this fails' into a concrete answer.

Faster in Whisper

Threat Investigation

The deep-dive you run when something looks bad and you need the full story. Give it one indicator and it works outward across its whole footprint — the related domains, the real servers behind any CDN, the neighbouring infrastructure — and checks each piece for known abuse. You get one coherent read on how dangerous it is and why, with safe next steps to pivot on. Reach for it when a quick check says 'look closer.'

Only in Whisper

Infrastructure Concentration & Resilience

Resilience and compliance in one view. This grades how concentrated an organisation's infrastructure is — too much riding on one provider, one region, one data centre, one cable landing — surfacing the single points of failure that matter for resilience planning and for fourth-party risk rules like DORA and NIS2.

Only in Whisper

Ownership & Registrant Portfolio

One domain is rarely the whole story. Starting from a seed, this pivots on the registration details — the owner's email, organisation, and phone — to surface every other asset the same operator registered, and shows which detail connected each one. The reverse-lookup for mapping an owner's full portfolio, whether it's a brand, an investigation target, or an adversary.

Only in Whisper

Network & Routing Report

The full picture of how a network is put together and reaches the internet. Give it a network or address block and get a health card: what it announces, who it peers and buys transit from, whether it leans dangerously on a single upstream, and how well its routes are protected. The one-look report for network engineers assessing reach and resilience.

Only in Whisper

Sanctions & Counterparty Due Diligence

Know who you're dealing with before you deal with them. This screens a domain, address, or network against sanctions lists and assesses the counterparty's hosting, true owner, jurisdiction, and reputation — the external due-diligence pass for compliance teams, crypto-AML checks, and vetting an acquisition or an exchange before you transact.

Only in Whisper

TLS-Fingerprint Infrastructure Pivot

Attackers change domains and addresses easily — but their servers often share a telltale fingerprint. Starting from one address, this pivots on that fingerprint to every other server sharing it, enriched with network and location, so you can cluster covert command-and-control infrastructure that would otherwise look unrelated.

Only in Whisper

Tor Exit-Node Exposure

Anonymised traffic changes how you weigh a source. This tells you whether an address is a Tor exit node, and maps a whole network's exit presence by block and country — so you can size how much anonymised egress a given network carries when you're triaging where traffic really came from.