Digital Infrastructure Mapping
Trace one indicator to its true owner and full estate, even behind privacy screens and CDNs.
Free tier — no credit card. Runs up to 3 hops deep; Pro goes to 5.
Dig deeper
Read the how-to
What this workflow does and how it uses the graph, plus the copy-paste recipes it's built from.
Open the documentation →Related flows
All use cases →Attack Path & Connection Finder
Think like the adversary. From a starting foothold, this finds the shared dependencies whose compromise would reach the furthest across a target — the pivot points worth defending first. And for any two indicators, it traces how they're actually connected, so you can explain the link behind a hunch.
Attack-Surface Mapper
See your organisation the way an attacker does. Give it a domain and it maps the full external footprint — every subdomain, the name and mail servers, who registered it, the third-party services it leans on, and the wider web of sites it connects to — and scores the exposure. The starting point for shrinking what's reachable from the outside.
Dependency Blast Radius
Understand the fallout before it happens. Choose any asset and this maps dependencies in both directions: everything that would break if it went down (your single points of failure), and everything it quietly relies on to work (its own supply chain of DNS, mail, hosting, and networks). The resilience view that turns 'what if this fails' into a concrete answer.
Threat Investigation
The deep-dive you run when something looks bad and you need the full story. Give it one indicator and it works outward across its whole footprint — the related domains, the real servers behind any CDN, the neighbouring infrastructure — and checks each piece for known abuse. You get one coherent read on how dangerous it is and why, with safe next steps to pivot on. Reach for it when a quick check says 'look closer.'
Infrastructure Concentration & Resilience
Resilience and compliance in one view. This grades how concentrated an organisation's infrastructure is — too much riding on one provider, one region, one data centre, one cable landing — surfacing the single points of failure that matter for resilience planning and for fourth-party risk rules like DORA and NIS2.
Ownership & Registrant Portfolio
One domain is rarely the whole story. Starting from a seed, this pivots on the registration details — the owner's email, organisation, and phone — to surface every other asset the same operator registered, and shows which detail connected each one. The reverse-lookup for mapping an owner's full portfolio, whether it's a brand, an investigation target, or an adversary.
Network & Routing Report
The full picture of how a network is put together and reaches the internet. Give it a network or address block and get a health card: what it announces, who it peers and buys transit from, whether it leans dangerously on a single upstream, and how well its routes are protected. The one-look report for network engineers assessing reach and resilience.
Sanctions & Counterparty Due Diligence
Know who you're dealing with before you deal with them. This screens a domain, address, or network against sanctions lists and assesses the counterparty's hosting, true owner, jurisdiction, and reputation — the external due-diligence pass for compliance teams, crypto-AML checks, and vetting an acquisition or an exchange before you transact.
TLS-Fingerprint Infrastructure Pivot
Attackers change domains and addresses easily — but their servers often share a telltale fingerprint. Starting from one address, this pivots on that fingerprint to every other server sharing it, enriched with network and location, so you can cluster covert command-and-control infrastructure that would otherwise look unrelated.
Tor Exit-Node Exposure
Anonymised traffic changes how you weigh a source. This tells you whether an address is a Tor exit node, and maps a whole network's exit presence by block and country — so you can size how much anonymised egress a given network carries when you're triaging where traffic really came from.