Use cases
BGP, routing & network security
MOAS detection, RPKI validity, and ASN reputation sit in three separate tools, so a routing anomaly and a threat signal never land on the same row. WhisperGraph joins routing to reputation: one query returns a prefix's origin conflicts, its ROA coverage, and the standing of the networks involved.
A hijack and the network behind it show up together, while there's still time to act.
Why this is hard without a graph
BGP tooling tells you a prefix has two origins; it doesn't tell you whether either is authorized, or whether the announcing AS has a history. RPKI checkers validate routes in isolation. Reputation lives somewhere else entirely. The picture only forms after you've manually crossed all three.
What changes with WhisperGraph
Prefixes, ASNs, ROAs, and threat feeds are all nodes on the same graph. A route-health query reads across them at once — MOAS conflicts cross-checked against RPKI, the announcing networks scored in the same pass. The workflows below turn that into a card you can run on any prefix or ASN.
4 workflows in Network & routing
Each one runs live on the graph — no signup.
BGP Hijack & Routing-Hygiene Audit
Routing security you can act on. This grades a network on the conflicts and gaps that make route hijacking possible, then traces any conflict to the specific domains and organisations exposed on the affected blocks. An adversarial audit — not just a profile — for finding where a hijack could hurt and who it would hit.
Digital Infrastructure Mapping
Map the digital estate an indicator belongs to. Starting from any domain, IP, ASN or prefix, this works out the true owner — even behind privacy WHOIS and CDNs — via the atlas operator, the canonical registrant organization and the registrant email, then enumerates everything that owner owns: the subdomain namespace, the rest of its domain estate, the networks and prefixes that host it, and the facilities it physically sits at. Assets run by someone else (CDN, managed DNS, cloud) are marked as the vendor border, not owned.
Network & Routing Report
The full picture of how a network is put together and reaches the internet. Give it a network or address block and get a health card: what it announces, who it peers and buys transit from, whether it leans dangerously on a single upstream, and how well its routes are protected. The one-look report for network engineers assessing reach and resilience.
Supply-Chain Dependency Mapping
Maps every external provider a domain depends on — nameservers, mail exchangers, third-party email senders (SPF), CDN and hosting networks, registrar and DKIM vendors — by reading each layer of the graph and keeping only providers whose registrable apex differs from the target’s own. Each dependency is grouped by function and the flow flags single-vendor concentration: one DNS operator, one mail provider or one hosting network is a single point of failure whose outage takes the whole function down. The mirror of Digital Infrastructure Mapping: that flow maps what an entity owns, this maps what it depends on.