Network & Routing Report
Profile a network or address block into a full routing and reachability health card.
Free tier — no credit card. Runs up to 3 hops deep; Pro goes to 5.
Dig deeper
Read the how-to
What this workflow does and how it uses the graph, plus the copy-paste recipes it's built from.
Open the documentation →Related flows
All use cases →Anycast DNS-Root Sovereignty
Could a country still resolve names if it were isolated? This assesses a nation's DNS-root resilience — how many of the core root servers have a copy inside its borders, and who operates them — the sovereignty read for national-resilience and policy analysis.
BGP Hijack & Routing-Hygiene Audit
Routing security you can act on. This grades a network on the conflicts and gaps that make route hijacking possible, then traces any conflict to the specific domains and organisations exposed on the affected blocks. An adversarial audit — not just a profile — for finding where a hijack could hurt and who it would hit.
Dependency Blast Radius
Understand the fallout before it happens. Choose any asset and this maps dependencies in both directions: everything that would break if it went down (your single points of failure), and everything it quietly relies on to work (its own supply chain of DNS, mail, hosting, and networks). The resilience view that turns 'what if this fails' into a concrete answer.
Threat Investigation
The deep-dive you run when something looks bad and you need the full story. Give it one indicator and it works outward across its whole footprint — the related domains, the real servers behind any CDN, the neighbouring infrastructure — and checks each piece for known abuse. You get one coherent read on how dangerous it is and why, with safe next steps to pivot on. Reach for it when a quick check says 'look closer.'
Indicator Enrichment
Everything worth knowing about one indicator, on a single card. Give it a domain or an address and it fills in the picture: who registered it, where it's hosted and in which country, its mail and name servers, the network behind it, and a reputation read. The fast way to go from a bare indicator to real context before you decide what to do with it.
Digital Infrastructure Mapping
Follow the infrastructure back to who really runs it. Starting from one indicator, this works out the true operator — even behind privacy registration — de-cloaks CDN-fronted sites to their real servers, and pivots out to the rest of that owner's estate. The mapping view for research, attribution, and understanding who's really on the other end.
Infrastructure Concentration & Resilience
Resilience and compliance in one view. This grades how concentrated an organisation's infrastructure is — too much riding on one provider, one region, one data centre, one cable landing — surfacing the single points of failure that matter for resilience planning and for fourth-party risk rules like DORA and NIS2.
Historical State & Change Tracking
Change is a signal. This tracks how an indicator's ownership and routing shifted across snapshots — registrar changes, routing hand-offs, and the timeline behind them — surfacing the kind of movement that flags a hijack, a transfer, or a quiet change of control.
TLS-Fingerprint Infrastructure Pivot
Attackers change domains and addresses easily — but their servers often share a telltale fingerprint. Starting from one address, this pivots on that fingerprint to every other server sharing it, enriched with network and location, so you can cluster covert command-and-control infrastructure that would otherwise look unrelated.
Tor Exit-Node Exposure
Anonymised traffic changes how you weigh a source. This tells you whether an address is a Tor exit node, and maps a whole network's exit presence by block and country — so you can size how much anonymised egress a given network carries when you're triaging where traffic really came from.