Use cases
Threat actor & TTP
Adversary hunters live between two systems that never talk: MITRE technique lists on one side, infrastructure intelligence on the other. WhisperGraph joins them, so you pivot from a named actor or an ATT&CK technique straight into the live hosting, domains, and TLS fingerprints behind it.
Attribution and infrastructure land on the same row, instead of in two reports you reconcile by hand.
Why this is hard without a graph
Knowing an actor's techniques tells you how they operate, not where. Connecting a technique to live hosting means leaving your TTP database, jumping to passive DNS, then to WHOIS, then to a TLS scanner — and hoping the pivot still resolves by the time you get there.
What changes with WhisperGraph
The threat layer is wired into the same graph as DNS, hosting, and certificates. A single traversal walks from an actor or technique to the domains and IPs that carry it, then to the shared fingerprints that betray the next campaign. The workflows below make that walk runnable.
2 workflows in Threat actor & TTP
Each one runs live on the graph — no signup.
Threat-Actor & TTP Attribution
Connect the behaviour to the name. This maps a named threat actor to the techniques it's known for, then pivots to other actors who share that same tradecraft — and, from a set of observed techniques, narrows down who's most likely responsible. The attribution view for turning 'how they operate' into 'who they are.'
Attack Path & Connection Finder
Think like the adversary. From a starting foothold, this finds the shared dependencies whose compromise would reach the furthest across a target — the pivot points worth defending first. And for any two indicators, it traces how they're actually connected, so you can explain the link behind a hunch.