Use cases
Threat investigation & SOC
Triage an indicator and the work is the same every time: gather context from ten consoles before you can decide whether the alert matters. WhisperGraph puts that context on one pre-joined graph, so a single traversal returns the verdict, the network that owns the asset, where it sits, every feed that lists it, and everything co-hosted beside it.
From there you keep pivoting on the same graph — out from one indicator to the adversary infrastructure around it, then along the blast radius a compromise can reach — without ever leaving for another tool.
Why this is hard without a graph
DNS, WHOIS, hosting, routing, and threat intel were never built to join. Analysts swivel-chair between them by hand, copying an IP from one tab into the next, and the relationships that matter — shared registrant, shared /24, shared upstream — only appear if someone thinks to look. The clock is running the whole time.
What changes with WhisperGraph
Because every layer is already linked, the pivot that took five tools is one query. You start from an IOC and the campaign around it surfaces in the same result — siblings on the same prefix, the announcing ASN, the feeds that flag them. Each workflow below runs live on the graph, no signup, so you can see the answer before you commit to it.
15 workflows in Threat investigation
Each one runs live on the graph — no signup.
Threat-Actor & TTP Attribution
Connect the behaviour to the name. This maps a named threat actor to the techniques it's known for, then pivots to other actors who share that same tradecraft — and, from a set of observed techniques, narrows down who's most likely responsible. The attribution view for turning 'how they operate' into 'who they are.'
Attack Path & Connection Finder
Think like the adversary. From a starting foothold, this finds the shared dependencies whose compromise would reach the furthest across a target — the pivot points worth defending first. And for any two indicators, it traces how they're actually connected, so you can explain the link behind a hunch.
Attack-Surface Mapper
See your organisation the way an attacker does. Give it a domain and it maps the full external footprint — every subdomain, the name and mail servers, who registered it, the third-party services it leans on, and the wider web of sites it connects to — and scores the exposure. The starting point for shrinking what's reachable from the outside.
BGP Hijack & Routing-Hygiene Audit
Routing security you can act on. This grades a network on the conflicts and gaps that make route hijacking possible, then traces any conflict to the specific domains and organisations exposed on the affected blocks. An adversarial audit — not just a profile — for finding where a hijack could hurt and who it would hit.
Takedown Evidence Package
When you've found a malicious domain, the next hurdle is proving it. This assembles a one-pass takedown package — the reputation verdict, who owns it, the abuse lists naming it, and the infrastructure around it — laid out ready to hand to a registrar or hosting provider so the takedown actually sticks.
Certificate Transparency Asset Discovery
Every HTTPS certificate is logged publicly — and that log is a goldmine for finding assets you forgot you had. This surfaces a domain's certificates (wildcards included), when they first and last appeared, and the sibling hostnames issued alongside them. A clean way to uncover shadow assets and expansion no inventory captured.
Threat Investigation
The deep-dive you run when something looks bad and you need the full story. Give it one indicator and it works outward across its whole footprint — the related domains, the real servers behind any CDN, the neighbouring infrastructure — and checks each piece for known abuse. You get one coherent read on how dangerous it is and why, with safe next steps to pivot on. Reach for it when a quick check says 'look closer.'
Nameserver & DNS Delegation Audit
Your name servers decide where your domain points — and a broken or inconsistent setup is a hijacking opportunity. This audits a domain's delegation, flags stale or mismatched name servers, sizes how much each provider actually handles, and surfaces registry facts — so you can catch delegation weakness before it's exploited.
Neighborhood Threat Scan
Guilt by association, made visible. Point it at a domain or address and it looks at everything living nearby — other sites on the same server, flagged neighbours in the same network block, and the related infrastructure an attacker tends to reuse. You learn whether your target sits in a clean neighbourhood or a bad one, and get the leads to pivot into the wider campaign around it.
Quick Threat Scan
Your everyday first check. Drop in any indicator and get a fast, honest read: is this known-bad, how bad, and who says so. You see the reputation call, the abuse lists that name it, and what the target actually is — so a well-known service reads as recognised rather than just unlisted, and 'nothing found' never gets mistaken for 'safe.' Built for the check you run dozens of times a day before deciding whether anything deserves a deeper look.
Sanctions & Counterparty Due Diligence
Know who you're dealing with before you deal with them. This screens a domain, address, or network against sanctions lists and assesses the counterparty's hosting, true owner, jurisdiction, and reputation — the external due-diligence pass for compliance teams, crypto-AML checks, and vetting an acquisition or an exchange before you transact.
Subdomain Takeover Detection
A dangling subdomain — one still pointing at a service you've since torn down — is an open door: anyone can re-register that service and speak as you. This walks a domain's subdomains and flags the ones aiming at deprovisioned targets, so you can reclaim or remove them before someone else does.
Threat-Hunting Sweep
A hunt with no seed. Instead of starting from an indicator you already have, this surfaces suspicious infrastructure the data itself flags — crowded phishing hubs, shared servers with bad tenants, and look-alike hosting clusters — handing you fresh leads to chase. For the hunter who wants to find what nobody's reported yet.
Historical State & Change Tracking
Change is a signal. This tracks how an indicator's ownership and routing shifted across snapshots — registrar changes, routing hand-offs, and the timeline behind them — surfacing the kind of movement that flags a hijack, a transfer, or a quiet change of control.
Typosquat & Brand-Impersonation Scanner
Someone registering a look-alike of your domain usually isn't doing it for fun. This finds the registered impersonations of a brand — across misspellings and risky extensions — checks whether each is yours or a stranger's, and flags the ones that are freshly registered, hidden behind privacy, or already flagged for abuse. The brand-protection sweep that turns look-alikes into a prioritised list.