Threat Investigation
Investigate one suspicious domain, IP, or network in depth and get back a clear picture of the threat and everything connected to it.
Free tier — no credit card. Runs up to 3 hops deep; Pro goes to 5.
Dig deeper
Read the how-to
What this workflow does and how it uses the graph, plus the copy-paste recipes it's built from.
Open the documentation →Related flows
All use cases →Threat-Actor & TTP Attribution
Connect the behaviour to the name. This maps a named threat actor to the techniques it's known for, then pivots to other actors who share that same tradecraft — and, from a set of observed techniques, narrows down who's most likely responsible. The attribution view for turning 'how they operate' into 'who they are.'
Attack Path & Connection Finder
Think like the adversary. From a starting foothold, this finds the shared dependencies whose compromise would reach the furthest across a target — the pivot points worth defending first. And for any two indicators, it traces how they're actually connected, so you can explain the link behind a hunch.
Attack-Surface Mapper
See your organisation the way an attacker does. Give it a domain and it maps the full external footprint — every subdomain, the name and mail servers, who registered it, the third-party services it leans on, and the wider web of sites it connects to — and scores the exposure. The starting point for shrinking what's reachable from the outside.
Dependency Blast Radius
Understand the fallout before it happens. Choose any asset and this maps dependencies in both directions: everything that would break if it went down (your single points of failure), and everything it quietly relies on to work (its own supply chain of DNS, mail, hosting, and networks). The resilience view that turns 'what if this fails' into a concrete answer.
Takedown Evidence Package
When you've found a malicious domain, the next hurdle is proving it. This assembles a one-pass takedown package — the reputation verdict, who owns it, the abuse lists naming it, and the infrastructure around it — laid out ready to hand to a registrar or hosting provider so the takedown actually sticks.
Indicator Enrichment
Everything worth knowing about one indicator, on a single card. Give it a domain or an address and it fills in the picture: who registered it, where it's hosted and in which country, its mail and name servers, the network behind it, and a reputation read. The fast way to go from a bare indicator to real context before you decide what to do with it.
Digital Infrastructure Mapping
Follow the infrastructure back to who really runs it. Starting from one indicator, this works out the true operator — even behind privacy registration — de-cloaks CDN-fronted sites to their real servers, and pivots out to the rest of that owner's estate. The mapping view for research, attribution, and understanding who's really on the other end.
Neighborhood Threat Scan
Guilt by association, made visible. Point it at a domain or address and it looks at everything living nearby — other sites on the same server, flagged neighbours in the same network block, and the related infrastructure an attacker tends to reuse. You learn whether your target sits in a clean neighbourhood or a bad one, and get the leads to pivot into the wider campaign around it.
Watchlist Risk Scorecard
Scores an entire portfolio of indicators (brand domains, an IOC batch, a vendor list — domains and/or IPs) in a single pass using whisper.assess, which is LIST-native and coverage-qualified. The result is a ranked scorecard sorted worst-first, a coverage roll-up that buckets hosts into listed / known-clean / no-data, an escalation list (scored-risky plus no-data hosts that must not be assumed clean), and the specific abuse feeds backing each listed hostname and IP. This is the continuous bulk-scoring pattern enterprises run a risk API over a watchlist for, made graph-native.
Quick Threat Scan
Your everyday first check. Drop in any indicator and get a fast, honest read: is this known-bad, how bad, and who says so. You see the reputation call, the abuse lists that name it, and what the target actually is — so a well-known service reads as recognised rather than just unlisted, and 'nothing found' never gets mistaken for 'safe.' Built for the check you run dozens of times a day before deciding whether anything deserves a deeper look.
Network & Routing Report
The full picture of how a network is put together and reaches the internet. Give it a network or address block and get a health card: what it announces, who it peers and buys transit from, whether it leans dangerously on a single upstream, and how well its routes are protected. The one-look report for network engineers assessing reach and resilience.
Sanctions & Counterparty Due Diligence
Know who you're dealing with before you deal with them. This screens a domain, address, or network against sanctions lists and assesses the counterparty's hosting, true owner, jurisdiction, and reputation — the external due-diligence pass for compliance teams, crypto-AML checks, and vetting an acquisition or an exchange before you transact.
Threat-Hunting Sweep
A hunt with no seed. Instead of starting from an indicator you already have, this surfaces suspicious infrastructure the data itself flags — crowded phishing hubs, shared servers with bad tenants, and look-alike hosting clusters — handing you fresh leads to chase. For the hunter who wants to find what nobody's reported yet.
Historical State & Change Tracking
Change is a signal. This tracks how an indicator's ownership and routing shifted across snapshots — registrar changes, routing hand-offs, and the timeline behind them — surfacing the kind of movement that flags a hijack, a transfer, or a quiet change of control.
TLS-Fingerprint Infrastructure Pivot
Attackers change domains and addresses easily — but their servers often share a telltale fingerprint. Starting from one address, this pivots on that fingerprint to every other server sharing it, enriched with network and location, so you can cluster covert command-and-control infrastructure that would otherwise look unrelated.
Tor Exit-Node Exposure
Anonymised traffic changes how you weigh a source. This tells you whether an address is a Tor exit node, and maps a whole network's exit presence by block and country — so you can size how much anonymised egress a given network carries when you're triaging where traffic really came from.
Typosquat & Brand-Impersonation Scanner
Someone registering a look-alike of your domain usually isn't doing it for fun. This finds the registered impersonations of a brand — across misspellings and risky extensions — checks whether each is yours or a stranger's, and flags the ones that are freshly registered, hidden behind privacy, or already flagged for abuse. The brand-protection sweep that turns look-alikes into a prioritised list.