Only in WhisperThreat intelligence

Neighborhood Threat Scan

See whether the infrastructure surrounding a target is toxic — bad neighbours, shared servers, and campaign siblings.

Try this in Console

Free tier — no credit card. Runs up to 3 hops deep; Pro goes to 5.

Dig deeper

Read the how-to

What this workflow does and how it uses the graph, plus the copy-paste recipes it's built from.

Open the documentation →

Related flows

All use cases →
Only in Whisper

Threat-Actor & TTP Attribution

Connect the behaviour to the name. This maps a named threat actor to the techniques it's known for, then pivots to other actors who share that same tradecraft — and, from a set of observed techniques, narrows down who's most likely responsible. The attribution view for turning 'how they operate' into 'who they are.'

Faster in Whisper

Takedown Evidence Package

When you've found a malicious domain, the next hurdle is proving it. This assembles a one-pass takedown package — the reputation verdict, who owns it, the abuse lists naming it, and the infrastructure around it — laid out ready to hand to a registrar or hosting provider so the takedown actually sticks.

Faster in Whisper

Threat Investigation

The deep-dive you run when something looks bad and you need the full story. Give it one indicator and it works outward across its whole footprint — the related domains, the real servers behind any CDN, the neighbouring infrastructure — and checks each piece for known abuse. You get one coherent read on how dangerous it is and why, with safe next steps to pivot on. Reach for it when a quick check says 'look closer.'

Faster in Whisper

Quick Threat Scan

Your everyday first check. Drop in any indicator and get a fast, honest read: is this known-bad, how bad, and who says so. You see the reputation call, the abuse lists that name it, and what the target actually is — so a well-known service reads as recognised rather than just unlisted, and 'nothing found' never gets mistaken for 'safe.' Built for the check you run dozens of times a day before deciding whether anything deserves a deeper look.

Only in Whisper

Sanctions & Counterparty Due Diligence

Know who you're dealing with before you deal with them. This screens a domain, address, or network against sanctions lists and assesses the counterparty's hosting, true owner, jurisdiction, and reputation — the external due-diligence pass for compliance teams, crypto-AML checks, and vetting an acquisition or an exchange before you transact.

Only in Whisper

Threat-Hunting Sweep

A hunt with no seed. Instead of starting from an indicator you already have, this surfaces suspicious infrastructure the data itself flags — crowded phishing hubs, shared servers with bad tenants, and look-alike hosting clusters — handing you fresh leads to chase. For the hunter who wants to find what nobody's reported yet.

Only in Whisper

TLS-Fingerprint Infrastructure Pivot

Attackers change domains and addresses easily — but their servers often share a telltale fingerprint. Starting from one address, this pivots on that fingerprint to every other server sharing it, enriched with network and location, so you can cluster covert command-and-control infrastructure that would otherwise look unrelated.

Only in Whisper

Typosquat & Brand-Impersonation Scanner

Someone registering a look-alike of your domain usually isn't doing it for fun. This finds the registered impersonations of a brand — across misspellings and risky extensions — checks whether each is yours or a stranger's, and flags the ones that are freshly registered, hidden behind privacy, or already flagged for abuse. The brand-protection sweep that turns look-alikes into a prioritised list.