Quick Threat Scan
Paste any domain, IP, or network and instantly see whether it's known-bad and on whose evidence.
Free tier — no credit card. Runs up to 3 hops deep; Pro goes to 5.
Dig deeper
Read the how-to
What this workflow does and how it uses the graph, plus the copy-paste recipes it's built from.
Open the documentation →Related flows
All use cases →Threat Investigation
The deep-dive you run when something looks bad and you need the full story. Give it one indicator and it works outward across its whole footprint — the related domains, the real servers behind any CDN, the neighbouring infrastructure — and checks each piece for known abuse. You get one coherent read on how dangerous it is and why, with safe next steps to pivot on. Reach for it when a quick check says 'look closer.'
Indicator Enrichment
Everything worth knowing about one indicator, on a single card. Give it a domain or an address and it fills in the picture: who registered it, where it's hosted and in which country, its mail and name servers, the network behind it, and a reputation read. The fast way to go from a bare indicator to real context before you decide what to do with it.
Neighborhood Threat Scan
Guilt by association, made visible. Point it at a domain or address and it looks at everything living nearby — other sites on the same server, flagged neighbours in the same network block, and the related infrastructure an attacker tends to reuse. You learn whether your target sits in a clean neighbourhood or a bad one, and get the leads to pivot into the wider campaign around it.
Watchlist Risk Scorecard
Scores an entire portfolio of indicators (brand domains, an IOC batch, a vendor list — domains and/or IPs) in a single pass using whisper.assess, which is LIST-native and coverage-qualified. The result is a ranked scorecard sorted worst-first, a coverage roll-up that buckets hosts into listed / known-clean / no-data, an escalation list (scored-risky plus no-data hosts that must not be assumed clean), and the specific abuse feeds backing each listed hostname and IP. This is the continuous bulk-scoring pattern enterprises run a risk API over a watchlist for, made graph-native.