Faster in WhisperSOC, DFIR & IR

Quick Threat Scan

Paste any domain, IP, or network and instantly see whether it's known-bad and on whose evidence.

Try this in Console

Free tier — no credit card. Runs up to 3 hops deep; Pro goes to 5.

Dig deeper

Read the how-to

What this workflow does and how it uses the graph, plus the copy-paste recipes it's built from.

Open the documentation →

Related flows

All use cases →
Faster in Whisper

Threat Investigation

The deep-dive you run when something looks bad and you need the full story. Give it one indicator and it works outward across its whole footprint — the related domains, the real servers behind any CDN, the neighbouring infrastructure — and checks each piece for known abuse. You get one coherent read on how dangerous it is and why, with safe next steps to pivot on. Reach for it when a quick check says 'look closer.'

Only in Whisper

Indicator Enrichment

Everything worth knowing about one indicator, on a single card. Give it a domain or an address and it fills in the picture: who registered it, where it's hosted and in which country, its mail and name servers, the network behind it, and a reputation read. The fast way to go from a bare indicator to real context before you decide what to do with it.

Only in Whisper

Neighborhood Threat Scan

Guilt by association, made visible. Point it at a domain or address and it looks at everything living nearby — other sites on the same server, flagged neighbours in the same network block, and the related infrastructure an attacker tends to reuse. You learn whether your target sits in a clean neighbourhood or a bad one, and get the leads to pivot into the wider campaign around it.

Only in Whisper

Watchlist Risk Scorecard

Scores an entire portfolio of indicators (brand domains, an IOC batch, a vendor list — domains and/or IPs) in a single pass using whisper.assess, which is LIST-native and coverage-qualified. The result is a ranked scorecard sorted worst-first, a coverage roll-up that buckets hosts into listed / known-clean / no-data, an escalation list (scored-risky plus no-data hosts that must not be assumed clean), and the specific abuse feeds backing each listed hostname and IP. This is the continuous bulk-scoring pattern enterprises run a risk API over a watchlist for, made graph-native.