Threat-Hunting Sweep
Surface fresh suspicious infrastructure to investigate — no starting point needed.
Free tier — no credit card. Runs up to 3 hops deep; Pro goes to 5.
Dig deeper
Read the how-to
What this workflow does and how it uses the graph, plus the copy-paste recipes it's built from.
Open the documentation →Related flows
All use cases →Threat Investigation
The deep-dive you run when something looks bad and you need the full story. Give it one indicator and it works outward across its whole footprint — the related domains, the real servers behind any CDN, the neighbouring infrastructure — and checks each piece for known abuse. You get one coherent read on how dangerous it is and why, with safe next steps to pivot on. Reach for it when a quick check says 'look closer.'
Neighborhood Threat Scan
Guilt by association, made visible. Point it at a domain or address and it looks at everything living nearby — other sites on the same server, flagged neighbours in the same network block, and the related infrastructure an attacker tends to reuse. You learn whether your target sits in a clean neighbourhood or a bad one, and get the leads to pivot into the wider campaign around it.