TLS-Fingerprint Infrastructure Pivot
Cluster hidden command-and-control servers by their shared TLS fingerprint.
Free tier — no credit card. Runs up to 3 hops deep; Pro goes to 5.
Dig deeper
Key concepts
Read the how-to
What this workflow does and how it uses the graph, plus the copy-paste recipes it's built from.
Open the documentation →Related flows
All use cases →Threat Investigation
The deep-dive you run when something looks bad and you need the full story. Give it one indicator and it works outward across its whole footprint — the related domains, the real servers behind any CDN, the neighbouring infrastructure — and checks each piece for known abuse. You get one coherent read on how dangerous it is and why, with safe next steps to pivot on. Reach for it when a quick check says 'look closer.'
Digital Infrastructure Mapping
Follow the infrastructure back to who really runs it. Starting from one indicator, this works out the true operator — even behind privacy registration — de-cloaks CDN-fronted sites to their real servers, and pivots out to the rest of that owner's estate. The mapping view for research, attribution, and understanding who's really on the other end.
Neighborhood Threat Scan
Guilt by association, made visible. Point it at a domain or address and it looks at everything living nearby — other sites on the same server, flagged neighbours in the same network block, and the related infrastructure an attacker tends to reuse. You learn whether your target sits in a clean neighbourhood or a bad one, and get the leads to pivot into the wider campaign around it.
Network & Routing Report
The full picture of how a network is put together and reaches the internet. Give it a network or address block and get a health card: what it announces, who it peers and buys transit from, whether it leans dangerously on a single upstream, and how well its routes are protected. The one-look report for network engineers assessing reach and resilience.