Internet infrastructure intelligence
The internet as one graph.
From one bad domainto what feeds miss.
WhisperGraph joins naming, routing, ownership, hosting and threat data into one graph. Built for threat intel, SOCs, security products and AI agents to ask who runs any IP or domain, with evidence.
Pick a question. Watch it cross the graph.
Every question below is one query. Select one to see the layers it crosses, in order, and what comes back.
What comes backthe network that routes it, whether RPKI accepts the route, and the data centres and exchanges that network is in
What comes backthe other domains on the same address, and which feeds list each one, so the unlisted ones stand out
What comes backwho announces the prefix, whether RPKI accepts that origin, any rival announcement, and who stands behind the network
What comes backthe mail providers and networks your suppliers share, and the data centres and exchanges those networks are in
What comes backwhich feeds list it, the address it resolves to, the network that routes it, and the company behind that network
What goes in, and how it stays current.
Every layer below holds its own kind of data, and the table names what stays current and how. Live feeds keep the fastest-moving layers current: threat intelligence, newly observed DNS resolutions, the global routing table and route-origin records reach the graph through the day, so an answer reflects what those sources most recently published.
- Livenew data arrives continuously
- Regularrefreshed on a schedule
- Snapshottaken from periodic snapshots
- Referenceslow-changing records
- Naming & DNSLivehostnames, DNS records, nameservers, DNSSECLive
- Addressing & geographySnapshotIPv4 and IPv6 addresses, address blocks, city, country, cloud regionsSnapshot
- Network & routingLivenetworks, announced routes, BGP paths and peering, RPKI, origin conflictsLive
- Ownership & registrationRegularregistrants, registrars, registries, RDAP recordsRegular
- Email securityRegularMX, SPF, DMARC, DKIMRegular
- Certificates & TLSRegularcertificate transparency names, TLS fingerprintsRegular
- Threat intelligenceLivefeed listings, risk signals, Tor relays, VPN and proxy exitsLive
- Threat actors & ATT&CKReferencenamed actors, ATT&CK techniquesReference
- Physical infrastructureReferencedata centres, internet exchanges, subsea cables, landing stations, CDN points of presenceReference
- Company & technologySnapshotcompanies, subsidiaries, peers and the technology they runSnapshot
Where the graph has never seen an indicator, the answer says no data. It never reads that as clean.
Two ways to ask the same question.
Query the graph directly in Cypher, or connect an agent over the WhisperGraph MCP server and ask in plain English. Either way, the answer carries its evidence.
In Cypher, over the query API
MATCH (h:HOSTNAME {name: $domain})
-[:RESOLVES_TO]->(ip:IPV4)
WITH h, ip LIMIT 1
CALL { WITH ip
MATCH (ip)-[:ANNOUNCED_BY]->(p)
-[:ROUTES]->(a:ASN)
RETURN p, a LIMIT 1 }
CALL { WITH a MATCH (a)-[:HAS_NAME]->(n)
RETURN n LIMIT 1 }
CALL { WITH h
MATCH (h)-[:LISTED_IN]->(f:FEED_SOURCE)
WHERE f.isThreat
RETURN count(f) AS feeds }
RETURN ip.name AS address, p.name AS route,
p.rpkiStatus AS rpki, n.name AS network,
feedsIn plain English, through your agent
Who runs login-verify.example, and does any feed list it?
In this example, Example Hosting Ltd runs the network behind it, and two feeds list it for phishing.
Set it up once
- Take a free key
- Add mcp.whisper.security to your client
- Ask in plain English
The graph counts itself, and dates the count.
Every figure below comes from the graph itself, stamped with the date it answered. Anchored queries return in single-digit milliseconds, server-side.
Measured
Two products run on it. Yours can too.
Whisper Intelligence and Whisper Graph XDR query the same graph your product can, through the query API or the MCP server.
Whisper Intelligence
IOC enrichment in the console or inside Splunk, Sentinel, OpenCTI, MISP and Wazuh: ask the graph about any address and get the evidence attached.
When WHOIS publishes no registrant, follow what is published: the address, the network, the nameservers and the names beside it.
Whisper Graph XDR
Machines and AI agents you enrol get an identity on Whisper's own network. Graph XDR checks what each one may reach against the graph, and you can cut a host off from outside it.
Inside your product
The same graph through one query endpoint and the MCP server, for security products and agents.
One read-only endpoint behind your own product.
Start from the desk you sit at.
Each one has its own page, with the workflows behind it.
Threat intel and SOC
Turn one indicator into the infrastructure behind it, inside your SIEM or the console.
Security vendors
Put infrastructure answers inside your own product.
AI agent builders
Let an agent look up any host's infrastructure over the read-only MCP server, with evidence attached.
Security leaders
See where your vendors actually run, with evidence an auditor can check.
MSSPs and MDRs
Run Graph XDR and Intelligence for your clients.
We run the network we are telling you about.
Whisper operates its own RIPE-allocated autonomous system, AS219419, checkable in the RIPE database.
Our own network
AS219419 is allocated by RIPE and signed with exact-length RPKI ROAs. It announces its prefixes into the same public tables the graph reads, and every claim about it here is checkable in the RIPE database.
An advisory board you can look up
Geoff Huston, Chief Scientist at APNIC; Jeff Osborn, President of ISC; Maarten Botterman, former ICANN board chair; Merike Kaeo, founder of Double Shot Security; and Jonathan Cave, economist and former Turing Fellow.
Founded by the architect of K-root
Kaveh Ranjbar, co-founder and CEO, former CIO of RIPE NCC and the architect of K-root, one of the thirteen root server identities at the top of the DNS.
Questions about WhisperGraph.
Short answers about WhisperGraph and how to try it.
