Skip to content

whisper-sec/whisper-graph

v2.0.0MIT

Investigation playbooks for the WhisperGraph internet-infrastructure graph: indicator triage that reads coverage before it reports a verdict, bulk triage over a SIEM export, Cypher that passes the server's validator, and brand-protection sweeps.

whisper-brand-protection

WhisperGraph brand-protection and takedown playbook — find registered lookalike domains impersonating a brand, work out which ones are actually dangerous, attribute them to a registrant, and assemble evidence a registrar or hosting provider will act on. Use when the user asks about typosquats, lookalike or copycat domains, homoglyph or punycode domains, bitsquatting, domain impersonation, phishing domains targeting their company, brand or domain monitoring, a watchlist of domains an attacker might register, or preparing a takedown, abuse report or evidence package. Separates registered from weaponised so a defensive registration is never reported as an attack, and tells the user what the sweep did not cover. Requires the WhisperGraph MCP connector.

License
MIT
Compatibility
Requires the WhisperGraph MCP connector at https://mcp.whisper.security. No local runtime, packages, or filesystem access needed.
Read SKILL.md at the source

Pinned to revision ee13f53e4d63, so it is the text this page describes rather than whatever the author pushed since.

Files

Every link opens the file at its source, pinned to the revision this page describes.