Skip to content

whisper-sec/whisper-graph

v2.0.0MIT

Investigation playbooks for the WhisperGraph internet-infrastructure graph: indicator triage that reads coverage before it reports a verdict, bulk triage over a SIEM export, Cypher that passes the server's validator, and brand-protection sweeps.

whisper-investigate

WhisperGraph investigation playbook — triage a domain, IP, ASN, CIDR or prefix against an internet-infrastructure graph covering DNS, BGP and RPKI, WHOIS ownership, GeoIP, email (SPF/DMARC/DKIM), certificate transparency, TLS fingerprints, web links and threat feeds. Use when the user asks whether an indicator is malicious or safe, says to investigate or enrich an IOC, asks who owns, hosts, registered or runs something, asks what a domain resolves to or depends on, wants an attack surface or supply chain mapped, wants a subdomain takeover, DNS delegation or BGP hijack check, or wants an investigation written up with evidence. Also use to check WhisperGraph connectivity. Chooses the right server-side workflow instead of hand-rolling queries, and reads the coverage fields so an unseen indicator is never reported as clean. Requires the WhisperGraph MCP connector.

License
MIT
Compatibility
Requires the WhisperGraph MCP connector at https://mcp.whisper.security. No local runtime, packages, or filesystem access needed.
Read SKILL.md at the source

Pinned to revision ee13f53e4d63, so it is the text this page describes rather than whatever the author pushed since.

Files

Every link opens the file at its source, pinned to the revision this page describes.