Whisper icon

Whisper

Whisper is an infrastructure intelligence platform that helps security teams investigate IPs, domains, ASNs, and related infrastructure from a live graph. It supports direct API access, native integrations, and MCP connections for AI agents.

Whisper

What Whisper is

Whisper is an infrastructure intelligence platform for security teams. It maps internet infrastructure data into a live knowledge graph so users can query relationships between IPs, domains, ASNs, routing paths, ownership, and reputation from one place.

The product is designed to support threat detection, alert enrichment, and investigations. Users can access the graph directly through an API, connect existing tools with native integrations, or give AI agents access through MCP for plain-language investigation workflows.

Core capabilities

AI Context over MCP

Connect an AI assistant to Whisper through MCP so questions about IPs, domains, ASNs, and threat intel are answered from the live infrastructure graph instead of model memory.

Direct graph queries

Query the underlying graph directly with Cypher for infrastructure intelligence, including DNS, BGP, WHOIS, GeoIP, web links, and threat feeds.

Native integrations

Use native connectors to feed Whisper context into existing security platforms, rather than forcing analysts to work in a separate interface.

Unified infrastructure graph

Pull together ownership, routing, hosting, and historical changes in one place so analysts can pivot from a single indicator to related infrastructure.

Evidence-backed results

Use explainability tools to surface the evidence chain behind an assessment, including feed sources and timestamps.

Common workflows

  • Instant alert enrichment

    Enrich an alert by checking ownership, hosting, ASN history, and recent infrastructure changes before an analyst opens the ticket.

  • Adversary infrastructure mapping

    Start from one suspicious domain or IP and pivot through shared nameservers, registrants, routing, and hosting patterns to map related infrastructure.

  • External attack surface mapping

    Use the graph to examine domains, subdomains, IPs, and ASNs tied to an organization so security teams can find forgotten or shadow assets.

  • AI-assisted investigation reports

    Run an AI-assisted investigation where the agent asks Whisper for live context and produces a report with ownership, hosting, risk scoring, and historical changes.

  • Typosquat and brand protection checks

    Generate lookalike domains, check which are registered, and identify the ones already associated with phishing or other suspicious activity.

Pros and Cons

Pros

  • Combines routing, DNS, WHOIS, hosting, GeoIP, and threat intelligence in a single graph.
  • Supports three access patterns: API, native connectors, and MCP for AI agents.
  • Returns live, sourced answers with explainability data and evidence chains.
  • Offers deployment options including cloud-hosted, dedicated cloud, and on-prem for enterprise use.
  • Includes read-only agent access, which keeps AI-assisted investigations constrained to query and read operations.

Cons

  • The source pages do not list the full set of native connector products or every supported platform in detail.
  • Historical DNS is marked as coming soon on the pricing page, so not every historical capability is available in all plans today.

FAQ

Does AI Context only work with Claude?

No. The AI Context product page says Whisper works with any MCP-compatible client, including Claude Desktop, ChatGPT, Cursor, VS Code, Windsurf, and others.

Can the agent change the data it reads?

Whisper describes the graph as read-only for connected agents. The agent can query and read infrastructure data, but it cannot modify the graph.

How do you set it up?

You connect your MCP client to `https://mcp.whisper.security`. The setup page says OAuth handles authentication, or you can use an API key, and it provides copy-paste configuration for major clients.

Do I need to know Cypher to use it?

The product is intended for plain-language questions. The agent translates the request into graph queries and returns sourced answers from the live infrastructure graph, so users do not need to write Cypher for typical investigations.

How are answers supported or explained?

The page states that Whisper returns live, sourced answers from its graph, and each edge carries source-feed and first-seen/last-seen information. The `explain_indicator` tool is used to return the evidence chain behind a threat assessment.

Quick Facts

Category
Infrastructure intelligence platform
Primary users
Security teams, SOCs, threat hunters, brand and fraud teams, builders and platform teams
Access methods
API, native connectors, MCP
Supported MCP clients
Any MCP-compatible client; examples include Claude, ChatGPT, Cursor, VS Code, Windsurf
Deployment options
Cloud-hosted, dedicated cloud, on-prem
Pricing flow
Free trial available; paid plans include Starter, Professional, Business, and Enterprise contact sales