Asset Relationship Graph
The Asset Relationship Graph shows how one asset (a domain, URL, or contract address) connects to the rest of an investigation in your workspace: its scans, the findings on those scans, EvidencePacks, and TicketBridge cases. Start from one asset and see what is linked to it in one focused view.
It only ever shows real, stored links. It never guesses or infers a relationship the data does not already record, and it never shows sample data. Every connection names where it came from.
Overview
- Focused, one asset at a time. You pick an asset; the graph centers on it and draws only its direct, recorded relationships.
- Explicit links only. Edges come from real records: a scan of that asset, a finding on that scan, a case whose artifact is that asset, and the EvidencePacks those records point to. Nothing is inferred from co-occurrence or similarity.
- Every edge names its source. Each connection carries a short "via" note stating the record and field that established it, so you can trust and trace it.
- Two ways to read it. A visual graph and an equivalent list view. The list view is always present, so the graph is fully usable with a screen reader or keyboard.
- Hosting context when available. For a domain with stored scan enrichment, the page shows the newest scan's country, ASN, and hosting provider.
What it is for
Use it to answer "what is connected to this asset?" without opening every console:
- From a suspicious domain, jump to its scan, the findings, and any case or EvidencePack already raised for it.
- Confirm whether an asset already has an open case before starting a new one.
- Follow any node straight to its full detail view.
How to use it
- Sign in to Dralvia and open the graph from a scan result, an activity-timeline entry ("View related"), or a case, or open it directly and type an asset.
- The graph centers on the asset and draws its recorded relationships.
- Read the visual graph, or use the list view below it for the same information as text with links.
- Use zoom in / out / reset to adjust the visual layout.
- Select any node (or its Open link in the list) to go to that record's existing detail view.
API
GET /api/security/asset-graph
Query parameters:
| Parameter | Meaning | Notes |
|---|---|---|
asset | The asset value to center on (domain, URL, or contract address) | Required |
asset_type | domain, url, contract, or wallet | Optional; inferred from the value when omitted |
The response is a graph object:
{
"entity": { "id": "asset:evil.example", "kind": "domain", "label": "evil.example" },
"nodes": [
{ "id": "scan:1842", "kind": "scan", "label": "Scan scanpub-1", "href": "#/scan?target=evil.example" }
],
"edges": [
{ "source": "asset:evil.example", "target": "scan:1842",
"type": "scanned", "label": "scanned", "provenance": "ScanResult.domain" }
],
"meta": { "asset_type": "domain", "node_count": 5, "edge_count": 4,
"partial": false, "explicit_only": true }
}
Every edge includes a provenance string. meta.partial is true when a very large graph was capped.
Selecting a domain, URL, or scan node opens the supported URL & Phishing
Scanner with the graph's asset filled in. The #/scan?target=... form is a
compatibility alias handled by the application router; it does not represent a
separate scanner page.
API error quick reference
| Status | Meaning | What to do |
|---|---|---|
| 400 | No asset value was supplied | Include the asset parameter. |
| 401 | Not signed in, or no workspace context on the request | Sign in, or include your API key and workspace context. |
| 403 | Your plan does not include this module | Available on Pro and Enterprise. Compare plans in the dashboard. |
| 429 | Too many requests in a short time | Slow down and retry after a short pause. |
| 500 | Temporary service error | Retry shortly. The page shows a "Try again" action. |
Plan availability
The Asset Relationship Graph is available on Pro and Enterprise. On lower plans it shows a locked state with a link to compare plans.
Accessibility
The graph ships with a built-in list view that mirrors the visual graph: every node, its kind, its links, and each connection with its source. Nodes are keyboard-focusable and openable with Enter or Space, and a zoom reset control is always available.
The visual canvas grows in concentric rings as node count increases. Each node uses a bounded label card with the complete value available on hover or focus, so dense graphs do not place multiple raw labels on top of one another. Pan and zoom remain available when the expanded canvas is wider than the panel. The list view is still the authoritative readable fallback for very large graphs.
Limits
- Explicit links only. If the backend has not recorded a relationship, it is not drawn. This is deliberate: the graph never speculates.
- Scoped to your own workspace, and to one asset at a time.
- Very large graphs are capped;
meta.partialindicates when that happened. - The current graph supports stored domain, URL, contract-scan, finding, report, EvidencePack, and case links. Repository packages, email or mailbox records, and cloud resources are not graph sources yet. Wallets appear only when an existing case stores the wallet as its exact artifact.
- Hosting location is country-level context from the newest matching scan. Dralvia does not show an exact server pin because reliable coordinates are not stored for the asset.
- The country can describe CDN, proxy, or hosting infrastructure. It is not proof of a person's or attacker's location.
- Sign-in location is separate identity data and is never reused as hosting location.
- Hosting context does not change verdicts or scoring.
Where it appears
Opened from a scan result, a Security Activity Timeline entry ("View related"), or a case, or directly by entering an asset.