Integrations
Ways to connect WhisperGraph to your stack: native connectors, the REST Cypher API for pipelines, and MCP for AI assistants.
In this chapter
- What Every Connector GuaranteesThe field contract the four table-writing connectors share: guaranteed/conditional columns, what's absent on failure, and verdict semantics.
- Splunk8 pagesConnect Splunk to WhisperGraph for IOC enrichment, ad-hoc graph queries, threat intel and attack-surface monitoring — components, commands.
- OpenCTI6 pagesConnect OpenCTI to WhisperGraph for one-click observable enrichment: DNS, WHOIS, BGP and threat context written back as STIX 2.1 objects.
- Microsoft Sentinel8 pagesBring WhisperGraph into Microsoft Sentinel: playbooks, pipelines, workbooks, analytics rules and hunting queries from the Content Hub.
- Wazuh2 pagesEnrich Wazuh alerts with Whisper context on external indicators, and optionally bring agent DNS and egress activity into Wazuh.
- MISP1 pageEnrich a MISP attribute — IP, domain, hostname or AS number — with ASN, DNS, WHOIS and threat-intel context, returned as MISP objects.
Integrations Documentation
WhisperGraph has native connectors for Splunk, OpenCTI, Microsoft Sentinel, Wazuh and MISP, each documented in its own subsection: what it enriches, where to get it, and how to configure it. Everything else uses one of two open interfaces: the REST Cypher API for any tool that can send an HTTPS request, and the MCP server for AI assistants. This page maps which path fits which job.
Any other tool: the REST API
Any SIEM, SOAR, TIP, or ETL job that can POST JSON can integrate directly. Send Cypher to the query endpoint and get columns and rows back:
curl -s -A "your-app/1.0" \
-X POST https://graph.whisper.security/api/query \
-H "Content-Type: application/json" \
-H "X-API-Key: whisper-YOUR_API_KEY" \
-d '{"query": "CALL explain(\"185.220.101.1\") YIELD indicator, level, score, explanation"}'
The request above carries a key; sign in to copy yours. The HTTP API chapter has the request fields, the response envelope and the status codes, and the query language itself is documented in Cypher.
Read
coveragebeforeband. Only known-clean — coverage: known-clean. In coverage, no malicious evidence. licenses the word "clean"; no-data — coverage: no-data. Not in coverage. This is not a verdict — nothing was looked at. means unknown, which is a different thing again; malicious-evidenced — coverage: malicious-evidenced. In coverage, with positive evidence of malice. and ambiguous — coverage: ambiguous. In coverage, and the evidence points both ways. mean there is evidence, whatever the band says. Full contract: Coverage — what we looked at.
AI assistants over MCP
MCP-capable clients such as Claude and Cursor connect to the server at https://mcp.whisper.security and get graph queries, schema introspection, threat verdicts, and guided workflows as tools, with no custom code. See AI & Agents for what the server exposes.
Asking for a connector
The integration contract says what a connector is expected to do. If you need one that is not listed here, tell us through Support.