Skip to content
Integrations
Skip navigation

Microsoft Sentinel Integration

Bring WhisperGraph into Microsoft Sentinel: playbooks, pipelines, workbooks, analytics rules and hunting queries from the Content Hub.

Published Last updated

On this page (4)

Microsoft Sentinel Integration Documentation

Bring WhisperGraph into Microsoft Sentinel. The Whisper Security solution installs from the Content Hub and enriches every IP, domain, and ASN in your incidents with threat scores, infrastructure context, WHOIS and BGP history, and ASN reputation — from a single API.

Whisper is the internet's infrastructure graph: DNS, BGP, WHOIS, hosting, and threat intel pre-joined into one queryable map. The solution puts that graph behind your incidents, workbooks, and hunts, so the pivot that used to mean five tools happens inside Sentinel.

Get the solution: Whisper Security on the Microsoft Marketplace →

What you get

ComponentCountPurpose
Playbooks10On-demand enrichment of IPs, domains, ASNs, and infrastructure relationships, posted back to the incident as a comment
Ingestion pipelines5Incident-triggered enrichment plus scheduled WHOIS history, BGP history, and hourly ASN reputation polling
Custom tables4Threat intel, infrastructure context, WHOIS/BGP history, and ASN reputation, queryable from any KQL surface
Workbooks5Threat landscape, attack surface, ASN reputation, domain anomalies, and an enrichment audit
Analytics rule templates8Scheduled detections with MITRE ATT&CK mappings — C2 traffic, newly registered domains, BGP anomalies, registrar changes, and more
Hunting queries6Proactive pivots through Whisper infrastructure context

On a default install, 1 of 8 analytics rules and 1 of 6 hunts can produce a non-zero result. The two incident-triggered pipelines are a hard precondition for five rules and five hunts. Workbooks & Detections says which content item is dark and why, row by row.

The install also provisions managed identities for every playbook and pipeline, the role assignments they need, and diagnostic settings that feed the enrichment audit workbook — no credentials to manage.

How data flows

Three modes run side by side:

  • On incident — the two incident-triggered pipelines read the entities of a new incident, call the Whisper API, and write the results into the custom tables. They only run once you have wired them to an automation rule.
  • On demand — playbooks run against one incident from Actions → Run playbook and post what they find as a comment on that incident. They do not write to the custom tables.
  • Scheduled — the three scheduled pipelines keep baseline intel fresh: ASN reputation hourly, WHOIS and BGP history daily, for the domains, IPs and ASNs you put on the watchlists.

Workbooks, analytics rules, and hunting queries all read from the same four custom tables, so everything downstream sharpens as the pipelines accumulate data.

Getting started

  1. Get a Whisper API key. It's the same key the API and MCP server use.
  2. Check the Requirements — the Key Vault and permission prerequisites matter here.
  3. Follow the Installation to install from the Content Hub or the Marketplace listing.
  4. Complete the Configuration — three one-time steps wire the solution into your incident workflow.
  5. Open an incident and run Whisper-ExplainIP from Actions → Run playbook. Playbooks walks through what comes back.

Documentation index

Setup

  • Requirements — Azure permissions, workspace, Key Vault, and API key prerequisites
  • Installation — store the key, run the install wizard, verify first data
  • Configuration — playbook permissions, automation rules, analytics rules, watchlists

Using the solution

  • Playbooks — the ten enrichment playbooks and recommended automation pairings
  • Workbooks & Detections — workbooks, analytics rules, and hunting queries

Reference

  • Data Reference — the four custom tables with their column contracts, and the pipelines that write them
  • Troubleshooting — error codes, ingestion issues, and diagnostics