Microsoft Sentinel Integration
Bring WhisperGraph into Microsoft Sentinel: incident playbooks, scheduled pipelines, workbooks, analytics rules, and hunting queries, installed from the Content Hub. Components, data flow, and the full documentation index.
Microsoft Sentinel Integration Documentation
Bring WhisperGraph into Microsoft Sentinel. The Whisper Security solution installs from the Content Hub and enriches every IP, domain, and ASN in your incidents with threat scores, infrastructure context, WHOIS and BGP history, and ASN reputation — from a single API.
Whisper is the internet's infrastructure graph: DNS, BGP, WHOIS, hosting, and threat intel pre-joined into one queryable map. The solution puts that graph behind your incidents, workbooks, and hunts, so the pivot that used to mean five tools happens inside Sentinel.
Get the solution: Whisper Security on the Microsoft Marketplace →
What you get
| Component | Count | Purpose |
|---|---|---|
| Playbooks | 10 | On-demand enrichment of IPs, domains, ASNs, and infrastructure relationships, posted back to the incident as a comment |
| Ingestion pipelines | 5 | Incident-triggered enrichment plus scheduled WHOIS history, BGP history, and hourly ASN reputation polling |
| Custom tables | 4 | Threat intel, infrastructure context, WHOIS/BGP history, and ASN reputation, queryable from any KQL surface |
| Workbooks | 5 | Threat landscape, attack surface, ASN reputation, domain anomalies, and an enrichment audit |
| Analytics rule templates | 8 | Scheduled detections with MITRE ATT&CK mappings — C2 traffic, newly registered domains, BGP anomalies, registrar changes, and more |
| Hunting queries | 6 | Proactive pivots through Whisper infrastructure context |
The install also provisions managed identities for every playbook and pipeline, the role assignments they need, and diagnostic settings that feed the enrichment audit workbook — no credentials to manage.
How data flows
Two ingestion modes run side by side:
- On demand — playbooks read the entities of an incident, call the Whisper API, write results to the custom tables, and post a summary comment on the incident. Run them manually from an incident or wire them to automation rules.
- Scheduled — pipelines keep baseline intel fresh: ASN reputation hourly, WHOIS and BGP history daily for the domains and IPs you put on the watchlists.
Workbooks, analytics rules, and hunting queries all read from the same four custom tables, so everything downstream sharpens as enrichment data accumulates.
Getting started
- Get a Whisper API key. It's the same key the API and MCP server use.
- Check the Requirements — the Key Vault and permission prerequisites matter here.
- Follow the Installation to install from the Content Hub or the Marketplace listing.
- Complete the Configuration — three one-time steps wire the solution into your incident workflow.
- Open an incident and run
Whisper-ExplainIPfrom Actions → Run playbook. Playbooks walks through what comes back.
Documentation index
Setup
- Requirements — Azure permissions, workspace, Key Vault, and API key prerequisites
- Installation — store the key, run the install wizard, verify first data
- Configuration — playbook permissions, automation rules, analytics rules, watchlists
Using the solution
- Playbooks — the ten enrichment playbooks and recommended automation pairings
- Workbooks & Detections — workbooks, analytics rules, and hunting queries
Reference
- Data Reference — custom tables, ingestion pipelines, and API quota management
- Troubleshooting — error codes, ingestion issues, and diagnostics