# Microsoft Sentinel Integration

> The Whisper solution for Microsoft Sentinel, from the Content Hub: enrich incidents with threat scores, infrastructure context, WHOIS, BGP and ASN data.

*Source: https://www.whisper.security/docs/integrations/sentinel/overview*

---
Bring WhisperGraph into Microsoft Sentinel. The Whisper Security solution installs from the Content Hub and enriches every IP, domain, and ASN in your incidents with threat scores, infrastructure context, WHOIS and BGP history, and ASN reputation — from a single API.

Whisper is the internet's infrastructure graph: DNS, BGP, WHOIS, hosting, and threat intel pre-joined into one queryable map. The solution puts that graph behind your incidents, workbooks, and hunts, so the pivot that used to mean five tools happens inside Sentinel.

> **Get the solution:** [Whisper Security on the Microsoft Marketplace →](https://marketplace.microsoft.com/en-us/product/whisper-security.azure-sentinel-solution-whisper)

## What you get

| Component | Count | Purpose |
| --- | --- | --- |
| Playbooks | 10 | On-demand enrichment of IPs, domains, ASNs, and infrastructure relationships, posted back to the incident as a comment |
| Ingestion pipelines | 5 | Incident-triggered enrichment plus scheduled WHOIS history, BGP history, and hourly ASN reputation polling |
| Custom tables | 4 | Threat intel, infrastructure context, WHOIS/BGP history, and ASN reputation, queryable from any KQL surface |
| Workbooks | 5 | Threat landscape, attack surface, ASN reputation, domain anomalies, and an enrichment audit |
| Analytics rule templates | 8 | Scheduled detections with MITRE ATT&CK mappings — C2 traffic, newly registered domains, BGP anomalies, registrar changes, and more |
| Hunting queries | 6 | Proactive pivots through Whisper infrastructure context |

On a default install, 1 of 8 analytics rules and 1 of 6 hunts can produce a non-zero result. The two incident-triggered pipelines are a hard precondition for five rules and five hunts. [Workbooks & Detections](/docs/integrations/sentinel/workbooks-detections) says which content item is dark and why, row by row.

The install also provisions managed identities for every playbook and pipeline, the role assignments they need, and diagnostic settings that feed the enrichment audit workbook — no credentials to manage.

## How data flows

Three modes run side by side:

- **On incident** — the two incident-triggered pipelines read the entities of a new incident, call the Whisper API, and write the results into the custom tables. They only run once you have wired them to an automation rule.
- **On demand** — playbooks run against one incident from **Actions → Run playbook** and post what they find as a comment on that incident. They do not write to the custom tables.
- **Scheduled** — the three scheduled pipelines keep baseline intel fresh: ASN reputation hourly, WHOIS and BGP history daily, for the domains, IPs and ASNs you put on the watchlists.

Workbooks, analytics rules, and hunting queries all read from the same four custom tables, so everything downstream sharpens as the pipelines accumulate data.

## Getting started

1. Get a Whisper API key. It's the same key the API and MCP server use.
2. Check the [Requirements](/docs/integrations/sentinel/requirements) — the Key Vault and permission prerequisites matter here.
3. Follow the [Installation](/docs/integrations/sentinel/installation) to install from the Content Hub or the Marketplace listing.
4. Complete the [Configuration](/docs/integrations/sentinel/configuration) — three one-time steps wire the solution into your incident workflow.
5. Open an incident and run `Whisper-ExplainIP` from **Actions → Run playbook**. [Playbooks](/docs/integrations/sentinel/playbooks) walks through what comes back.

## Documentation index

Setup

- [Requirements](/docs/integrations/sentinel/requirements) — Azure permissions, workspace, Key Vault, and API key prerequisites
- [Installation](/docs/integrations/sentinel/installation) — store the key, run the install wizard, verify first data
- [Configuration](/docs/integrations/sentinel/configuration) — playbook permissions, automation rules, analytics rules, watchlists

Using the solution

- [Playbooks](/docs/integrations/sentinel/playbooks) — the ten enrichment playbooks and recommended automation pairings
- [Workbooks & Detections](/docs/integrations/sentinel/workbooks-detections) — workbooks, analytics rules, and hunting queries

Reference

- [Data Reference](/docs/integrations/sentinel/data-reference) — the four custom tables with their column contracts, and the pipelines that write them
- [Troubleshooting](/docs/integrations/sentinel/troubleshooting) — error codes, ingestion issues, and diagnostics
