Solution: Whisper
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Publisher | Whisper Security |
| Support Tier | Partner |
| Support Link | https://whisper.security/contact |
| Categories | Security - Threat Intelligence,Security - Network |
| Version | 3.0.0 |
| Author | Whisper Security - support@whisper.security |
| First Published | 2026-06-01 |
| Last Updated | 2026-07-22 |
| Solution Folder | Whisper |
| Marketplace | Azure Marketplace · Popularity: 🟡 Low (39%) |
The Whisper Security solution for Microsoft Sentinel brings the Whisper internet-scale infrastructure knowledge graph (7+ billion nodes, 39+ billion edges, 40+ threat feeds) into Microsoft Sentinel's detection and response workflows. It provides real-time threat intelligence enrichment, infrastructure context, WHOIS/BGP history, and ASN reputation polling.
Underlying Microsoft technologies used:
This solution does not include data connectors.
This solution may contain other components such as analytics rules, workbooks, hunting queries, or playbooks.
This solution queries 6 table(s) from its content items:
| Table | Used By Content |
|---|---|
AzureDiagnostics |
Workbooks |
CommonSecurityLog |
Analytics |
WhisperASNReputation_CL |
Analytics, Hunting, Workbooks |
WhisperHistory_CL |
Analytics, Workbooks |
WhisperInfraContext_CL |
Analytics, Hunting, Workbooks |
WhisperThreatIntel_CL |
Analytics, Hunting, Workbooks |
This solution includes 30 content item(s) (29 in solution, 1 discovered 🔍):
| Content Type | Total | In Solution | Discovered |
|---|---|---|---|
| Playbooks | 10 | 10 | - |
| Analytic Rules | 8 | 8 | - |
| Hunting Queries | 6 | 6 | - |
| Workbooks | 6 | 5 | 1 |
| Name | Severity | Tactics | Tables Used |
|---|---|---|---|
| Whisper Security - ASN Reputation Degradation | Medium | ResourceDevelopment | WhisperASNReputation_CL |
| Whisper Security - BGP Route Anomaly with Traffic Spike | High | Collection | CommonSecurityLogWhisperHistory_CL |
| Whisper Security - C2 Communication Detection | High | CommandAndControl | CommonSecurityLogWhisperThreatIntel_CL |
| Whisper Security - Co-Hosted Malware Cluster Detection | High | ResourceDevelopment | WhisperInfraContext_CLWhisperThreatIntel_CL |
| Whisper Security - Domain Registrar Change Anomaly | Medium | ResourceDevelopment | WhisperHistory_CL |
| Whisper Security - Newly Registered Domain on Threat ASN | High | ResourceDevelopment | WhisperASNReputation_CLWhisperInfraContext_CL |
| Whisper Security - SPF Record Unauthorized Include Detection | High | InitialAccess | WhisperInfraContext_CL |
| Whisper Security - Tor Exit Node Communication | Medium | CommandAndControl | CommonSecurityLogWhisperThreatIntel_CL |
| Name | Tactics | Tables Used |
|---|---|---|
| Whisper - ASN Reputation Score Hunt | Collection, CredentialAccess | WhisperASNReputation_CL |
| Whisper - Attack Surface Discovery | Discovery | WhisperInfraContext_CLWhisperThreatIntel_CL |
| Whisper - Domain to ASN Migration | ResourceDevelopment | WhisperInfraContext_CLWhisperThreatIntel_CL |
| Whisper - Infrastructure Pivot Analysis | ResourceDevelopment | WhisperInfraContext_CLWhisperThreatIntel_CL |
| Whisper - Newly Registered Domain Hunt | ResourceDevelopment | WhisperInfraContext_CLWhisperThreatIntel_CL |
| Whisper - Shared Infrastructure Clustering | ResourceDevelopment | WhisperInfraContext_CLWhisperThreatIntel_CL |
| Name | Description | Tables Used |
|---|---|---|
| Whisper Security - Batch Indicator Enrichment | Microsoft Sentinel incident trigger playbook that extracts all IP and DNS entities from an incident,... | - |
| Whisper Security - Check ASN Reputation | Microsoft Sentinel incident trigger playbook that extracts IP entities from an incident, determines ... | - |
| Whisper Security - Discover Co-Hosted Domains | Microsoft Sentinel playbook that extracts IP entities from an incident and queries the Whisper Secur... | - |
| Whisper Security - Explain ASN | Microsoft Sentinel incident trigger playbook that extracts ASN references from incident entities, ca... | - |
| Whisper Security - Explain Domain | Microsoft Sentinel incident trigger playbook that extracts DNS/domain entities from an incident, cal... | - |
| Whisper Security - Explain IP Address | Microsoft Sentinel incident trigger playbook that extracts IP entities from an incident, calls the W... | - |
| Whisper Security - Explain Network | Microsoft Sentinel playbook that extracts IP entities from an incident, calls the Whisper explain() ... | - |
| Whisper Security - Get BGP History | Microsoft Sentinel incident trigger playbook that extracts IP entities from an incident, posts an im... | - |
| Whisper Security - Get Infrastructure Chain | Microsoft Sentinel playbook that extracts IP and domain entities from an incident and queries the Wh... | - |
| Whisper Security - Get WHOIS History | Microsoft Sentinel incident trigger playbook that extracts DNS entities from an incident, calls the ... | - |
⚠️ Items marked with ⚠️ are not listed in the Solution JSON file. They were discovered by scanning the solution folder and may be legacy items, under development, or excluded from the official solution package.
| Version | Date Modified (DD-MM-YYYY) | Change History |
|---|---|---|
| 3.0.0 | 13-07-2026 | Initial Solution Release. Data Connector Whisper Security custom-API connector for the Whisper graph API | v 1.0.0 Custom tables WhisperThreatIntel_CL, WhisperInfraContext_CL, WhisperHistory_CL, WhisperASNReputation_CL with their data collection endpoints and rules | v 1.0.0Ingestion pipelines five scheduled Logic Apps that enrich indicators and watchlists into the custom tables | v 1.0.0 Playbooks ten on-demand enrichment playbooks: ExplainIP, ExplainDomain, ExplainASN, ExplainNetwork, BatchEnrich, CheckAsnReputation, DiscoverCoHosted, GetInfraChain, GetBgpHistory, GetWhoisHistory | v 1.0.0 Analytic Rules eight scheduled detections covering C2 communication, Tor exit-node traffic, newly registered domains on threat ASNs, co-hosted malware clusters, ASN reputation degradation, BGP route anomalies, registrar change anomalies, and unauthorized SPF includes | v 1.0.0 Hunting Queries six queries for attack-surface discovery, newly registered domain hunting, shared-infrastructure clustering, pivot analysis, domain-to-ASN migration, and BGP anomalies | v 1.0.0 Workbooks five workbooks: External Attack Surface Overview, Infrastructure Threat Landscape, ASN Reputation Monitoring, Domain Registration Anomaly, Incident Enrichment Audit | v 1.0.0 Deployment reliability Pinned nested Microsoft.Resources/deployments to apiVersion 2025-04-01 (V3-emitted 2025-07-01 is rejected by ARM at deploy time; older versions fail ARM-TTK recency). createUiDefinition outputs.location uses the standard [location()] (required by ARM-TTK "Location Should Be In Outputs"; the marketplace wizard populates it from the Basics blade). Accepts versioned Key Vault secret URIs (.../secrets/<name>/<32-hex-version>).Observability Auto-provisions diagnosticSettings (WorkflowRuntime + AllMetrics) on all 10 playbooks and 5 pipelines, routed to the workspace, so IncidentEnrichmentAudit populates without manual customer setup. Added a prerequisite banner in the workbook explaining the first-run latency until AzureDiagnostics receives Logic App records.Workbook fixes AsnReputationMonitoring — Top Degraded ASNs query rewritten with tuple destructuring of arg_min / arg_max. All 5 workbooks registered in WorkbooksMetadata.json (required for V3 packaging inclusion). IncidentEnrichmentAudit queries now use column_ifexists() for every AzureDiagnostics column so panels parse before the schema is populated.Certification hardening ARM-TTK sanitizer wraps contentProductId alongside other id fields to satisfy IDs Should Be Derived From ResourceIDs. keyVaultSecretUri parameter standardized to securestring. Added workspaceResourceId as a top-level template output so ARM-TTK's Variables Must Be Referenced rule sees it.Release pipeline release.yml sparse-checks-out Azure/Azure-Sentinel@master, runs createSolutionV3.ps1 -VersionMode catalog, then post-processor, then sanitizer, then version stamp (order is load-bearing). Frozen role_seed values in the pipeline table preserve guid()-derived role-assignment names across upgrades.Certification feedback fixes (13-07-2026) Logo SVG gradient converted from a CSS <style> class to inline fill attributes (the Azure portal sanitizer strips <style> blocks, which broke rendering). Publisher ID aligned with Partner Center: whisper-security.azure-sentinel-solution-whisper. Support links updated to https://whisper.security/contact. |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊