Whisper Security - Batch Indicator Enrichment
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
↑ Back to Content Index
Microsoft Sentinel incident trigger playbook that extracts all IP and DNS entities from an incident, collects them into a single array (capped at 50), then iterates through indicators calling explain() for each. Results are posted as an incident comment with an enrichment summary table.
Logic App Connectors
This playbook uses 3 Logic App connectors / built-in actions:
Action parameters (URLs, paths, function IDs)
| Action |
Method |
Endpoint |
Other |
| Entities_-_Get_IPs |
post |
/entities/ip |
— |
| Entities_-_Get_DNS |
post |
/entities/dnsresolution |
— |
| Add_Incident_Comment_Success |
post |
/Incidents/Comment |
— |
| Add_Incident_Comment_Error |
post |
/Incidents/Comment |
— |
| Action |
Method |
Endpoint |
Other |
| Get_API_Key |
get |
/secrets/@{encodeURIComponent(last(split(parameters('keyVaultSecretUri'), '/')))}/value |
— |
http (Built-in)
| Action |
Method |
Endpoint |
Other |
| Call_Whisper_Explain |
POST |
https://graph.whisper.security/api/query |
— |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
↑ Back to Playbooks · Back to Whisper