Whisper Security - Discover Co-Hosted Domains

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Microsoft Sentinel playbook that extracts IP entities from an incident and queries the Whisper Security knowledge graph to discover domains co-hosted on the same infrastructure. Results are posted as an incident comment with a domain list and count.

Attribute Value
Type Playbook
Solution Whisper
Source View on GitHub

Logic App Connectors

This playbook uses 3 Logic App connectors / built-in actions:

Connector / Action Type Connections Actions
azuresentinel Managed 0 2
keyvault Managed 0 1
http Built-in 0 1
Action parameters (URLs, paths, function IDs)

azuresentinel (Managed)

Action Method Endpoint Other
Entities_-_Get_IPs post /entities/ip
Add_Incident_Comment post /Incidents/Comment

keyvault (Managed)

Action Method Endpoint Other
Get_API_Key get /secrets/@{encodeURIComponent(last(split(parameters('keyVaultSecretUri'), '/')))}/value

http (Built-in)

Action Method Endpoint Other
Call_Whisper_DiscoverCoHosted POST https://graph.whisper.security/api/query

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Playbooks · Back to Whisper