Whisper Security - Explain Network
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
↑ Back to Content Index
Microsoft Sentinel playbook that extracts IP entities from an incident, calls the Whisper explain() API for threat assessment, then queries infrastructure context for combined network analysis. Results including threat score, threat flags, and infrastructure details are posted as an incident comment.
Logic App Connectors
This playbook uses 3 Logic App connectors / built-in actions:
Action parameters (URLs, paths, function IDs)
| Action |
Method |
Endpoint |
Other |
| Entities_-_Get_IPs |
post |
/entities/ip |
— |
| Add_Incident_Comment |
post |
/Incidents/Comment |
— |
| Action |
Method |
Endpoint |
Other |
| Get_API_Key |
get |
/secrets/@{encodeURIComponent(last(split(parameters('keyVaultSecretUri'), '/')))}/value |
— |
http (Built-in)
| Action |
Method |
Endpoint |
Other |
| Call_Whisper_Explain |
POST |
https://graph.whisper.security/api/query |
— |
| Call_Whisper_InfraContext |
POST |
https://graph.whisper.security/api/query |
— |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
↑ Back to Playbooks · Back to Whisper