Whisper Security - Explain Network

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Microsoft Sentinel playbook that extracts IP entities from an incident, calls the Whisper explain() API for threat assessment, then queries infrastructure context for combined network analysis. Results including threat score, threat flags, and infrastructure details are posted as an incident comment.

Attribute Value
Type Playbook
Solution Whisper
Source View on GitHub

Logic App Connectors

This playbook uses 3 Logic App connectors / built-in actions:

Connector / Action Type Connections Actions
azuresentinel Managed 0 2
keyvault Managed 0 1
http Built-in 0 2
Action parameters (URLs, paths, function IDs)

azuresentinel (Managed)

Action Method Endpoint Other
Entities_-_Get_IPs post /entities/ip
Add_Incident_Comment post /Incidents/Comment

keyvault (Managed)

Action Method Endpoint Other
Get_API_Key get /secrets/@{encodeURIComponent(last(split(parameters('keyVaultSecretUri'), '/')))}/value

http (Built-in)

Action Method Endpoint Other
Call_Whisper_Explain POST https://graph.whisper.security/api/query
Call_Whisper_InfraContext POST https://graph.whisper.security/api/query

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Playbooks · Back to Whisper