Whisper Security - Get Infrastructure Chain
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
↑ Back to Content Index
Microsoft Sentinel playbook that extracts IP and domain entities from an incident and queries the Whisper Security knowledge graph to traverse the full infrastructure chain (IP, prefix, ASN, geolocation). Results are posted as an incident comment.
Logic App Connectors
This playbook uses 3 Logic App connectors / built-in actions:
Action parameters (URLs, paths, function IDs)
| Action |
Method |
Endpoint |
Other |
| Entities_-_Get_IPs |
post |
/entities/ip |
— |
| Entities_-_Get_DNS |
post |
/entities/dnsresolution |
— |
| Add_Incident_Comment |
post |
/Incidents/Comment |
— |
| Action |
Method |
Endpoint |
Other |
| Get_API_Key |
get |
/secrets/@{encodeURIComponent(last(split(parameters('keyVaultSecretUri'), '/')))}/value |
— |
| Get_API_Key_2 |
get |
/secrets/@{encodeURIComponent(last(split(parameters('keyVaultSecretUri'), '/')))}/value |
— |
http (Built-in)
| Action |
Method |
Endpoint |
Other |
| Call_Whisper_InfraChain_IP |
POST |
https://graph.whisper.security/api/query |
— |
| Call_Whisper_InfraChain_Domain |
POST |
https://graph.whisper.security/api/query |
— |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
↑ Back to Playbooks · Back to Whisper