Whisper for Sentinel

Solution: Whisper

Whisper Logo

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Solutions Index


Attribute Value
Publisher Whisper Security
Support Tier Partner
Support Link https://whisper.security/contact
Categories Security - Threat Intelligence,Security - Network
Version 3.0.0
Author Whisper Security - support@whisper.security
First Published 2026-06-01
Last Updated 2026-07-22
Solution Folder Whisper
Marketplace Azure Marketplace · Popularity: 🟡 Low (39%)

The Whisper Security solution for Microsoft Sentinel brings the Whisper internet-scale infrastructure knowledge graph (7+ billion nodes, 39+ billion edges, 40+ threat feeds) into Microsoft Sentinel's detection and response workflows. It provides real-time threat intelligence enrichment, infrastructure context, WHOIS/BGP history, and ASN reputation polling.

Underlying Microsoft technologies used:

Contents

Data Connectors

This solution does not include data connectors.

This solution may contain other components such as analytics rules, workbooks, hunting queries, or playbooks.

Tables Used

This solution queries 6 table(s) from its content items:

Table Used By Content
AzureDiagnostics Workbooks
CommonSecurityLog Analytics
WhisperASNReputation_CL Analytics, Hunting, Workbooks
WhisperHistory_CL Analytics, Workbooks
WhisperInfraContext_CL Analytics, Hunting, Workbooks
WhisperThreatIntel_CL Analytics, Hunting, Workbooks

Content Items

This solution includes 30 content item(s) (29 in solution, 1 discovered 🔍):

Content Type Total In Solution Discovered
Playbooks 10 10 -
Analytic Rules 8 8 -
Hunting Queries 6 6 -
Workbooks 6 5 1

Analytic Rules

Name Severity Tactics Tables Used
Whisper Security - ASN Reputation Degradation Medium ResourceDevelopment WhisperASNReputation_CL
Whisper Security - BGP Route Anomaly with Traffic Spike High Collection CommonSecurityLog
WhisperHistory_CL
Whisper Security - C2 Communication Detection High CommandAndControl CommonSecurityLog
WhisperThreatIntel_CL
Whisper Security - Co-Hosted Malware Cluster Detection High ResourceDevelopment WhisperInfraContext_CL
WhisperThreatIntel_CL
Whisper Security - Domain Registrar Change Anomaly Medium ResourceDevelopment WhisperHistory_CL
Whisper Security - Newly Registered Domain on Threat ASN High ResourceDevelopment WhisperASNReputation_CL
WhisperInfraContext_CL
Whisper Security - SPF Record Unauthorized Include Detection High InitialAccess WhisperInfraContext_CL
Whisper Security - Tor Exit Node Communication Medium CommandAndControl CommonSecurityLog
WhisperThreatIntel_CL

Hunting Queries

Name Tactics Tables Used
Whisper - ASN Reputation Score Hunt Collection, CredentialAccess WhisperASNReputation_CL
Whisper - Attack Surface Discovery Discovery WhisperInfraContext_CL
WhisperThreatIntel_CL
Whisper - Domain to ASN Migration ResourceDevelopment WhisperInfraContext_CL
WhisperThreatIntel_CL
Whisper - Infrastructure Pivot Analysis ResourceDevelopment WhisperInfraContext_CL
WhisperThreatIntel_CL
Whisper - Newly Registered Domain Hunt ResourceDevelopment WhisperInfraContext_CL
WhisperThreatIntel_CL
Whisper - Shared Infrastructure Clustering ResourceDevelopment WhisperInfraContext_CL
WhisperThreatIntel_CL

Workbooks

Name Tables Used
AsnReputationMonitoring WhisperASNReputation_CL
DomainRegistrationAnomaly WhisperHistory_CL
WhisperInfraContext_CL
ExternalAttackSurfaceOverview WhisperInfraContext_CL
IncidentEnrichmentAudit AzureDiagnostics
InfrastructureThreatLandscape WhisperASNReputation_CL
WhisperInfraContext_CL
WhisperThreatIntel_CL
WorkbooksMetadata ⚠️ -

Playbooks

Name Description Tables Used
Whisper Security - Batch Indicator Enrichment Microsoft Sentinel incident trigger playbook that extracts all IP and DNS entities from an incident,... -
Whisper Security - Check ASN Reputation Microsoft Sentinel incident trigger playbook that extracts IP entities from an incident, determines ... -
Whisper Security - Discover Co-Hosted Domains Microsoft Sentinel playbook that extracts IP entities from an incident and queries the Whisper Secur... -
Whisper Security - Explain ASN Microsoft Sentinel incident trigger playbook that extracts ASN references from incident entities, ca... -
Whisper Security - Explain Domain Microsoft Sentinel incident trigger playbook that extracts DNS/domain entities from an incident, cal... -
Whisper Security - Explain IP Address Microsoft Sentinel incident trigger playbook that extracts IP entities from an incident, calls the W... -
Whisper Security - Explain Network Microsoft Sentinel playbook that extracts IP entities from an incident, calls the Whisper explain() ... -
Whisper Security - Get BGP History Microsoft Sentinel incident trigger playbook that extracts IP entities from an incident, posts an im... -
Whisper Security - Get Infrastructure Chain Microsoft Sentinel playbook that extracts IP and domain entities from an incident and queries the Wh... -
Whisper Security - Get WHOIS History Microsoft Sentinel incident trigger playbook that extracts DNS entities from an incident, calls the ... -

⚠️ Items marked with ⚠️ are not listed in the Solution JSON file. They were discovered by scanning the solution folder and may be legacy items, under development, or excluded from the official solution package.

Release Notes

Version Date Modified (DD-MM-YYYY) Change History
3.0.0 13-07-2026 Initial Solution Release.

Data Connector Whisper Security custom-API connector for the Whisper graph API | v 1.0.0

Custom tables WhisperThreatIntel_CL, WhisperInfraContext_CL, WhisperHistory_CL, WhisperASNReputation_CL with their data collection endpoints and rules | v 1.0.0

Ingestion pipelines five scheduled Logic Apps that enrich indicators and watchlists into the custom tables | v 1.0.0

Playbooks ten on-demand enrichment playbooks: ExplainIP, ExplainDomain, ExplainASN, ExplainNetwork, BatchEnrich, CheckAsnReputation, DiscoverCoHosted, GetInfraChain, GetBgpHistory, GetWhoisHistory | v 1.0.0

Analytic Rules eight scheduled detections covering C2 communication, Tor exit-node traffic, newly registered domains on threat ASNs, co-hosted malware clusters, ASN reputation degradation, BGP route anomalies, registrar change anomalies, and unauthorized SPF includes | v 1.0.0

Hunting Queries six queries for attack-surface discovery, newly registered domain hunting, shared-infrastructure clustering, pivot analysis, domain-to-ASN migration, and BGP anomalies | v 1.0.0

Workbooks five workbooks: External Attack Surface Overview, Infrastructure Threat Landscape, ASN Reputation Monitoring, Domain Registration Anomaly, Incident Enrichment Audit | v 1.0.0

Deployment reliability Pinned nested Microsoft.Resources/deployments to apiVersion 2025-04-01 (V3-emitted 2025-07-01 is rejected by ARM at deploy time; older versions fail ARM-TTK recency). createUiDefinition outputs.location uses the standard [location()] (required by ARM-TTK "Location Should Be In Outputs"; the marketplace wizard populates it from the Basics blade). Accepts versioned Key Vault secret URIs (.../secrets/<name>/<32-hex-version>).

Observability Auto-provisions diagnosticSettings (WorkflowRuntime + AllMetrics) on all 10 playbooks and 5 pipelines, routed to the workspace, so IncidentEnrichmentAudit populates without manual customer setup. Added a prerequisite banner in the workbook explaining the first-run latency until AzureDiagnostics receives Logic App records.

Workbook fixes AsnReputationMonitoring — Top Degraded ASNs query rewritten with tuple destructuring of arg_min / arg_max. All 5 workbooks registered in WorkbooksMetadata.json (required for V3 packaging inclusion). IncidentEnrichmentAudit queries now use column_ifexists() for every AzureDiagnostics column so panels parse before the schema is populated.

Certification hardening ARM-TTK sanitizer wraps contentProductId alongside other id fields to satisfy IDs Should Be Derived From ResourceIDs. keyVaultSecretUri parameter standardized to securestring. Added workspaceResourceId as a top-level template output so ARM-TTK's Variables Must Be Referenced rule sees it.

Release pipeline release.yml sparse-checks-out Azure/Azure-Sentinel@master, runs createSolutionV3.ps1 -VersionMode catalog, then post-processor, then sanitizer, then version stamp (order is load-bearing). Frozen role_seed values in the pipeline table preserve guid()-derived role-assignment names across upgrades.

Certification feedback fixes (13-07-2026) Logo SVG gradient converted from a CSS <style> class to inline fill attributes (the Azure portal sanitizer strips <style> blocks, which broke rendering). Publisher ID aligned with Partner Center: whisper-security.azure-sentinel-solution-whisper. Support links updated to https://whisper.security/contact.

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Solutions Index