Whisper for Sentinel
by Whisper Security
Enrich Microsoft Sentinel incidents with real-time threat scores and infrastructure intelligence.
Whisper Security brings the internet's largest infrastructure graph into every Microsoft Sentinel incident.
When a Sentinel incident fires on a suspicious IP, a phishing domain or an unfamiliar ASN, the first question every analyst asks is the same: what is this thing, and is it actually dangerous? Today that answer is buried across half a dozen tools — VirusTotal for reputation, RDAP and ICANN for WHOIS, RIPE and Hurricane Electric for BGP, abuse.ch and Spamhaus for feeds, Shodan and Censys for infrastructure. Analysts copy and paste between tabs, lose context across systems, and burn hours per incident on work that should take seconds.
Whisper Security replaces that pivoting with a single integrated view inside Sentinel. Our knowledge graph maps the complete relationship structure of the internet — 7 billion nodes, 26 billion edges, 5.6 million threat intelligence edges and 40+ feeds covering DNS resolution, domain hierarchy, BGP routing, IP allocation, GeoIP, email infrastructure, DNSSEC, WHOIS registration and active threat intelligence. Every indicator you submit returns a calibrated threat score, the supporting evidence, the surrounding infrastructure, and the historical context — in under 300 milliseconds.
What's included in the Sentinel solution:
- 10 enrichment playbooks triggered on demand from any incident or alert: ExplainIP, ExplainDomain, ExplainASN, ExplainNetwork, DiscoverCoHosted, GetInfraChain, GetBgpHistory, GetWhoisHistory, BatchEnrich and CheckAsnReputation.
- 8 scheduled analytic rules that hunt for C2 communication, Tor exit-node traffic, newly registered domains on threat-bearing ASNs, co-hosted malware clusters, ASN reputation degradation, BGP route hijacks, registrar change anomalies and unauthorized SPF includes — all mapped to MITRE ATT&CK.
- 6 hunting queries for external attack-surface discovery, newly registered domain hunting, shared-infrastructure clustering, pivot analysis, domain-to-ASN migration and BGP anomaly investigation.
- 5 workbooks covering External Attack Surface Overview, Infrastructure Threat Landscape, ASN Reputation Monitoring, Domain Registration Anomaly and Incident Enrichment Audit.
- 4 custom Log Analytics tables that retain enrichment outputs for long-term analytics, custom KQL and cross-correlation with your existing logs.
Built for: SOC analysts, threat hunters, detection engineers and security architects running Microsoft Sentinel as their primary SIEM — particularly teams that triage high-volume external-threat alerts and need infrastructure context inside the incident workflow rather than across five external tabs.
How pricing works: The Sentinel solution is published free on Microsoft Sentinel Content Hub. This Marketplace listing activates the paid Whisper Security API tier (Professional, Enterprise or Strategic) that powers the enrichment playbooks at production rate limits, with co-sell support and direct engineering contact from Whisper Security.