You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/sentinel-security-copilot.md
+40-49Lines changed: 40 additions & 49 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -23,91 +23,82 @@ Microsoft Copilot for Security is a platform that helps you defend your organiza
23
23
24
24
Together with the iterative processing of other sophisticated Copilot for Security sources you enable, your Microsoft Sentinel incidents and data provide wider visibility into threats and their context for your organization.
25
25
26
-
> [!IMPORTANT]
27
-
> The "Microsoft Sentinel" and "Natural Language to KQL for Microsoft Sentinel" plugins are currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
28
-
>
29
-
30
26
For more information on Copilot for Security, see the following articles:
31
-
-[Get started with Microsoft Copilot for Security](/security-copilot/get-started-security-copilot)
32
-
-[Understand authentication in Microsoft Copilot for Security](/security-copilot/authentication)
33
-
34
-
## Microsoft Sentinel integration with Copilot for Security
35
-
36
-
Microsoft Sentinel integrates with Copilot for Security in the following ways:
37
-
- There are two Copilot for Security plugins, **Microsoft Sentinel (Preview)** and **Natural language to KQL for Microsoft Sentinel (Preview)**.
38
-
- Part of the embedded experience of Copilot in Microsoft Defender includes Microsoft Sentinel unified data.
39
-
40
-
These integration features combined are called, **Copilot in Microsoft Sentinel**.
27
+
-[Get started with Microsoft Copilot for Security](/copilot/security/get-started-security-copilot)
28
+
-[Understand authentication in Microsoft Copilot for Security](/copilot/security/authentication)
41
29
42
-
Copilot for Security doesn't have an embedded experience in the Microsoft Sentinel Azure portal or the Microsoft Sentinel section in the Microsoft Defender portal. However, Microsoft Sentinel features are available in the Microsoft Defender portal with the unified security operations platform. So, [Copilot in Microsoft Defender XDR](/defender-xdr/security-copilot-in-microsoft-365-defender) provides some access to Microsoft Sentinel data with its integration experience.
30
+
## Integrate Microsoft Sentinel with Copilot for Security
43
31
44
-
For more information, see [Microsoft Sentinel in the Microsoft Defender portal](microsoft-sentinel-defender-portal.md#new-and-improved-capabilities).
32
+
Microsoft Sentinel provides two plugins to integrate with Copilot for Security:
33
+
-**Microsoft Sentinel (Preview)**
34
+
-**Natural language to KQL for Microsoft Sentinel (Preview)**.
45
35
46
-
Example: (to be added)
36
+
> [!IMPORTANT]
37
+
> The "Microsoft Sentinel" and "Natural Language to KQL for Microsoft Sentinel" plugins are currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
38
+
>
47
39
48
-
##Microsoft Sentinel plugins
40
+
### Configure a default Microsoft Sentinel workspace
49
41
50
-
Copilot in Microsoft Sentinel has the following capabilities in the standalone experience.
42
+
Increase your prompt accuracy by configuring a Microsoft Sentinel workspace as the default.
51
43
52
-
From the **Microsoft Sentinel (Preview)** plugin:
53
-
- Get Microsoft Sentinel incidents
54
-
- List Microsoft Sentinel workspaces
44
+
1. Navigate to Copilot for Security at [https://securitycopilot.microsoft.com/](https://securitycopilot.microsoft.com/).
55
45
56
-
The **Natural language to KQL for Microsoft Sentinel (Preview)**plugin generates and runs KQL hunting queries using Microsoft Sentinel data.
46
+
1. Open **Sources**:::image type="icon" source="media/sentinel-security-copilot/sources.png"::: in the prompt bar.
57
47
58
-
>[!NOTE]
59
-
> In the [unified Microsoft Defender portal](/defender-xdr/advanced-hunting-microsoft-defender), you can prompt Copilot for Security to generate advanced hunting queries for both Defender XDR and Microsoft Sentinel tables. Not all Microsoft Sentinel tables are currently supported, but support for these tables can be expected in the future.
48
+
1. On the **Manage plugins** page, set the toggle to **On**
60
49
61
-
To view these capabilities in Copilot, select the **Prompts** :::image type="icon" source="media/sentinel-security-copilot/prompts.png"::: icon in the prompt bar and select **See all system capabilities**. Scroll down to the section for Microsoft Sentinel and Natural language to KQL.
50
+
1. Select the gear icon on the Microsoft Sentinel (Preview) plugin.
62
51
63
-
For more information, see [Copilot for Security in advanced hunting](/defender-xdr/advanced-hunting-security-copilot).
52
+
:::image type="content" source="media/sentinel-security-copilot/sentinel-plugins.png" alt-text="Screenshot of the personalization selection gear icon for the Microsoft Sentinel plugin.":::
64
53
65
-
### Enable the Microsoft Sentinel plugins in Copilot
54
+
1. Configure the default workspace name.
66
55
67
-
1. Navigate to Copilot for Security at [https://securitycopilot.microsoft.com/](https://securitycopilot.microsoft.com/).
56
+
:::image type="content" source="media/sentinel-security-copilot/configure-default-sentinel-workspace.png" alt-text="Screenshot of the plugin personalization options for the Microsoft Sentinel plugin.":::
68
57
69
-
1. Open **Sources** :::image type="icon" source="media/sentinel-security-copilot/sources.png"::: in the prompt bar.
58
+
When you create prompts designed to access the other workspaces, specify the workspace name in your prompt.
70
59
71
-
1. On the **Manage plugins** page, set the **Microsoft Sentinel (Preview)** toggle to **On**.
60
+
Example prompt:
72
61
73
-
1. Optionally, set the **Natural language to KQL for Microsoft Sentinel (Preview)** toggle to **On**.
62
+
`What are the top 5 high priority Sentinel incidents in workspace "soc-sentinel-workspace"?`
74
63
75
-
### Configure a default Microsoft Sentinel workspace
64
+
### Integrate Microsoft Sentinel with Copilot in Defender
76
65
77
-
If you have access to multiple Microsoft Sentinel workspaces, increase your prompt accuracy by configuring one of them as the default.
66
+
Use the unified security operations platform with your Microsoft Sentinel data for an embedded Copilot for Security experience. Microsoft Sentinel's new and improved capabilities in the Defender portal allows Copilot in Defender to serve up many of its capabilities with Microsoft Sentinel data.
78
67
79
-
1. On the **Manage plugins** page, select the gear icon on the Microsoft Sentinel (Preview) plugin.
68
+
Example:
80
69
81
-
:::image type="content" source="media/sentinel-security-copilot/sentinel-plugin.png" alt-text="Screenshot of the personalization selection gear icon for the Microsoft Sentinel plugin.":::
70
+
For more information, see the following resources:
82
71
83
-
1. Configure the default workspace name.
72
+
-[Microsoft Sentinel in the Microsoft Defender portal](microsoft-sentinel-defender-portal.md#new-and-improved-capabilities).
73
+
-[Copilot in Microsoft Defender XDR](/defender-xdr/security-copilot-in-microsoft-365-defender)
84
74
85
-
:::image type="content" source="media/sentinel-security-copilot/configure-default-sentinel-workspace.png" alt-text="Screenshot of the plugin personalization options for the Microsoft Sentinel plugin.":::
75
+
### Integrate Microsoft Sentinel with Copilot for Security in advanced hunting
86
76
87
-
1. When you create prompts designed to access the nondefault workspace, specify the workspace ID in your prompt.
77
+
The Natural language to KQL for Microsoft Sentinel (Preview) plugin generates and runs KQL hunting queries using Microsoft Sentinel data. This capability is available in the standalone experience and the advanced hunting section of the Microsoft Defender portal.
88
78
89
-
Example prompt:
79
+
> [!NOTE]
80
+
> In the unified Microsoft Defender portal, you can prompt Copilot for Security to generate advanced hunting queries for both Defender XDR and Microsoft Sentinel tables. Not all Microsoft Sentinel tables are currently supported, but support for these tables can be expected in the future.
90
81
91
-
`What are the top 5 high priority Sentinel incidents in workspace "soc-sentinel-workspace"?`
82
+
For more information, see [Copilot for Security in advanced hunting](/defender-xdr/advanced-hunting-security-copilot).
92
83
93
-
###Improve your Microsoft Sentinel prompts
84
+
## Improve your Microsoft Sentinel prompts
94
85
95
86
Consider the **Microsoft Sentinel incident investigation** promptbook as a starting point for creating effective prompts. This promptbook delivers a report about a specific incident, along with related alerts, reputation scores, users, and devices.
96
87
97
-
|Prompt guidance | prompt|
88
+
|Guidance | Prompt|
98
89
|---|---|
99
-
|Nudge Copilot to provide human readable information instead of responding with object IDs. |`Show me Sentinel incidents that were closed as a false positive. Supply the Incident number, Incident Title, and the time they were created.`|
100
-
|Copilot knows who you are. Use the "me" pronoun to find incidents related to you. The following prompt targets incidents assigned to you. |`What Sentinel incidents created in the last 24 hours are assigned to me? List them with highest priority incidents at the top.`|
101
-
|When you narrow a prompt response down to a single incident, Copilot knows the context.|`Tell me about the entities associated with that incident.`|
102
-
|Copilot is good at summarizing. A useful way to summarize the prompts and responses so far for a specific audience. |`Write an executive report summarizing this investigation. It should be suited for a nontechnical audience.`|
90
+
|Nudge Copilot to provide human readable information instead of responding with object IDs. |`Show me Sentinel incidents that were closed as a false positive. Supply the Incident number, Incident Title, and the time they were created.`|
91
+
|Copilot knows who you are. Use the "me" pronoun to find incidents related to you. The following prompt targets incidents assigned to you. |`What Sentinel incidents created in the last 24 hours are assigned to me? List them with highest priority incidents at the top.`|
92
+
|When you narrow a prompt response down to a single incident, Copilot knows the context.|`Tell me about the entities associated with that incident.`|
93
+
|Copilot is good at summarizing. A useful way to summarize the prompts and responses so far for a specific audience. |`Write an executive report summarizing this investigation. It should be suited for a nontechnical audience.`|
103
94
104
95
For more prompt guidance and samples, see the following resources:
0 commit comments