Skip to content

Commit 3c4f6fe

Browse files
changes from review
1 parent 8fc3f12 commit 3c4f6fe

File tree

2 files changed

+40
-49
lines changed

2 files changed

+40
-49
lines changed
11.3 KB
Loading

articles/sentinel/sentinel-security-copilot.md

Lines changed: 40 additions & 49 deletions
Original file line numberDiff line numberDiff line change
@@ -23,91 +23,82 @@ Microsoft Copilot for Security is a platform that helps you defend your organiza
2323

2424
Together with the iterative processing of other sophisticated Copilot for Security sources you enable, your Microsoft Sentinel incidents and data provide wider visibility into threats and their context for your organization.
2525

26-
> [!IMPORTANT]
27-
> The "Microsoft Sentinel" and "Natural Language to KQL for Microsoft Sentinel" plugins are currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
28-
>
29-
3026
For more information on Copilot for Security, see the following articles:
31-
- [Get started with Microsoft Copilot for Security](/security-copilot/get-started-security-copilot)
32-
- [Understand authentication in Microsoft Copilot for Security](/security-copilot/authentication)
33-
34-
## Microsoft Sentinel integration with Copilot for Security
35-
36-
Microsoft Sentinel integrates with Copilot for Security in the following ways:
37-
- There are two Copilot for Security plugins, **Microsoft Sentinel (Preview)** and **Natural language to KQL for Microsoft Sentinel (Preview)**.
38-
- Part of the embedded experience of Copilot in Microsoft Defender includes Microsoft Sentinel unified data.
39-
40-
These integration features combined are called, **Copilot in Microsoft Sentinel**.
27+
- [Get started with Microsoft Copilot for Security](/copilot/security/get-started-security-copilot)
28+
- [Understand authentication in Microsoft Copilot for Security](/copilot/security/authentication)
4129

42-
Copilot for Security doesn't have an embedded experience in the Microsoft Sentinel Azure portal or the Microsoft Sentinel section in the Microsoft Defender portal. However, Microsoft Sentinel features are available in the Microsoft Defender portal with the unified security operations platform. So, [Copilot in Microsoft Defender XDR](/defender-xdr/security-copilot-in-microsoft-365-defender) provides some access to Microsoft Sentinel data with its integration experience.
30+
## Integrate Microsoft Sentinel with Copilot for Security
4331

44-
For more information, see [Microsoft Sentinel in the Microsoft Defender portal](microsoft-sentinel-defender-portal.md#new-and-improved-capabilities).
32+
Microsoft Sentinel provides two plugins to integrate with Copilot for Security:
33+
- **Microsoft Sentinel (Preview)**
34+
- **Natural language to KQL for Microsoft Sentinel (Preview)**.
4535

46-
Example: (to be added)
36+
> [!IMPORTANT]
37+
> The "Microsoft Sentinel" and "Natural Language to KQL for Microsoft Sentinel" plugins are currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
38+
>
4739
48-
## Microsoft Sentinel plugins
40+
### Configure a default Microsoft Sentinel workspace
4941

50-
Copilot in Microsoft Sentinel has the following capabilities in the standalone experience.
42+
Increase your prompt accuracy by configuring a Microsoft Sentinel workspace as the default.
5143

52-
From the **Microsoft Sentinel (Preview)** plugin:
53-
- Get Microsoft Sentinel incidents
54-
- List Microsoft Sentinel workspaces
44+
1. Navigate to Copilot for Security at [https://securitycopilot.microsoft.com/](https://securitycopilot.microsoft.com/).
5545

56-
The **Natural language to KQL for Microsoft Sentinel (Preview)** plugin generates and runs KQL hunting queries using Microsoft Sentinel data.
46+
1. Open **Sources** :::image type="icon" source="media/sentinel-security-copilot/sources.png"::: in the prompt bar.
5747

58-
>[!NOTE]
59-
> In the [unified Microsoft Defender portal](/defender-xdr/advanced-hunting-microsoft-defender), you can prompt Copilot for Security to generate advanced hunting queries for both Defender XDR and Microsoft Sentinel tables. Not all Microsoft Sentinel tables are currently supported, but support for these tables can be expected in the future.
48+
1. On the **Manage plugins** page, set the toggle to **On**
6049

61-
To view these capabilities in Copilot, select the **Prompts** :::image type="icon" source="media/sentinel-security-copilot/prompts.png"::: icon in the prompt bar and select **See all system capabilities**. Scroll down to the section for Microsoft Sentinel and Natural language to KQL.
50+
1. Select the gear icon on the Microsoft Sentinel (Preview) plugin.
6251

63-
For more information, see [Copilot for Security in advanced hunting](/defender-xdr/advanced-hunting-security-copilot).
52+
:::image type="content" source="media/sentinel-security-copilot/sentinel-plugins.png" alt-text="Screenshot of the personalization selection gear icon for the Microsoft Sentinel plugin.":::
6453

65-
### Enable the Microsoft Sentinel plugins in Copilot
54+
1. Configure the default workspace name.
6655

67-
1. Navigate to Copilot for Security at [https://securitycopilot.microsoft.com/](https://securitycopilot.microsoft.com/).
56+
:::image type="content" source="media/sentinel-security-copilot/configure-default-sentinel-workspace.png" alt-text="Screenshot of the plugin personalization options for the Microsoft Sentinel plugin.":::
6857

69-
1. Open **Sources** :::image type="icon" source="media/sentinel-security-copilot/sources.png"::: in the prompt bar.
58+
When you create prompts designed to access the other workspaces, specify the workspace name in your prompt.
7059

71-
1. On the **Manage plugins** page, set the **Microsoft Sentinel (Preview)** toggle to **On**.
60+
Example prompt:
7261

73-
1. Optionally, set the **Natural language to KQL for Microsoft Sentinel (Preview)** toggle to **On**.
62+
`What are the top 5 high priority Sentinel incidents in workspace "soc-sentinel-workspace"?`
7463

75-
### Configure a default Microsoft Sentinel workspace
64+
### Integrate Microsoft Sentinel with Copilot in Defender
7665

77-
If you have access to multiple Microsoft Sentinel workspaces, increase your prompt accuracy by configuring one of them as the default.
66+
Use the unified security operations platform with your Microsoft Sentinel data for an embedded Copilot for Security experience. Microsoft Sentinel's new and improved capabilities in the Defender portal allows Copilot in Defender to serve up many of its capabilities with Microsoft Sentinel data.
7867

79-
1. On the **Manage plugins** page, select the gear icon on the Microsoft Sentinel (Preview) plugin.
68+
Example:
8069

81-
:::image type="content" source="media/sentinel-security-copilot/sentinel-plugin.png" alt-text="Screenshot of the personalization selection gear icon for the Microsoft Sentinel plugin.":::
70+
For more information, see the following resources:
8271

83-
1. Configure the default workspace name.
72+
- [Microsoft Sentinel in the Microsoft Defender portal](microsoft-sentinel-defender-portal.md#new-and-improved-capabilities).
73+
- [Copilot in Microsoft Defender XDR](/defender-xdr/security-copilot-in-microsoft-365-defender)
8474

85-
:::image type="content" source="media/sentinel-security-copilot/configure-default-sentinel-workspace.png" alt-text="Screenshot of the plugin personalization options for the Microsoft Sentinel plugin.":::
75+
### Integrate Microsoft Sentinel with Copilot for Security in advanced hunting
8676

87-
1. When you create prompts designed to access the nondefault workspace, specify the workspace ID in your prompt.
77+
The Natural language to KQL for Microsoft Sentinel (Preview) plugin generates and runs KQL hunting queries using Microsoft Sentinel data. This capability is available in the standalone experience and the advanced hunting section of the Microsoft Defender portal.
8878

89-
Example prompt:
79+
> [!NOTE]
80+
> In the unified Microsoft Defender portal, you can prompt Copilot for Security to generate advanced hunting queries for both Defender XDR and Microsoft Sentinel tables. Not all Microsoft Sentinel tables are currently supported, but support for these tables can be expected in the future.
9081
91-
`What are the top 5 high priority Sentinel incidents in workspace "soc-sentinel-workspace"?`
82+
For more information, see [Copilot for Security in advanced hunting](/defender-xdr/advanced-hunting-security-copilot).
9283

93-
### Improve your Microsoft Sentinel prompts
84+
## Improve your Microsoft Sentinel prompts
9485

9586
Consider the **Microsoft Sentinel incident investigation** promptbook as a starting point for creating effective prompts. This promptbook delivers a report about a specific incident, along with related alerts, reputation scores, users, and devices.
9687

97-
| Prompt guidance | prompt |
88+
| Guidance | Prompt |
9889
|---|---|
99-
|Nudge Copilot to provide human readable information instead of responding with object IDs. | `Show me Sentinel incidents that were closed as a false positive. Supply the Incident number, Incident Title, and the time they were created.`|
100-
| Copilot knows who you are. Use the "me" pronoun to find incidents related to you. The following prompt targets incidents assigned to you. | `What Sentinel incidents created in the last 24 hours are assigned to me? List them with highest priority incidents at the top.` |
101-
| When you narrow a prompt response down to a single incident, Copilot knows the context.| `Tell me about the entities associated with that incident.`|
102-
| Copilot is good at summarizing. A useful way to summarize the prompts and responses so far for a specific audience. | `Write an executive report summarizing this investigation. It should be suited for a nontechnical audience.`|
90+
|Nudge Copilot to provide human readable information instead of responding with object IDs. |`Show me Sentinel incidents that were closed as a false positive. Supply the Incident number, Incident Title, and the time they were created.`|
91+
|Copilot knows who you are. Use the "me" pronoun to find incidents related to you. The following prompt targets incidents assigned to you. |`What Sentinel incidents created in the last 24 hours are assigned to me? List them with highest priority incidents at the top.` |
92+
|When you narrow a prompt response down to a single incident, Copilot knows the context.|`Tell me about the entities associated with that incident.`|
93+
|Copilot is good at summarizing. A useful way to summarize the prompts and responses so far for a specific audience. |`Write an executive report summarizing this investigation. It should be suited for a nontechnical audience.`|
10394

10495
For more prompt guidance and samples, see the following resources:
10596

10697
- [Using promptbooks](/copilot/security/using-promptbooks)
107-
- [Prompting in Microsoft Copilot for Security](/security-copilot/prompting-security-copilot)
98+
- [Prompting in Microsoft Copilot for Security](/copilot/security/prompting-security-copilot)
10899
- [Rod Trent's Copilot for Security Prompt Library](https://github.com/rod-trent/Copilot-for-Security/tree/main/Prompts)
109100

110-
### Related articles
101+
## Related articles
111102

112103
- [Microsoft Copilot in Microsoft Defender](/defender-xdr/security-copilot-in-microsoft-365-defender)
113104
- [Microsoft Defender XDR integration with Microsoft Sentinel](microsoft-365-defender-sentinel-integration.md)

0 commit comments

Comments
 (0)