Skip to content

Commit b2f8157

Browse files
Update easm-copilot.md
1 parent 93f6303 commit b2f8157

File tree

1 file changed

+22
-3
lines changed

1 file changed

+22
-3
lines changed

articles/external-attack-surface-management/easm-copilot.md

Lines changed: 22 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -17,6 +17,7 @@ ms.localizationpriority: high
1717
> [!IMPORTANT]
1818
> The information in this article applies to the Microsoft Security Copilot Early Access Program, which is an invite-only paid preview program. Some information in this article relates to prereleased product, which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided in this article.
1919
20+
2021
Security Copilot is a cloud-based AI platform that provides a natural language copilot experience. It can help support security professionals in different scenarios, like incident response, threat hunting, and intelligence gathering. For more information about what it can do, go to [What is Microsoft Security Copilot?](/security-copilot/microsoft-security-copilot).
2122

2223
**Security Copilot integrates with Defender EASM**.
@@ -25,8 +26,12 @@ Security Copilot can surface insights from Defender EASM about an organization's
2526

2627
This article introduces you to Security Copilot and includes sample prompts that can help Defender EASM users.
2728

29+
30+
2831
## Know before you begin
2932

33+
- Ensure that you reference the company name in your first prompt. Unless otherwise specified, all future prompts will provide data about the initially specified company.
34+
3035
- Be clear and specific with your prompts. You might get better results if you include specific asset names or metadata values (e.g. CVE IDs) in your prompts.
3136

3237
It might also help to add **Defender EASM** to your prompt, like:
@@ -38,13 +43,15 @@ This article introduces you to Security Copilot and includes sample prompts that
3843

3944
- Security Copilot saves your prompt sessions. To see the previous sessions, in Security Copilot, go to the menu > **My investigations**:
4045

41-
![Screenshot that shows the Microsoft Security Copilot menu and My investigations with previous sessions.](media/copilot-1.png)
46+
![Screenshot that shows the Microsoft Security Copilot menu and My investigations with previous sessions.](media/copilot-1.png)
4247

4348

4449
For a walkthrough on Security Copilot, including the pin and share feature, go to [Navigating Microsoft Security Copilot](/security-copilot/navigating-security-copilot).
4550

4651
For more information on writing Security Copilot prompts, go to [Microsoft Security Copilot prompting tips](/security-copilot/prompting-tips).
4752

53+
54+
4855
## Open Security Copilot
4956

5057
1. Go to [Microsoft Security Copilot](https://go.microsoft.com/fwlink/?linkid=2247989) and sign in with your credentials.
@@ -60,6 +67,8 @@ For more information on writing Security Copilot prompts, go to [Microsoft Secur
6067
6168
3. Enter your prompt.
6269

70+
71+
6372
## Built-in system features
6473

6574
In Security Copilot, there are built in system features. These features can get data from the different plugins that are enabled.
@@ -78,6 +87,8 @@ To view the list of built-in system capabilities for Defender EASM, use the foll
7887
- Get expired SSL certificates.
7988
- Get SHA1 certificates.
8089

90+
91+
8192
## Sample prompts for Defender EASM?
8293

8394
There are many prompts you can use to get information about your Defender EASM data. This section lists some ideas and examples.
@@ -92,6 +103,7 @@ Get **general information** about your Defender EASM data, like an attack surfac
92103
- What are the high priority attack surface insights for my organization?
93104

94105

106+
95107
### CVE vulnerability data
96108

97109
Get details on **CVEs that are applicable to your inventory**.
@@ -102,6 +114,8 @@ Get details on **CVEs that are applicable to your inventory**.
102114
- Get assets affected by high priority CVSS's in my attack surface.
103115
- How many assets have critical CVSS's for my organization?
104116

117+
118+
105119
### Domain and SSL certificate posture
106120

107121
Get information about **domain and SSL certificate posture**, like expired domains and usage of SHA1 certificates.
@@ -113,11 +127,12 @@ Get information about **domain and SSL certificate posture**, like expired domai
113127
- How many assets are using SSL SHA1 for my organization?
114128
- Get list of expired SSL certificates.
115129

130+
131+
116132
## Provide feedback
117133

118-
Your feedback on the Defender EASM integration with Security Copilot helps with development. To provide feedback, in Security Copilot, use the feedback buttons at the bottom of each completed prompt:
134+
Your feedback on the Defender EASM integration with Security Copilot helps with development. To provide feedback, in Security Copilot, use the feedback buttons at the bottom of each completed prompt. Your options are "Looks Right," "Needs Improvement" and "Inappropriate."
119135

120-
![Screenshot that shows how to submit feedback on the prompt results in Microsoft Security Copilot.](media/copilot-3.png)
121136

122137
Your options:
123138

@@ -127,12 +142,16 @@ Your options:
127142

128143
Whenever possible, and when the result is **Off-target**, write a few words explaining what can be done to improve the outcome. If you entered Defender EASM-specific prompts and the results aren't EASM related, then include that information.
129144

145+
146+
130147
## Data processing and privacy
131148

132149
When you interact with the Security Copilot to get Defender EASM data, Security Copilot pulls that data from Defender EASM. The prompts, the data that's retrieved, and the output shown in the prompt results is processed and stored within the Security Copilot service.
133150

134151
For more information about data privacy in Security Copilot, go to [Privacy and data security in Microsoft Security Copilot](/security-copilot/privacy-data-security).
135152

153+
154+
136155
## Related articles
137156

138157
- [What is Microsoft Security Copilot?](/security-copilot/microsoft-security-copilot)

0 commit comments

Comments
 (0)