Skip to content

Commit f065633

Browse files
committed
Review
1 parent e54d58e commit f065633

File tree

1 file changed

+14
-34
lines changed

1 file changed

+14
-34
lines changed

articles/sentinel/sentinel-security-copilot-incident-summary.md

Lines changed: 14 additions & 34 deletions
Original file line numberDiff line numberDiff line change
@@ -11,17 +11,23 @@ audience: ITPro
1111
ms.topic: conceptual
1212
appliesto:
1313
- Microsoft Sentinel in the Azure portal
14+
- Microsoft Sentinel in the Defender portal
1415
- Security Copilot
1516
ms.date: 04/22/2025
1617
#Customer intent: As a security analyst, I want to integrate Security Copilot with Microsoft Sentinel data so that I can investigate incidents and generate advanced hunting queries at machine speed and scale.
1718
---
1819

1920
# Summarize Microsoft Sentinel incidents with Security Copilot
2021

21-
Microsoft Sentinel applies the capabilities of [Security Copilot](/security-copilot/microsoft-security-copilot) in the Azure portal to create enriched summaries of incidents, providing a comprehensive overview of security incidents by consolidating information from multiple alerts. This feature enhances incident response efficiency by offering a clear summary that helps security teams quickly understand the scope and impact of an incident. It provides a structured overview, including timelines, assets involved, and indicators of compromise, along with enrichments like user risk, device risk, and watchlist matching. These summaries suggest an investigation path for incident response teams to assess the scope and impact of an attack.
22+
Microsoft Sentinel applies the capabilities of [Security Copilot](/security-copilot/microsoft-security-copilot) in the Azure portal to create enriched summaries of incidents, providing a comprehensive overview of security incidents by consolidating information from multiple alerts. This feature enhances incident response efficiency by offering a clear summary that helps your security operations teams quickly understand the scope and impact of an incident. It provides a structured overview, including timelines, assets involved, and indicators of compromise, along with enrichments like user risk, device risk, and watchlist matching. These summaries suggest an investigation path for your analysts to assess the scope and impact of an attack. For more information, see [Navigate, triage, and manage Microsoft Sentinel incidents in the Azure portal](incident-navigate-triage.md).
23+
24+
If you onboarded Microsoft Sentinel to the Defender portal, you can move directly to the same incident in the Defender portal and follow the guided investigation procedures there. For more information, see [Triage and investigate incidents with guided responses from Security Copilot in Microsoft Defender](/defender-xdr/security-copilot-m365d-guided-response).
2225

2326
This guide outlines what to expect and how to access the summarizing capability of Copilot in Microsoft Sentinel, including information on providing feedback.
2427

28+
> [!IMPORTANT]
29+
> The Copilot incident summary feature for Microsoft Sentinel is currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
30+
2531
## Know before you begin
2632

2733
If you're new to Security Copilot, you should familiarize yourself with it by reading these articles:
@@ -35,7 +41,7 @@ If you're new to Security Copilot, you should familiarize yourself with it by re
3541

3642
The incident summary capability is available in Microsoft Sentinel in the Azure portal for customers who have provisioned access to Security Copilot.
3743

38-
This capability is also available in the Security Copilot standalone experience through the Microsoft Sentinel plugins. Know more about [preinstalled plugins in Security Copilot](/security-copilot/manage-plugins#preinstalled-plugins).
44+
This capability is also available in the Defender portal, and in the Security Copilot standalone experience through the Microsoft Sentinel plugins. Know more about [preinstalled plugins in Security Copilot](/security-copilot/manage-plugins#preinstalled-plugins).
3945

4046
## Key features
4147

@@ -47,44 +53,18 @@ Incidents containing up to 100 alerts can be summarized into one incident summar
4753
- The assets involved in the attack.
4854
- Indicators of compromise (IoCs).
4955
- Names of [threat actors](/unified-secops-platform/microsoft-threat-actor-naming) involved.
56+
- User risk and criticality.
57+
- Device risk and criticality.
58+
- Watchlist matches.
5059

51-
To summarize an incident, perform the following steps:
52-
53-
1. Open an incident page. Copilot automatically creates an incident summary upon opening the page. You can stop the summary creation by selecting **Cancel** or restart creation by selecting **Regenerate**.
54-
55-
1. The incident summary appears on the details pane of the incident page (in place of the description). Review the generated summary on the details pane.
60+
Copilot automatically generates an incident summary when you open the incident's page. The incident summary appears at the top of the details pane of the incident page, before the description.
5661

57-
:::image type="content" source="/defender/media/copilot-in-defender/incident-summary/copilot-defender-incident-summary-small.png" alt-text="Screenshot that shows the incident summary card on the Copilot pane as seen in the Microsoft Defender incident page." lightbox="/defender/media/copilot-in-defender/incident-summary/copilot-defender-incident-summary.png":::
62+
:::image type="content" source="media/sentinel-security-copilot-incident-summary/copilot-sentinel-incident-summary.png" alt-text="Screenshot that shows the Copilot-generated incident summary on the details pane of the Microsoft Sentinel incident page." lightbox="media/sentinel-security-copilot-incident-summary/copilot-sentinel-incident-summary.png":::
5863

5964
> [!TIP]
6065
> You can navigate to a file, IP, or URL page from the Copilot results pane by clicking on the evidence in the results.
6166
62-
1. **RELEVANT??? - YL**
63-
Select the **More actions** ellipsis (...) at the top of the incident summary card to copy or regenerate the summary, or view the summary in the Security Copilot portal. Selecting **Open in Security Copilot** opens a new tab to the Security Copilot standalone portal where you can input prompts and access other plugins.
64-
65-
:::image type="content" source="/defender/media/copilot-in-defender/incident-summary/incident-summary-options.png" alt-text="Screenshot that shows the actions available on the incident summary card.":::
66-
67-
1. Review the summary and use the information to guide your investigation and response to the incident.
68-
69-
> [!IMPORTANT]
70-
> The Copilot incident summary feature for Microsoft Sentinel is currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
71-
72-
## Sample incident summary prompt
73-
74-
**RELEVANT??? - YL**
75-
76-
In the Security Copilot standalone portal, you can use the following prompt to generate incident summaries:
77-
78-
- *Provide a summary for Microsoft Sentinel incident {incident ID}.*
79-
80-
> [!TIP]
81-
> When generating an incident summary in the Security Copilot portal, Microsoft recommends including the word ***Defender*** in your prompts to ensure that the incident summary capability delivers the results.
82-
83-
## Provide feedback
84-
85-
Microsoft highly encourages you to provide feedback to Copilot, as it's crucial for a capability's continuous improvement. You can provide feedback on the summary by selecting the feedback icon ![Screenshot of the feedback icon for Copilot in Defender cards](/defender/media/copilot-in-defender/copilot-defender-feedback.png) found on the bottom of the Copilot pane.
86-
87-
**HOW TO ADAPT FOR SENTINEL? --YL**
67+
Review the summary and use the information to guide your investigation and response to the incident.
8868

8969
## See also
9070

0 commit comments

Comments
 (0)