You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/sentinel-security-copilot-incident-summary.md
+14-34Lines changed: 14 additions & 34 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -11,17 +11,23 @@ audience: ITPro
11
11
ms.topic: conceptual
12
12
appliesto:
13
13
- Microsoft Sentinel in the Azure portal
14
+
- Microsoft Sentinel in the Defender portal
14
15
- Security Copilot
15
16
ms.date: 04/22/2025
16
17
#Customer intent: As a security analyst, I want to integrate Security Copilot with Microsoft Sentinel data so that I can investigate incidents and generate advanced hunting queries at machine speed and scale.
17
18
---
18
19
19
20
# Summarize Microsoft Sentinel incidents with Security Copilot
20
21
21
-
Microsoft Sentinel applies the capabilities of [Security Copilot](/security-copilot/microsoft-security-copilot) in the Azure portal to create enriched summaries of incidents, providing a comprehensive overview of security incidents by consolidating information from multiple alerts. This feature enhances incident response efficiency by offering a clear summary that helps security teams quickly understand the scope and impact of an incident. It provides a structured overview, including timelines, assets involved, and indicators of compromise, along with enrichments like user risk, device risk, and watchlist matching. These summaries suggest an investigation path for incident response teams to assess the scope and impact of an attack.
22
+
Microsoft Sentinel applies the capabilities of [Security Copilot](/security-copilot/microsoft-security-copilot) in the Azure portal to create enriched summaries of incidents, providing a comprehensive overview of security incidents by consolidating information from multiple alerts. This feature enhances incident response efficiency by offering a clear summary that helps your security operations teams quickly understand the scope and impact of an incident. It provides a structured overview, including timelines, assets involved, and indicators of compromise, along with enrichments like user risk, device risk, and watchlist matching. These summaries suggest an investigation path for your analysts to assess the scope and impact of an attack. For more information, see [Navigate, triage, and manage Microsoft Sentinel incidents in the Azure portal](incident-navigate-triage.md).
23
+
24
+
If you onboarded Microsoft Sentinel to the Defender portal, you can move directly to the same incident in the Defender portal and follow the guided investigation procedures there. For more information, see [Triage and investigate incidents with guided responses from Security Copilot in Microsoft Defender](/defender-xdr/security-copilot-m365d-guided-response).
22
25
23
26
This guide outlines what to expect and how to access the summarizing capability of Copilot in Microsoft Sentinel, including information on providing feedback.
24
27
28
+
> [!IMPORTANT]
29
+
> The Copilot incident summary feature for Microsoft Sentinel is currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
30
+
25
31
## Know before you begin
26
32
27
33
If you're new to Security Copilot, you should familiarize yourself with it by reading these articles:
@@ -35,7 +41,7 @@ If you're new to Security Copilot, you should familiarize yourself with it by re
35
41
36
42
The incident summary capability is available in Microsoft Sentinel in the Azure portal for customers who have provisioned access to Security Copilot.
37
43
38
-
This capability is also available in the Security Copilot standalone experience through the Microsoft Sentinel plugins. Know more about [preinstalled plugins in Security Copilot](/security-copilot/manage-plugins#preinstalled-plugins).
44
+
This capability is also available in the Defender portal, and in the Security Copilot standalone experience through the Microsoft Sentinel plugins. Know more about [preinstalled plugins in Security Copilot](/security-copilot/manage-plugins#preinstalled-plugins).
39
45
40
46
## Key features
41
47
@@ -47,44 +53,18 @@ Incidents containing up to 100 alerts can be summarized into one incident summar
47
53
- The assets involved in the attack.
48
54
- Indicators of compromise (IoCs).
49
55
- Names of [threat actors](/unified-secops-platform/microsoft-threat-actor-naming) involved.
56
+
- User risk and criticality.
57
+
- Device risk and criticality.
58
+
- Watchlist matches.
50
59
51
-
To summarize an incident, perform the following steps:
52
-
53
-
1. Open an incident page. Copilot automatically creates an incident summary upon opening the page. You can stop the summary creation by selecting **Cancel** or restart creation by selecting **Regenerate**.
54
-
55
-
1. The incident summary appears on the details pane of the incident page (in place of the description). Review the generated summary on the details pane.
60
+
Copilot automatically generates an incident summary when you open the incident's page. The incident summary appears at the top of the details pane of the incident page, before the description.
56
61
57
-
:::image type="content" source="/defender/media/copilot-in-defender/incident-summary/copilot-defender-incident-summary-small.png" alt-text="Screenshot that shows the incident summary card on the Copilot pane as seen in the Microsoft Defender incident page." lightbox="/defender/media/copilot-in-defender/incident-summary/copilot-defender-incident-summary.png":::
62
+
:::image type="content" source="media/sentinel-security-copilot-incident-summary/copilot-sentinel-incident-summary.png" alt-text="Screenshot that shows the Copilot-generated incident summary on the details pane of the Microsoft Sentinel incident page." lightbox="media/sentinel-security-copilot-incident-summary/copilot-sentinel-incident-summary.png":::
58
63
59
64
> [!TIP]
60
65
> You can navigate to a file, IP, or URL page from the Copilot results pane by clicking on the evidence in the results.
61
66
62
-
1.**RELEVANT??? - YL**
63
-
Select the **More actions** ellipsis (...) at the top of the incident summary card to copy or regenerate the summary, or view the summary in the Security Copilot portal. Selecting **Open in Security Copilot** opens a new tab to the Security Copilot standalone portal where you can input prompts and access other plugins.
64
-
65
-
:::image type="content" source="/defender/media/copilot-in-defender/incident-summary/incident-summary-options.png" alt-text="Screenshot that shows the actions available on the incident summary card.":::
66
-
67
-
1. Review the summary and use the information to guide your investigation and response to the incident.
68
-
69
-
> [!IMPORTANT]
70
-
> The Copilot incident summary feature for Microsoft Sentinel is currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
71
-
72
-
## Sample incident summary prompt
73
-
74
-
**RELEVANT??? - YL**
75
-
76
-
In the Security Copilot standalone portal, you can use the following prompt to generate incident summaries:
77
-
78
-
-*Provide a summary for Microsoft Sentinel incident {incident ID}.*
79
-
80
-
> [!TIP]
81
-
> When generating an incident summary in the Security Copilot portal, Microsoft recommends including the word ***Defender*** in your prompts to ensure that the incident summary capability delivers the results.
82
-
83
-
## Provide feedback
84
-
85
-
Microsoft highly encourages you to provide feedback to Copilot, as it's crucial for a capability's continuous improvement. You can provide feedback on the summary by selecting the feedback icon  found on the bottom of the Copilot pane.
86
-
87
-
**HOW TO ADAPT FOR SENTINEL? --YL**
67
+
Review the summary and use the information to guide your investigation and response to the incident.
0 commit comments