Skip to content

Commit 21d8b94

Browse files
authored
Merge pull request #1604 from MicrosoftDocs/poliveria-mdti-copilot-update-10162024
updated outline/organization
2 parents 3b47b4d + 745d6a7 commit 21d8b94

File tree

2 files changed

+38
-34
lines changed

2 files changed

+38
-34
lines changed

defender/threat-intelligence/security-copilot-and-defender-threat-intelligence.md

Lines changed: 37 additions & 33 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
---
2-
title: Microsoft Copilot for Security and Microsoft Defender Threat Intelligence
2+
title: Microsoft Copilot for Security in Microsoft Defender Threat Intelligence
33
description: Learn about Microsoft Defender Threat Intelligence capabilities embedded in Copilot for Security.
44
keywords: security copilot, threat intelligence, defender threat intelligence, defender ti, copilot for security, embedded experience, vulnerability impact assessment, threat actor profile, plugins, Microsoft plugins
55
ms.service: defender-xdr
@@ -16,28 +16,38 @@ ms.topic: conceptual
1616
ms.date: 12/04/2023
1717
---
1818

19-
# Microsoft Copilot for Security and Microsoft Defender Threat Intelligence
19+
# Microsoft Copilot for Security in Microsoft Defender Threat Intelligence
2020

2121
>[!IMPORTANT]
2222
> On June 30, 2024, The Microsoft Defender Threat Intelligence (Defender TI) standalone portal (https://ti.defender.microsoft.com) was retired and is no longer accessible. Customers can continue using Defender TI in the [Microsoft Defender portal](https://aka.ms/mdti-intel-explorer) or with [Microsoft Copilot for Security](security-copilot-and-defender-threat-intelligence.md). [Learn more](https://aka.ms/mdti-standaloneportal)
2323
2424
Microsoft Copilot for Security is a cloud-based AI platform that provides natural language copilot experience. It can help support security professionals in different scenarios, like incident response, threat hunting, and intelligence gathering. For more information about what it can do, read [What is Microsoft Copilot for Security?](/security-copilot/microsoft-security-copilot).
2525

26-
**Copilot for Security integrates with Microsoft Defender Threat Intelligence**
26+
Copilot for Security customers gain for each of their authenticated Copilot users access to Microsoft Defender Threat Intelligence (Defender TI). To ensure that you have access to Copilot, see the [Copilot for Security purchase and licensing information](/security-copilot/faq-security-copilot).
2727

28-
Copilot for Security delivers information about threat actors, indicators of compromise (IOCs), tools, and vulnerabilities, as well as contextual threat intelligence from Microsoft Defender Threat Intelligence (Defender TI). You can use the prompts and promptbooks to investigate incidents, enrich your hunting flows with threat intelligence information, or gain more knowledge about your organization's or the global threat landscape.
28+
Once you have access to Copilot for Security, the key features discussed in this article become accessible in either the Copilot for Security portal or the [Microsoft Defender portal](using-copilot-threat-intelligence-defender-xdr.md).
2929

30-
This article introduces you to Copilot and includes sample prompts that can help Defender TI users.
3130

3231
## Know before you begin
3332

34-
- You can use Copilot capabilities to surface threat intelligence in either the [Copilot for Security portal](#using-copilot-for-security-standalone-portal-to-get-threat-intelligence) or the [Microsoft Defender portal](#using-microsoft-copilot-in-defender-to-get-threat-intelligence). [Learn more about Copilot for Security experiences](/security-copilot/experiences-security-copilot)
33+
If you're new to Copilot for Security, you should familiarize yourself with it by reading these articles:
34+
35+
- [What is Microsoft Copilot for Security?](/security-copilot/microsoft-security-copilot)
36+
- [Microsoft Copilot for Security experiences](/security-copilot/experiences-security-copilot)
37+
- [Get started with Microsoft Copilot for Security](/security-copilot/get-started-security-copilot)
38+
- [Understand authentication in Microsoft Copilot for Security](/security-copilot/authentication)
39+
- [Prompting in Microsoft Copilot for Security](/security-copilot/prompting-security-copilot)
40+
41+
## Copilot for Security integration in Defender TI
42+
43+
Copilot for Security delivers information about threat actors, indicators of compromise (IOCs), tools, and vulnerabilities, as well as contextual threat intelligence from Defender TI. You can use the prompts and promptbooks to investigate incidents, enrich your hunting flows with threat intelligence information, or gain more knowledge about your organization's or the global threat landscape.
44+
3545
- Be clear and specific with your prompts. You might get better results if you include specific threat actor names or IOCs in your prompts. It might also help if you add **threat intelligence** to your prompt, like:
3646
- Show me threat intelligence data for Aqua Blizzard.
3747
- Summarize threat intelligence data for "malicious.com."
3848
- Be specific when referencing an incident (for example, "incident ID 15324").
3949
- Experiment with different prompts and variations to see what works best for your use case. Chat AI models vary, so iterate and refine your prompts based on the results you receive.
40-
- Copilot for Security saves your prompt sessions. To see the previous sessions, from the Copilot [Home menu](/security-copilot/navigating-security-copilot#home-menu), go to **My sessions**.
50+
- Copilot saves your prompt sessions. To see the previous sessions, from the Copilot for Security [Home menu](/security-copilot/navigating-security-copilot#home-menu), go to **My sessions**.
4151

4252
![Screenshot that shows the Microsoft Copilot for Security Home menu with My sessions highlighted.](/defender/threat-intelligence/media/defender-ti-and-copilot/copilot-my-sessions.png)
4353

@@ -46,7 +56,22 @@ This article introduces you to Copilot and includes sample prompts that can help
4656
4757
[Learn more about creating effective prompts](/security-copilot/prompting-tips)
4858

49-
## Using Copilot for Security standalone portal to get threat intelligence
59+
## Key features
60+
61+
Copilot for Security lets security teams understand, prioritize, and take action on threat intelligence information immediately.
62+
63+
You can ask about a threat actor, attack campaign, or any other threat intelligence that you want to know more about, and Copilot generates responses based on threat analytics reports, intel profiles and articles, and other Defender TI content.
64+
65+
You can also select any of the built-in prompts that are available in the Defender portal to do the following actions:
66+
67+
- [Summarize](using-copilot-threat-intelligence-defender-xdr.md#summarize-the-latest-threats-related-to-your-organization) the latest threats related to your organization
68+
- [Prioritize](using-copilot-threat-intelligence-defender-xdr.md#prioritize-which-threats-to-focus-on) which threats to focus on based on your environment's highest exposure level to these threats
69+
- [Ask](using-copilot-threat-intelligence-defender-xdr.md#ask-about-the-threat-actors-targeting-the-communications-infrastructure-industry) about the threat actors targeting the communications infrastructure industry
70+
71+
[Learn more about using Copilot in Defender for threat intelligence](using-copilot-threat-intelligence-defender-xdr.md)
72+
73+
74+
## Enable the Copilot for Security integration in Defender TI
5075

5176
1. Go to [Microsoft Copilot for Security](https://go.microsoft.com/fwlink/?linkid=2247989) and sign in with your credentials.
5277
2. Make sure that the Defender TI plugin is turned on. In the prompt bar, select the **Sources** icon ![Screenshot of the Sources icon.](/defender/threat-intelligence/media/defender-ti-and-copilot/copilot-sources-icon.png).
@@ -81,7 +106,7 @@ Copilot also has the following promptbooks that also deliver information from De
81106

82107
To view these promptbooks, in the prompt bar, select the **Prompts** icon then select **See all promptbooks**.
83108

84-
### Sample prompts for Defender TI
109+
## Sample Defender TI prompts
85110

86111
You can use many prompts to get information from Defender TI. This section lists some ideas and examples.
87112

@@ -126,38 +151,17 @@ Get contextual information and threat intelligence on Common Vulnerabilities and
126151
- Show me threat actors associated with CVE-2021-44228.
127152
- Show me the threat articles associated with CVE-2021-44228.
128153

129-
### Provide feedback
154+
## Provide feedback
130155

131-
Your feedback on the Defender TI integration with Copilot for Security helps with development. To provide feedback, in Copilot, select **How's this response?** At the bottom of each completed prompt and choose any of the following options:
156+
Your feedback on the Defender TI integration in Copilot for Security helps with development. To provide feedback, in Copilot, select **How's this response?** At the bottom of each completed prompt and choose any of the following options:
132157
- **Looks right** - Select this button if the results are accurate, based on your assessment.
133158
- **Needs improvement** - Select this button if any detail in the results is incorrect or incomplete, based on your assessment.
134159
- **Inappropriate** - Select this button if the results contain questionable, ambiguous, or potentially harmful information.
135160

136161
For each feedback button, you can provide more information in the next dialog box that appears. Whenever possible, and when the result is **Needs improvement**, write a few words explaining what can be done to improve the outcome. If you entered prompts specific to Defender TI and the results aren't related, then include that information.
137162

138-
## Using Microsoft Copilot in Defender to get threat intelligence
139-
140-
Copilot for Security customers gain for each of their authenticated Copilot users access to Defender TI within the Microsoft Defender portal. To ensure that you have access to Copilot, see the [Copilot for Security purchase and licensing information](/security-copilot/faq-security-copilot).
141-
142-
Once you have access to Copilot for Security, the key features discussed in the next section become accessible in the following *Threat intelligence* sections of the Defender portal:
143-
- Threat analytics
144-
- Intel profiles
145-
- Intel explorer
146-
- Intel projects
147-
148-
### Key features
149-
150-
Copilot in Defender brings Copilot for Security's capability to look up threat intelligence into the portal, letting security teams understand, prioritize, and take action on threat intelligence information immediately.
151-
152-
You can ask about a threat actor, attack campaign, or any other threat intelligence that you want to know more about, and Copilot generates responses based on threat analytics reports, intel profiles and articles, and other Defender TI content. You can also select any of the available built-in prompts that let you do the following actions:
153-
154-
- [Summarize](using-copilot-threat-intelligence-defender-xdr.md#summarize-the-latest-threats-related-to-your-organization) the latest threats related to your organization
155-
- [Prioritize](using-copilot-threat-intelligence-defender-xdr.md#prioritize-which-threats-to-focus-on) which threats to focus on based on your environment's highest exposure level to these threats
156-
- [Ask](using-copilot-threat-intelligence-defender-xdr.md#ask-about-the-threat-actors-targeting-the-communications-infrastructure-industry) about the threat actors targeting the communications infrastructure industry
157-
158-
[Learn more about using Copilot in Defender for threat intelligence](using-copilot-threat-intelligence-defender-xdr.md)
159163

160-
## Data processing and privacy
164+
## Privacy and data security in Copilot for Security
161165

162166
When you interact with Copilot for Security to get Defender TI data, Copilot pulls that data from Defender TI. The prompts, the data retrieved, and the output shown in the prompt results are processed and stored within the Copilot service. [Learn more about privacy and data security in Microsoft Copilot for Security](/security-copilot/privacy-data-security)
163167

defender/threat-intelligence/using-copilot-threat-intelligence-defender-xdr.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -49,7 +49,7 @@ You can experience Copilot for Security's capability to look up threat intellige
4949
:::image type="content" source="/defender/threat-intelligence/media/defender-ti-and-copilot/copilot-defender-side-pane.png" alt-text="Screenshot that shows the Microsoft Defender portal Threat analytics page with the open Microsoft Copilot in Defender side pane highlighted." lightbox="/defender/threat-intelligence/media/defender-ti-and-copilot/copilot-defender-side-pane.png":::
5050

5151
You can also reopen Copilot by selecting the **Copilot icon** ![Screenshot that shows the Copilot icon in the Microsoft Defender portal.](media/defender-ti-and-copilot/copilot-defender-icon.png) at the top of the page.
52-
2. In the Copilot prompt bar, ask about a threat actor, attack campaign, or any other threat intelligence that you want to know more about, then select the **Send message** icon ![Screenshot that shows the Send message icon in Copilot in Defender.](media/defender-ti-and-copilot/copilot-defender-arrow.png) or press **Enter**. [See sample prompts for Defender TI](security-copilot-and-defender-threat-intelligence.md#sample-prompts-for-defender-ti).
52+
2. In the Copilot prompt bar, ask about a threat actor, attack campaign, or any other threat intelligence that you want to know more about, then select the **Send message** icon ![Screenshot that shows the Send message icon in Copilot in Defender.](media/defender-ti-and-copilot/copilot-defender-arrow.png) or press **Enter**. [See sample prompts for Defender TI](security-copilot-and-defender-threat-intelligence.md#sample-defender-ti-prompts).
5353

5454
3. Copilot generates a response from your text instruction or question. While Copilot is generating, you can cancel the response by selecting **Stop generating**.
5555

0 commit comments

Comments
 (0)