You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender/threat-intelligence/security-copilot-and-defender-threat-intelligence.md
+37-33Lines changed: 37 additions & 33 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,5 +1,5 @@
1
1
---
2
-
title: Microsoft Copilot for Security and Microsoft Defender Threat Intelligence
2
+
title: Microsoft Copilot for Security in Microsoft Defender Threat Intelligence
3
3
description: Learn about Microsoft Defender Threat Intelligence capabilities embedded in Copilot for Security.
4
4
keywords: security copilot, threat intelligence, defender threat intelligence, defender ti, copilot for security, embedded experience, vulnerability impact assessment, threat actor profile, plugins, Microsoft plugins
5
5
ms.service: defender-xdr
@@ -16,28 +16,38 @@ ms.topic: conceptual
16
16
ms.date: 12/04/2023
17
17
---
18
18
19
-
# Microsoft Copilot for Security and Microsoft Defender Threat Intelligence
19
+
# Microsoft Copilot for Security in Microsoft Defender Threat Intelligence
20
20
21
21
>[!IMPORTANT]
22
22
> On June 30, 2024, The Microsoft Defender Threat Intelligence (Defender TI) standalone portal (https://ti.defender.microsoft.com) was retired and is no longer accessible. Customers can continue using Defender TI in the [Microsoft Defender portal](https://aka.ms/mdti-intel-explorer) or with [Microsoft Copilot for Security](security-copilot-and-defender-threat-intelligence.md). [Learn more](https://aka.ms/mdti-standaloneportal)
23
23
24
24
Microsoft Copilot for Security is a cloud-based AI platform that provides natural language copilot experience. It can help support security professionals in different scenarios, like incident response, threat hunting, and intelligence gathering. For more information about what it can do, read [What is Microsoft Copilot for Security?](/security-copilot/microsoft-security-copilot).
25
25
26
-
**Copilot for Security integrates with Microsoft Defender Threat Intelligence**
26
+
Copilot for Security customers gain for each of their authenticated Copilot users access to Microsoft Defender Threat Intelligence (Defender TI). To ensure that you have access to Copilot, see the [Copilot for Security purchase and licensing information](/security-copilot/faq-security-copilot).
27
27
28
-
Copilot for Security delivers information about threat actors, indicators of compromise (IOCs), tools, and vulnerabilities, as well as contextual threat intelligence from Microsoft Defender Threat Intelligence (Defender TI). You can use the prompts and promptbooks to investigate incidents, enrich your hunting flows with threat intelligence information, or gain more knowledge about your organization's or the global threat landscape.
28
+
Once you have access to Copilot for Security, the key features discussed in this article become accessible in either the Copilot for Security portal or the [Microsoft Defender portal](using-copilot-threat-intelligence-defender-xdr.md).
29
29
30
-
This article introduces you to Copilot and includes sample prompts that can help Defender TI users.
31
30
32
31
## Know before you begin
33
32
34
-
- You can use Copilot capabilities to surface threat intelligence in either the [Copilot for Security portal](#using-copilot-for-security-standalone-portal-to-get-threat-intelligence) or the [Microsoft Defender portal](#using-microsoft-copilot-in-defender-to-get-threat-intelligence). [Learn more about Copilot for Security experiences](/security-copilot/experiences-security-copilot)
33
+
If you're new to Copilot for Security, you should familiarize yourself with it by reading these articles:
34
+
35
+
-[What is Microsoft Copilot for Security?](/security-copilot/microsoft-security-copilot)
36
+
-[Microsoft Copilot for Security experiences](/security-copilot/experiences-security-copilot)
37
+
-[Get started with Microsoft Copilot for Security](/security-copilot/get-started-security-copilot)
38
+
-[Understand authentication in Microsoft Copilot for Security](/security-copilot/authentication)
39
+
-[Prompting in Microsoft Copilot for Security](/security-copilot/prompting-security-copilot)
40
+
41
+
## Copilot for Security integration in Defender TI
42
+
43
+
Copilot for Security delivers information about threat actors, indicators of compromise (IOCs), tools, and vulnerabilities, as well as contextual threat intelligence from Defender TI. You can use the prompts and promptbooks to investigate incidents, enrich your hunting flows with threat intelligence information, or gain more knowledge about your organization's or the global threat landscape.
44
+
35
45
- Be clear and specific with your prompts. You might get better results if you include specific threat actor names or IOCs in your prompts. It might also help if you add **threat intelligence** to your prompt, like:
36
46
- Show me threat intelligence data for Aqua Blizzard.
37
47
- Summarize threat intelligence data for "malicious.com."
38
48
- Be specific when referencing an incident (for example, "incident ID 15324").
39
49
- Experiment with different prompts and variations to see what works best for your use case. Chat AI models vary, so iterate and refine your prompts based on the results you receive.
40
-
- Copilot for Security saves your prompt sessions. To see the previous sessions, from the Copilot [Home menu](/security-copilot/navigating-security-copilot#home-menu), go to **My sessions**.
50
+
- Copilot saves your prompt sessions. To see the previous sessions, from the Copilot for Security[Home menu](/security-copilot/navigating-security-copilot#home-menu), go to **My sessions**.
41
51
42
52

43
53
@@ -46,7 +56,22 @@ This article introduces you to Copilot and includes sample prompts that can help
46
56
47
57
[Learn more about creating effective prompts](/security-copilot/prompting-tips)
48
58
49
-
## Using Copilot for Security standalone portal to get threat intelligence
59
+
## Key features
60
+
61
+
Copilot for Security lets security teams understand, prioritize, and take action on threat intelligence information immediately.
62
+
63
+
You can ask about a threat actor, attack campaign, or any other threat intelligence that you want to know more about, and Copilot generates responses based on threat analytics reports, intel profiles and articles, and other Defender TI content.
64
+
65
+
You can also select any of the built-in prompts that are available in the Defender portal to do the following actions:
66
+
67
+
-[Summarize](using-copilot-threat-intelligence-defender-xdr.md#summarize-the-latest-threats-related-to-your-organization) the latest threats related to your organization
68
+
-[Prioritize](using-copilot-threat-intelligence-defender-xdr.md#prioritize-which-threats-to-focus-on) which threats to focus on based on your environment's highest exposure level to these threats
69
+
-[Ask](using-copilot-threat-intelligence-defender-xdr.md#ask-about-the-threat-actors-targeting-the-communications-infrastructure-industry) about the threat actors targeting the communications infrastructure industry
70
+
71
+
[Learn more about using Copilot in Defender for threat intelligence](using-copilot-threat-intelligence-defender-xdr.md)
72
+
73
+
74
+
## Enable the Copilot for Security integration in Defender TI
50
75
51
76
1. Go to [Microsoft Copilot for Security](https://go.microsoft.com/fwlink/?linkid=2247989) and sign in with your credentials.
52
77
2. Make sure that the Defender TI plugin is turned on. In the prompt bar, select the **Sources** icon .
@@ -81,7 +106,7 @@ Copilot also has the following promptbooks that also deliver information from De
81
106
82
107
To view these promptbooks, in the prompt bar, select the **Prompts** icon then select **See all promptbooks**.
83
108
84
-
###Sample prompts for Defender TI
109
+
## Sample Defender TI prompts
85
110
86
111
You can use many prompts to get information from Defender TI. This section lists some ideas and examples.
87
112
@@ -126,38 +151,17 @@ Get contextual information and threat intelligence on Common Vulnerabilities and
126
151
- Show me threat actors associated with CVE-2021-44228.
127
152
- Show me the threat articles associated with CVE-2021-44228.
128
153
129
-
###Provide feedback
154
+
## Provide feedback
130
155
131
-
Your feedback on the Defender TI integration with Copilot for Security helps with development. To provide feedback, in Copilot, select **How's this response?** At the bottom of each completed prompt and choose any of the following options:
156
+
Your feedback on the Defender TI integration in Copilot for Security helps with development. To provide feedback, in Copilot, select **How's this response?** At the bottom of each completed prompt and choose any of the following options:
132
157
-**Looks right** - Select this button if the results are accurate, based on your assessment.
133
158
-**Needs improvement** - Select this button if any detail in the results is incorrect or incomplete, based on your assessment.
134
159
-**Inappropriate** - Select this button if the results contain questionable, ambiguous, or potentially harmful information.
135
160
136
161
For each feedback button, you can provide more information in the next dialog box that appears. Whenever possible, and when the result is **Needs improvement**, write a few words explaining what can be done to improve the outcome. If you entered prompts specific to Defender TI and the results aren't related, then include that information.
137
162
138
-
## Using Microsoft Copilot in Defender to get threat intelligence
139
-
140
-
Copilot for Security customers gain for each of their authenticated Copilot users access to Defender TI within the Microsoft Defender portal. To ensure that you have access to Copilot, see the [Copilot for Security purchase and licensing information](/security-copilot/faq-security-copilot).
141
-
142
-
Once you have access to Copilot for Security, the key features discussed in the next section become accessible in the following *Threat intelligence* sections of the Defender portal:
143
-
- Threat analytics
144
-
- Intel profiles
145
-
- Intel explorer
146
-
- Intel projects
147
-
148
-
### Key features
149
-
150
-
Copilot in Defender brings Copilot for Security's capability to look up threat intelligence into the portal, letting security teams understand, prioritize, and take action on threat intelligence information immediately.
151
-
152
-
You can ask about a threat actor, attack campaign, or any other threat intelligence that you want to know more about, and Copilot generates responses based on threat analytics reports, intel profiles and articles, and other Defender TI content. You can also select any of the available built-in prompts that let you do the following actions:
153
-
154
-
-[Summarize](using-copilot-threat-intelligence-defender-xdr.md#summarize-the-latest-threats-related-to-your-organization) the latest threats related to your organization
155
-
-[Prioritize](using-copilot-threat-intelligence-defender-xdr.md#prioritize-which-threats-to-focus-on) which threats to focus on based on your environment's highest exposure level to these threats
156
-
-[Ask](using-copilot-threat-intelligence-defender-xdr.md#ask-about-the-threat-actors-targeting-the-communications-infrastructure-industry) about the threat actors targeting the communications infrastructure industry
157
-
158
-
[Learn more about using Copilot in Defender for threat intelligence](using-copilot-threat-intelligence-defender-xdr.md)
159
163
160
-
## Data processing and privacy
164
+
## Privacy and data security in Copilot for Security
161
165
162
166
When you interact with Copilot for Security to get Defender TI data, Copilot pulls that data from Defender TI. The prompts, the data retrieved, and the output shown in the prompt results are processed and stored within the Copilot service. [Learn more about privacy and data security in Microsoft Copilot for Security](/security-copilot/privacy-data-security)
Copy file name to clipboardExpand all lines: defender/threat-intelligence/using-copilot-threat-intelligence-defender-xdr.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -49,7 +49,7 @@ You can experience Copilot for Security's capability to look up threat intellige
49
49
:::image type="content" source="/defender/threat-intelligence/media/defender-ti-and-copilot/copilot-defender-side-pane.png" alt-text="Screenshot that shows the Microsoft Defender portal Threat analytics page with the open Microsoft Copilot in Defender side pane highlighted." lightbox="/defender/threat-intelligence/media/defender-ti-and-copilot/copilot-defender-side-pane.png":::
50
50
51
51
You can also reopen Copilot by selecting the **Copilot icon** at the top of the page.
52
-
2. In the Copilot prompt bar, ask about a threat actor, attack campaign, or any other threat intelligence that you want to know more about, then select the **Send message** icon  or press **Enter**. [See sample prompts for Defender TI](security-copilot-and-defender-threat-intelligence.md#sample-prompts-for-defender-ti).
52
+
2. In the Copilot prompt bar, ask about a threat actor, attack campaign, or any other threat intelligence that you want to know more about, then select the **Send message** icon  or press **Enter**. [See sample prompts for Defender TI](security-copilot-and-defender-threat-intelligence.md#sample-defender-ti-prompts).
53
53
54
54
3. Copilot generates a response from your text instruction or question. While Copilot is generating, you can cancel the response by selecting **Stop generating**.
0 commit comments