Skip to content

Commit 2c035ab

Browse files
authored
Merge pull request #1838 from MicrosoftDocs/poliveria-mdti-ignite-draft-11082024
[OOB publish 11/18 @ 10:30 AM PST] MDTI Security Copilot updates for Ignite
2 parents 3f974f8 + c020e5e commit 2c035ab

File tree

4 files changed

+70
-64
lines changed

4 files changed

+70
-64
lines changed
811 Bytes
Loading
13.4 KB
Loading
Lines changed: 56 additions & 50 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
---
2-
title: Microsoft Copilot for Security in Microsoft Defender Threat Intelligence
3-
description: Learn about Microsoft Defender Threat Intelligence capabilities embedded in Copilot for Security.
2+
title: Microsoft Security Copilot in Microsoft Defender Threat Intelligence
3+
description: Learn about Microsoft Defender Threat Intelligence capabilities embedded in Security Copilot.
44
keywords: security copilot, threat intelligence, defender threat intelligence, defender ti, copilot for security, embedded experience, vulnerability impact assessment, threat actor profile, plugins, Microsoft plugins
55
ms.service: defender-xdr
66
ms.author: pauloliveria
@@ -16,52 +16,52 @@ ms.custom:
1616
- cx-ti
1717
- cx-mdti
1818
ms.topic: conceptual
19-
ms.date: 10/18/2024
19+
ms.date: 11/18/2024
2020
---
2121

22-
# Microsoft Copilot for Security in Microsoft Defender Threat Intelligence
22+
# Microsoft Security Copilot in Microsoft Defender Threat Intelligence
2323

2424
>[!IMPORTANT]
25-
> On June 30, 2024, The Microsoft Defender Threat Intelligence (Defender TI) standalone portal (https://ti.defender.microsoft.com) was retired and is no longer accessible. Customers can continue using Defender TI in the [Microsoft Defender portal](https://aka.ms/mdti-intel-explorer) or with [Microsoft Copilot for Security](security-copilot-and-defender-threat-intelligence.md). [Learn more](https://aka.ms/mdti-standaloneportal)
25+
> On June 30, 2024, The Microsoft Defender Threat Intelligence (Defender TI) standalone portal (`https://ti.defender.microsoft.com`) was retired and is no longer accessible. Customers can continue using Defender TI in the [Microsoft Defender portal](https://aka.ms/mdti-intel-explorer) or with [Microsoft Security Copilot](security-copilot-and-defender-threat-intelligence.md). [Learn more](https://aka.ms/mdti-standaloneportal)
2626
27-
Microsoft Copilot for Security is a cloud-based AI platform that provides natural language copilot experience. It can help support security professionals in different scenarios, like incident response, threat hunting, and intelligence gathering. For more information about what it can do, read [What is Microsoft Copilot for Security?](/security-copilot/microsoft-security-copilot).
27+
Microsoft Security Copilot is a cloud-based AI platform that provides natural language copilot experience. It can help support security professionals in different scenarios, like incident response, threat hunting, and intelligence gathering. For more information about what it can do, read [What is Microsoft Security Copilot?](/copilot/security/microsoft-security-copilot).
2828

29-
Copilot for Security customers gain for each of their authenticated Copilot users access to Microsoft Defender Threat Intelligence (Defender TI). To ensure that you have access to Copilot, see the [Copilot for Security purchase and licensing information](/security-copilot/faq-security-copilot).
29+
Security Copilot customers gain for each of their authenticated Copilot users access to Microsoft Defender Threat Intelligence (Defender TI). To ensure that you have access to Copilot, see the [Security Copilot purchase and licensing information](/copilot/security/faq-security-copilot).
3030

31-
Once you have access to Copilot for Security, the key features discussed in this article become accessible in either the Copilot for Security portal or the [Microsoft Defender portal](using-copilot-threat-intelligence-defender-xdr.md).
31+
Once you have access to Security Copilot, the key features discussed in this article become accessible in either the Security Copilot portal or the [Microsoft Defender portal](using-copilot-threat-intelligence-defender-xdr.md).
3232

3333

3434
## Know before you begin
3535

36-
If you're new to Copilot for Security, you should familiarize yourself with it by reading these articles:
36+
If you're new to Security Copilot, you should familiarize yourself with it by reading these articles:
3737

38-
- [What is Microsoft Copilot for Security?](/security-copilot/microsoft-security-copilot)
39-
- [Microsoft Copilot for Security experiences](/security-copilot/experiences-security-copilot)
40-
- [Get started with Microsoft Copilot for Security](/security-copilot/get-started-security-copilot)
41-
- [Understand authentication in Microsoft Copilot for Security](/security-copilot/authentication)
42-
- [Prompting in Microsoft Copilot for Security](/security-copilot/prompting-security-copilot)
38+
- [What is Microsoft Security Copilot?](/copilot/security/microsoft-security-copilot)
39+
- [Microsoft Security Copilot experiences](/copilot/security/experiences-security-copilot)
40+
- [Get started with Microsoft Security Copilot](/copilot/security/get-started-security-copilot)
41+
- [Understand authentication in Microsoft Security Copilot](/copilot/security/authentication)
42+
- [Prompting in Microsoft Security Copilot](/copilot/security/prompting-security-copilot)
4343

44-
## Copilot for Security integration in Defender TI
44+
## Security Copilot integration in Defender TI
4545

46-
Copilot for Security delivers information about threat actors, indicators of compromise (IOCs), tools, and vulnerabilities, as well as contextual threat intelligence from Defender TI. You can use the prompts and promptbooks to investigate incidents, enrich your hunting flows with threat intelligence information, or gain more knowledge about your organization's or the global threat landscape.
46+
Security Copilot delivers information about threat actors, indicators of compromise (IOCs), tools, and vulnerabilities, as well as contextual threat intelligence from Defender TI. You can use the prompts and promptbooks to investigate incidents, enrich your hunting flows with threat intelligence information, or gain more knowledge about your organization's or the global threat landscape.
4747

4848
- Be clear and specific with your prompts. You might get better results if you include specific threat actor names or IOCs in your prompts. It might also help if you add **threat intelligence** to your prompt, like:
4949
- Show me threat intelligence data for Aqua Blizzard.
5050
- Summarize threat intelligence data for "malicious.com."
5151
- Be specific when referencing an incident (for example, "incident ID 15324").
5252
- Experiment with different prompts and variations to see what works best for your use case. Chat AI models vary, so iterate and refine your prompts based on the results you receive.
53-
- Copilot saves your prompt sessions. To see the previous sessions, from the Copilot for Security [Home menu](/security-copilot/navigating-security-copilot#home-menu), go to **My sessions**.
53+
- Copilot saves your prompt sessions. To see the previous sessions, from the Security Copilot [Home menu](/copilot/security/navigating-security-copilot#home-menu), go to **My sessions**.
5454

55-
![Screenshot that shows the Microsoft Copilot for Security Home menu with My sessions highlighted.](/defender/threat-intelligence/media/defender-ti-and-copilot/copilot-my-sessions.png)
55+
![Screenshot that shows the Microsoft Security Copilot Home menu with My sessions highlighted.](/defender/threat-intelligence/media/defender-ti-and-copilot/copilot-my-sessions.png)
5656

5757
> [!NOTE]
58-
> For a walkthrough on Copilot, including the pin and share feature, read [Navigate Microsoft Copilot for Security](/security-copilot/navigating-security-copilot).
58+
> For a walkthrough on Copilot, including the pin and share feature, read [Navigate Microsoft Security Copilot](/copilot/security/navigating-security-copilot).
5959
60-
[Learn more about creating effective prompts](/security-copilot/prompting-tips)
60+
[Learn more about creating effective prompts](/copilot/security/prompting-tips)
6161

6262
## Key features
6363

64-
Copilot for Security lets security teams understand, prioritize, and take action on threat intelligence information immediately.
64+
Security Copilot lets security teams understand, prioritize, and take action on threat intelligence information immediately.
6565

6666
You can ask about a threat actor, attack campaign, or any other threat intelligence that you want to know more about, and Copilot generates responses based on threat analytics reports, intel profiles and articles, and other Defender TI content.
6767

@@ -74,46 +74,48 @@ You can also select any of the built-in prompts that are available in the Defend
7474
[Learn more about using Copilot in Defender for threat intelligence](using-copilot-threat-intelligence-defender-xdr.md)
7575

7676

77-
## Enable the Copilot for Security integration in Defender TI
77+
## Turn on the Security Copilot integration in Defender TI
7878

79-
1. Go to [Microsoft Copilot for Security](https://go.microsoft.com/fwlink/?linkid=2247989) and sign in with your credentials.
79+
1. Go to [Microsoft Security Copilot](https://securitycopilot.microsoft.com/) and sign in with your credentials.
8080
2. Make sure that the Defender TI plugin is turned on. In the prompt bar, select the **Sources** icon ![Screenshot of the Sources icon.](/defender/threat-intelligence/media/defender-ti-and-copilot/copilot-sources-icon.png).
8181

82-
![Screenshot of the prompt bar in Microsoft Copilot for Security with the Sources icon highlighted.](media/defender-ti-and-copilot/copilot-prompts-bar-sources.png)
82+
![Screenshot of the prompt bar in Microsoft Security Copilot with the Sources icon highlighted.](media/defender-ti-and-copilot/copilot-prompts-bar-sources.png)
8383

8484
In the **Manage sources** pop-up window that appears, under **Plugins**, confirm that the **Microsoft Threat Intelligence** toggle is turned on, then close the window.
8585

8686
![Screenshot of the Manage plugins pop-up window with the Microsoft Threat Intelligence plugin highlighted.](media/defender-ti-and-copilot/copilot-manage-plugins.png)
8787

8888
> [!NOTE]
89-
> Some roles can turn the toggle on or off for plugins like Defender TI. For more information, read [Manage plugins in Microsoft Copilot for Security](/security-copilot/manage-plugins).
89+
> Some roles can turn the toggle on or off for plugins like Defender TI. For more information, read [Manage plugins in Microsoft Security Copilot](/copilot/security/manage-plugins).
9090

9191

9292
3. Enter your prompt in the prompt bar.
9393

9494
### Built-in system features
9595

96-
Copilot for Security has built-in system features that can get data from the different plugins that are turned on.
96+
Security Copilot has built-in system features that can get data from the different plugins that are turned on.
9797

9898
To view the list of built-in system capabilities for Defender TI:
9999

100100
1. In the prompt bar, select the **Prompts** icon ![Screenshot of the prompts icon.](/defender/threat-intelligence/media/defender-ti-and-copilot/copilot-prompts-icon.png).
101101

102-
![Screenshot of the prompt bar in Microsoft Copilot for Security with the Prompts icon highlighted.](media/defender-ti-and-copilot/copilot-prompts-bar-prompts.png)
102+
![Screenshot of the prompt bar in Microsoft Security Copilot with the Prompts icon highlighted.](media/defender-ti-and-copilot/copilot-prompts-bar-prompts.png)
103103

104-
2. Select **See all system capabilities**. The *Microsoft Defender Threat Intelligence* section lists all the available capabilities for Defender TI that you can use.
104+
2. Select **See all system capabilities**. The *Microsoft Threat Intelligence* section lists all the available capabilities for Defender TI that you can use.
105105

106106
Copilot also has the following promptbooks that also deliver information from Defender TI:
107-
- **Threat actor profile** – Generates a report profiling a known threat actor, including suggestions to defend against their common tools and tactics.
108-
- **Vulnerability impact assessment** – Generates a report summarizing the intelligence for a known vulnerability, including steps on how to address it.
107+
- [**Check impact of an external threat article**](/copilot/security/using-promptbooks#check-impact-of-an-external-threat-article) – Analyzes an external or third-party (that is, not published in Defender TI) article to extract related IOCs, summarize the intelligence, and generate hunting queries so you can assess the potential impact of the threat reported in the article to your organization.
108+
- [**Threat actor profile**](/copilot/security/using-promptbooks#threat-actor-profile) – Generates a report profiling a known threat actor, including suggestions to defend against their common tools and tactics.
109+
- [**Threat Intelligence 360 report based on MDTI article**](/copilot/security/using-promptbooks#threat-intelligence-360-report-based-on-mdti-article) – Analyzes a [Defender TI article](what-is-microsoft-defender-threat-intelligence-defender-ti.md#articles) to extract related IOCs, summarize the intelligence, and generate hunting queries so you can assess the potential impact of the threat reported in the article to your organization.
110+
- [**Vulnerability impact assessment**](/copilot/security/using-promptbooks#vulnerability-impact-assessment) – Generates a report summarizing the intelligence for a known vulnerability, including steps on how to address it.
109111

110112
To view these promptbooks, in the prompt bar, select the **Prompts** icon then select **See all promptbooks**.
111113

112114
## Sample Defender TI prompts
113115

114116
You can use many prompts to get information from Defender TI. This section lists some ideas and examples.
115117

116-
#### General information about threat intelligence trends
118+
### General information about threat intelligence trends
117119

118120
Get threat intelligence from threat articles and threat actors.
119121

@@ -123,16 +125,7 @@ Get threat intelligence from threat articles and threat actors.
123125
- Show me the latest threat articles.
124126
- Get threat articles related to ransomware in the last six months.
125127

126-
#### IP address and host contextual information in relation to threat intelligence
127-
128-
Get information on datasets associated with IP addresses and hosts, such as ports, reputation scores, components, certificates, cookies, services, and host pairs.
129-
130-
**Sample prompts**:
131-
132-
- Show me the reputation of the host _\<host name\>_.
133-
- Get resolutions for IP address _\<IP address\>_.
134-
135-
#### Threat actor mapping and infrastructure
128+
### Threat actor mapping and infrastructure
136129
Get information on threat actors and the tactics, techniques, and procedures (TTPs), sponsored states, industries, and IOCs associated with them.
137130

138131
**Sample prompts**:
@@ -142,9 +135,9 @@ Get information on threat actors and the tactics, techniques, and procedures (TT
142135
- Share the TTPs associated with Silk Typhoon.
143136
- Share threat actors associated with Russia.
144137

145-
#### Vulnerability data by CVE
138+
### Vulnerability data by CVE
146139

147-
Get contextual information and threat intelligence on Common Vulnerabilities and Exposures (CVEs).
140+
Get contextual information and threat intelligence on Common Vulnerabilities and Exposures (CVEs), which are derived from Defender TI articles, [threat analytics reports](/defender-xdr/threat-analytics), and data from [Microsoft Defender Vulnerability Management](/defender-vulnerability-management/defender-vulnerability-management) and [Microsoft Defender Endpoint Attack Surface Management](/azure/external-attack-surface-management/overview).
148141

149142
**Sample prompts**:
150143

@@ -154,22 +147,35 @@ Get contextual information and threat intelligence on Common Vulnerabilities and
154147
- Show me threat actors associated with CVE-2021-44228.
155148
- Show me the threat articles associated with CVE-2021-44228.
156149

150+
### Indicator data in relation to threat intelligence
151+
152+
Get detailed information about an indicator (for example, IP addresses, domains, and file hashes) based on the numerous [data sets](data-sets.md) available in Defender TI, including reputation scores, WHOIS information, domain name system (DNS), host pairs, and certificates.
153+
154+
**Sample prompts**:
155+
156+
- What can you tell me about the domain _\<domain name\>_?
157+
- Show me indicators related to _\<domain name\>_.
158+
- Show me all resolutions for _\<domain name\>_.
159+
- Show me host pairs related to _\<domain name\>_.
160+
- Show me the reputation of the host _\<host name\>_.
161+
- Show me all resolutions for IP address _\<IP address\>_.
162+
- Show me the open services in _\<IP address\>_.
163+
157164
## Provide feedback
158165

159-
Your feedback on the Defender TI integration in Copilot for Security helps with development. To provide feedback, in Copilot, select **How's this response?** At the bottom of each completed prompt and choose any of the following options:
166+
Your feedback on the Defender TI integration in Security Copilot helps with development. To provide feedback, in Copilot, select **How's this response?** At the bottom of each completed prompt and choose any of the following options:
160167
- **Looks right** - Select this button if the results are accurate, based on your assessment.
161168
- **Needs improvement** - Select this button if any detail in the results is incorrect or incomplete, based on your assessment.
162169
- **Inappropriate** - Select this button if the results contain questionable, ambiguous, or potentially harmful information.
163170

164171
For each feedback button, you can provide more information in the next dialog box that appears. Whenever possible, and when the result is **Needs improvement**, write a few words explaining what can be done to improve the outcome. If you entered prompts specific to Defender TI and the results aren't related, then include that information.
165172

173+
## Privacy and data security in Security Copilot
166174

167-
## Privacy and data security in Copilot for Security
168-
169-
When you interact with Copilot for Security to get Defender TI data, Copilot pulls that data from Defender TI. The prompts, the data retrieved, and the output shown in the prompt results are processed and stored within the Copilot service. [Learn more about privacy and data security in Microsoft Copilot for Security](/security-copilot/privacy-data-security)
175+
When you interact with Security Copilot to get Defender TI data, Copilot pulls that data from Defender TI. The prompts, the data retrieved, and the output shown in the prompt results are processed and stored within the Copilot service. [Learn more about privacy and data security in Microsoft Security Copilot](/copilot/security/privacy-data-security)
170176

171177
### See also
172178

173-
- [What is Microsoft Copilot for Security?](/security-copilot/microsoft-security-copilot)
174-
- [Privacy and data security in Microsoft Copilot for Security](/security-copilot/privacy-data-security)
175-
- [Using Microsoft Copilot for Security for threat intelligence](using-copilot-threat-intelligence-defender-xdr.md)
179+
- [What is Microsoft Security Copilot?](/copilot/security/microsoft-security-copilot)
180+
- [Privacy and data security in Microsoft Security Copilot](/copilot/security/privacy-data-security)
181+
- [Using Microsoft Security Copilot for threat intelligence](using-copilot-threat-intelligence-defender-xdr.md)

0 commit comments

Comments
 (0)