Skip to content

Commit 46786a0

Browse files
Merge pull request #4908 from MicrosoftDocs/main
[AutoPublish] main to live - 09/03 01:33 PDT | 09/03 14:03 IST
2 parents 586836d + 10a3c58 commit 46786a0

File tree

1 file changed

+6
-6
lines changed

1 file changed

+6
-6
lines changed

defender-xdr/security-copilot-m365d-incident-summary.md

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,7 @@ appliesto:
2828

2929
[!INCLUDE [Microsoft Defender XDR rebranding](../includes/microsoft-defender.md)]
3030

31-
Microsoft Defender XDR applies the capabilities of [Security Copilot](/security-copilot/microsoft-security-copilot) to summarize incidents, delivering impactful information and insights to simplify investigation tasks. Attack investigation is a crucial step for incident response teams to successfully defend an organization against further damage from a cyber threat. Investigations can often be time-consuming as it involves numerous steps. Incident response teams need to understand how the attack happened: sort through numerous alerts, identify which assets and entities are involved, and assess the scope and impact of an attack.
31+
Microsoft Defender XDR applies the capabilities of [Security Copilot](/security-copilot/microsoft-security-copilot) to summarize incidents, delivering impactful information and insights to simplify investigation tasks. Attack investigation is a crucial step for incident response teams to successfully defend an organization against further damage from a cyber threat. Investigations can often be time-consuming as they involve numerous steps. Incident response teams need to understand how the attack happened: sort through numerous alerts, identify which assets and entities are involved, and assess the scope and impact of an attack.
3232

3333
This guide outlines what to expect and how to access the summarizing capability of Copilot in Defender, including information on providing feedback.
3434

@@ -58,24 +58,24 @@ Incidents containing up to 100 alerts can be summarized into one incident summar
5858
- The entity or asset where the attack started.
5959
- A summary of timelines of how the attack unfolded.
6060
- The assets involved in the attack.
61-
- Suggested prompts, which provide insights into the specific assets involved in the incident.
6261
- Indicators of compromise (IoCs).
6362
- Names of [threat actors](/unified-secops-platform/microsoft-threat-actor-naming) involved.
63+
- Suggested Security Copilot prompts, which guide you to focus on the most relevant next steps, gain deeper insights, and simplify investigations.
6464

65-
To summarize an incident, perform the following steps:
65+
To summarize an incident:
6666

6767
1. Open an incident page. Copilot automatically creates an incident summary upon opening the page. You can stop the summary creation by selecting **Cancel** or restart creation by selecting **Regenerate**.
6868

69-
1. The incident summary card loads on the Copilot pane. Review the generated summary on the card.
69+
1. The incident summary card loads on the Copilot pane. Review the generated summary on the card. Review the summary and use the information to guide your investigation and response to the incident.
7070

7171
:::image type="content" source="/defender/media/copilot-in-defender/incident-summary/copilot-defender-incident-summary.png" alt-text="Screenshot that shows the incident summary card on the Copilot pane as seen in the Microsoft Defender incident page." lightbox="/defender/media/copilot-in-defender/incident-summary/copilot-defender-incident-summary.png":::
7272

7373
> [!TIP]
7474
> You can navigate to a file, IP, or URL page from the Copilot results pane by clicking on the evidence in the results.
7575
76-
1. Review the summary and use the information to guide your investigation and response to the incident.
76+
1. Select **See prompts** to view suggested prompts. Suggested prompts surface relevant follow-up questions based on the most crucial information in the given incident.
7777

78-
1. Select **See prompts** to get more insights about the specific assets involved in the incident, such as device summaries, identity summaries, and related threat intelligence.
78+
Select a suggested prompt to get more insights about the specific assets involved in the incident, such as device summaries, identity summaries, and related threat intelligence.
7979

8080
:::image type="content" source="/defender/media/copilot-in-defender/incident-summary/copilot-defender-incident-summary-see-prompts.png" lightbox="/defender/media/copilot-in-defender/incident-summary/copilot-defender-incident-summary-see-prompts-large.png" alt-text="Screenshot that shows the Copilot suggested prompts on the incident summary card.":::
8181

0 commit comments

Comments
 (0)