Skip to content

Commit 8b3f7dc

Browse files
committed
suggested prompts in incident summaries
1 parent d62a93f commit 8b3f7dc

File tree

3 files changed

+11
-5
lines changed

3 files changed

+11
-5
lines changed

defender-xdr/security-copilot-in-microsoft-365-defender.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -61,7 +61,7 @@ Enable security teams to tackle attack investigations in a timely manner with ea
6161

6262
#### Summarize incidents quickly
6363

64-
Investigating incidents with multiple alerts can be a daunting task. To immediately understand an incident, you can tap Copilot to [summarize an incident](security-copilot-m365d-incident-summary.md) for you. Copilot creates an overview of the attack. The overview contains essential information for you to understand what transpired in the attack, what assets are involved, and the timeline of the attack. Copilot automatically creates a summary when you navigate to an incident's page.
64+
Investigating incidents with multiple alerts can be a daunting task. To immediately understand an incident, you can tap Copilot to [summarize an incident](security-copilot-m365d-incident-summary.md) for you. Copilot creates an overview of the attack. The overview contains essential information for you to understand what transpired in the attack, what assets are involved, and the timeline of the attack. Copilot automatically creates a summary when you navigate to an incident's page. It also helps you dig deeper and determine whether an incident requires further action by suggesting prompts about specific assets involved in the attack, such as devices, identities, and IPs.
6565

6666
:::image type="content" source="/defender/media/copilot-in-defender/incident-summary/copilot-defender-incident-summary-small.png" alt-text="Screenshot of the incident summary card on the Copilot pane as seen in the Microsoft Defender incident page." lightbox="/defender/media/copilot-in-defender/incident-summary/copilot-defender-incident-summary.png":::
6767

defender-xdr/security-copilot-m365d-incident-summary.md

Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -58,25 +58,28 @@ Incidents containing up to 100 alerts can be summarized into one incident summar
5858
- The entity or asset where the attack started.
5959
- A summary of timelines of how the attack unfolded.
6060
- The assets involved in the attack.
61+
- Suggested prompts, which provide insights into the specific assets involved in the incident.
6162
- Indicators of compromise (IoCs).
6263
- Names of [threat actors](/unified-secops-platform/microsoft-threat-actor-naming) involved.
6364

6465
To summarize an incident, perform the following steps:
6566

6667
1. Open an incident page. Copilot automatically creates an incident summary upon opening the page. You can stop the summary creation by selecting **Cancel** or restart creation by selecting **Regenerate**.
6768

68-
2. The incident summary card loads on the Copilot pane. Review the generated summary on the card.
69+
1. The incident summary card loads on the Copilot pane. Review the generated summary on the card.
6970

7071
:::image type="content" source="/defender/media/copilot-in-defender/incident-summary/copilot-defender-incident-summary-small.png" alt-text="Screenshot that shows the incident summary card on the Copilot pane as seen in the Microsoft Defender incident page." lightbox="/defender/media/copilot-in-defender/incident-summary/copilot-defender-incident-summary.png":::
7172

7273
> [!TIP]
7374
> You can navigate to a file, IP, or URL page from the Copilot results pane by clicking on the evidence in the results.
7475
75-
3. Select the **More actions** ellipsis (...) at the top of the incident summary card to copy or regenerate the summary, or view the summary in the Security Copilot portal. Selecting **Open in Security Copilot** opens a new tab to the Security Copilot standalone portal where you can input prompts and access other plugins.
76+
1. Review the summary and use the information to guide your investigation and response to the incident.
7677

77-
:::image type="content" source="/defender/media/copilot-in-defender/incident-summary/incident-summary-options.png" alt-text="Screenshot that shows the actions available on the incident summary card.":::
78+
1. Select **Suggested prompts** to get more insights about the specific assets involved in the incident, such as device summaries, identity summaries, and related threat intelligence.
79+
80+
1. Select the **More actions** ellipsis (...) at the top of the incident summary card to copy or regenerate the summary, or view the summary in the Security Copilot portal. Selecting **Open in Security Copilot** opens a new tab to the Security Copilot standalone portal where you can input prompts and access other plugins.
7881

79-
4. Review the summary and use the information to guide your investigation and response to the incident.
82+
:::image type="content" source="/defender/media/copilot-in-defender/incident-summary/incident-summary-options.png" alt-text="Screenshot that shows the actions available on the incident summary card.":::
8083

8184
## Sample incident summary prompt
8285

defender-xdr/whats-new.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -32,6 +32,9 @@ For more information on what's new with other Microsoft Defender security produc
3232

3333
You can also get product updates and important notifications through the [message center](https://admin.microsoft.com/Adminportal/Home#/MessageCenter).
3434

35+
## June 2025
36+
37+
- (Preview) Microsoft Copilot now provides suggested prompts as part of incident summaries in the Microsoft Defender portal. Suggested prompts help you get more insights into the specific assets involved in the incident. For more information, see [Summarize incidents with Microsoft Copilot in Microsoft Defender](security-copilot-m365d-incident-summary.md).
3538

3639
## May 2025
3740
- (Preview) In advanced hunting, you can now [view all your user-defined rules](custom-detection-manage.md)—both custom detection rules and analytics rules—in the **Detection rules** page. This feature also brings the following improvements:

0 commit comments

Comments
 (0)