Skip to content

Commit a910b5f

Browse files
authored
Merge pull request #1562 from MicrosoftDocs/diannegali-updatecopilotoverview
updated text flow
2 parents 50056bd + 9bd2855 commit a910b5f

File tree

5 files changed

+51
-22
lines changed

5 files changed

+51
-22
lines changed

defender-xdr/security-copilot-in-microsoft-365-defender.md

Lines changed: 51 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ ms.topic: conceptual
1818
search.appverid:
1919
- MOE150
2020
- MET150
21-
ms.date: 09/23/2024
21+
ms.date: 10/10/2024
2222
appliesto:
2323
- Microsoft Defender XDR
2424
- Microsoft Sentinel in the Microsoft Defender portal
@@ -31,87 +31,109 @@ appliesto:
3131
> [!NOTE]
3232
> Microsoft Defender XDR provides a unified XDR experience for Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Office 365, Microsoft Defender for Cloud Apps, and Microsoft Defender for Vulnerability Management. Learn more about this pre- and post-breach defense suite in [What is Microsoft Defender XDR?](microsoft-365-defender.md)
3333
34-
[Microsoft Copilot for Security](/security-copilot/microsoft-security-copilot) brings together the power of AI and human expertise to help security teams respond to attacks faster and more effectively. Copilot for Security is embedded in the Microsoft Defender portal to enable security teams to efficiently summarize incidents, analyze scripts and codes, analyze files, summarize device information, use guided responses to resolve incidents, generate KQL queries, and create incident reports.
34+
This article provides an overview for users of Microsoft Copilot in Microsoft Defender, including steps to access, key capabilities, and links to the details of these capabilities.
3535

36-
This article provides an overview for users of the Copilot in Defender, including steps to access, key capabilities, and links to the details of these capabilities.
36+
## Know before you begin
3737

38-
<a name='access-security-copilot-in-microsoft-365-defender'></a>
38+
If you're new to Copilot for Security, you should familiarize yourself with it by reading the following articles:
3939

40-
## Access Copilot in Defender
40+
- [What is Copilot for Security?](/security-copilot/microsoft-security-copilot)
41+
- [Copilot for Security experiences](/security-copilot/experiences-security-copilot)
42+
- [Get started with Copilot for Security](/security-copilot/get-started-security-copilot)
43+
- [Understand authentication in Copilot for Security](/security-copilot/authentication)
44+
- [Prompting in Copilot for Security](/security-copilot/prompting-security-copilot)
4145

42-
To ensure that you have access to Copilot in Defender, see the [Copilot for Security purchase and licensing information](/security-copilot/faq-security-copilot). Once you have access to Copilot for Security, the key capabilities discussed below become accessible in the Microsoft Defender portal.
46+
## Microsoft Copilot integration in Microsoft Defender
4347

44-
## Investigate and respond to incidents like an expert
48+
[Microsoft Copilot for Security](/security-copilot/microsoft-security-copilot) brings together the power of AI and human expertise to help security teams respond to attacks faster and more effectively. Copilot for Security is embedded in the Microsoft Defender portal to help provide security teams with enhanced capabilities to investigate and respond to incidents, hunt for threats, and protect their organization with relevant threat intelligence. Copilot in Defender is available to users who have provisioned access to Copilot for Security.
49+
50+
## Key features
51+
52+
### Investigate and respond to incidents like an expert
4553

4654
Enable security teams to tackle attack investigations in a timely manner with ease and precision. Copilot helps teams to understand attacks immediately, quickly analyze suspicious files and scripts, and promptly assess and apply appropriate mitigation to stop and contain attacks.
4755

48-
### Summarize incidents quickly
56+
#### Summarize incidents quickly
4957

5058
Investigating incidents with multiple alerts can be a daunting task. To immediately understand an incident, you can tap Copilot to [summarize an incident](security-copilot-m365d-incident-summary.md) for you. Copilot creates an overview of the attack. The overview contains essential information for you to understand what transpired in the attack, what assets are involved, and the timeline of the attack. Copilot automatically creates a summary when you navigate to an incident's page.
5159

5260
:::image type="content" source="/defender/media/copilot-in-defender/incident-summary/copilot-defender-incident-summary-small.png" alt-text="Screenshot of the incident summary card on the Copilot pane as seen in the Microsoft Defender incident page." lightbox="/defender/media/copilot-in-defender/incident-summary/copilot-defender-incident-summary.png":::
5361

54-
### Take action on incidents through guided responses
62+
#### Take action on incidents through guided responses
5563

5664
Resolving incidents require analysts to have an understanding of an attack to know what solutions are appropriate. Copilot recommends solutions through [guided responses](security-copilot-m365d-guided-response.md) that are specific to each incident.
5765

5866
:::image type="content" source="/defender/media/copilot-in-defender/guided-response/copilot-defender-guided-response-small.png" alt-text="Screenshot highlighting the Copilot pane with the guided responses in the Microsoft Defender incident page." lightbox="/defender/media/copilot-in-defender/guided-response/copilot-defender-guided-response.png":::
5967

60-
### Run script analysis with ease
68+
#### Run script analysis with ease
6169

6270
Most attackers rely on sophisticated malware when launching attacks to avoid detection and analysis. These malware are usually obfuscated, and might be in the form of scripts or command lines in PowerShell. Copilot can quickly [analyze scripts](security-copilot-m365d-script-analysis.md), reducing the time for investigation.
6371

6472
:::image type="content" source="/defender/media/copilot-in-defender/script-analyzer/copilot-defender-script-analysis-incident-small.png" alt-text="Screenshot highlighting the script analysis button in the attack story view in the incident page." lightbox="/defender/media/copilot-in-defender/script-analyzer/copilot-defender-script-analysis-incident.png":::
6573

66-
### Generate device summaries
74+
#### Generate device summaries
6775

6876
Investigating devices involved in incidents can be a tasking job. To quickly assess a device, Copilot can [summarize a device's information](copilot-in-defender-device-summary.md), including the device's security posture, any unusual behaviors, a list of vulnerable software, and relevant Microsoft Intune information.
6977

7078
:::image type="content" source="/defender/media/copilot-in-defender/device-summary/copilot-defender-device-summary-device-page-small.png" alt-text="Screenshot of the device summary results in Copilot in Defender." lightbox="/defender/media/copilot-in-defender/device-summary/copilot-defender-device-summary-device-page.png":::
7179

72-
### Analyze files promptly
80+
#### Analyze files promptly
7381

7482
Copilot helps security teams quickly assess and understand suspicious files with [file analysis](copilot-in-defender-file-analysis.md). Copilot provides a file's summary, including detection information, related file certificates, a list of API calls, and strings found in the file.
7583

7684
:::image type="content" source="/defender/media/copilot-in-defender/file-analysis/copilot-defender-file-analysis-hide-small.png" alt-text="Screenshot of the file analysis results in Copilot in Defender with the Hide details option highlighted." lightbox="/defender/media/copilot-in-defender/file-analysis/copilot-defender-file-analysis-hide.png":::
7785

78-
### Investigate identities immediately
86+
#### Investigate identities immediately
7987

8088
Quickly assess a user’s risk by generating an [identity summary](security-copilot-defender-identity-summary.md) with Copilot. Identify when an identity is at risk or suspicious with contextualized information about a user’s role and role changes, sign in behaviors, devices signed in to, and relevant contact information.
8189

8290
:::image type="content" source="/defender/media/copilot-in-defender/identity-summary/identity-incident-graph-small.png" alt-text="Screenshot showing the Summarize option in the user details pane." lightbox="/defender/media/copilot-in-defender/identity-summary/identity-incident-graph.png":::
8391

84-
### Write incident reports efficiently
92+
#### Write incident reports efficiently
8593

8694
Security operations teams usually write reports to record important information, including what response actions were taken and the corresponding results, the team members involved, and other information to aid future security decisions and learning. Oftentimes, documenting incidents can be time-consuming. For an incident report to be effective, it must contain an incident's summary along with the actions taken, including what actions were taken by whom and when. Copilot [generates an incident report](security-copilot-m365d-create-incident-report.md) by quickly consolidating these pieces of information.
8795

8896
:::image type="content" source="/defender/media/copilot-in-defender/create-report/incident-report-main1-small.png" alt-text="Screenshot of the incident report card in the incident page showing the top half of the card." lightbox="/defender/media/copilot-in-defender/create-report/incident-report-main1.png":::
8997

90-
## Hunt like a pro
98+
### Hunt like a pro
9199

92100
Copilot in Defender helps security teams proactively hunt for threats in their network by quickly building appropriate KQL queries.
93101

94-
### Generate KQL queries from natural-language input
102+
#### Generate KQL queries from natural-language input
95103

96104
Security teams who use advanced hunting to proactively hunt for threats in their network can now use a query assistant that converts any natural-language question, in the context of threat hunting, into a ready-to-run KQL query. The query assistant saves security teams time by generating a KQL query that can then be automatically run or further tweaked according to the analyst needs. Read more about the query assistant in [Copilot for Security in advanced hunting](advanced-hunting-security-copilot.md).
97105

98106
:::image type="content" source="/defender/media/advanced-hunting-security-copilot-pane.png" alt-text="Screenshot of the Copilot pane in advanced hunting." lightbox="/defender/media/advanced-hunting-security-copilot-pane-big.png":::
99107

100-
## Protect your organization with relevant threat intelligence
108+
### Protect your organization with relevant threat intelligence
101109

102110
Empower your security organization to make informed decisions with the latest threat intelligence. Copilot consolidates and summarizes threat intelligence to help security teams prioritize and respond to threats effectively.
103111

104-
### Monitor threat intelligence
112+
#### Monitor threat intelligence
105113

106114
Ask Copilot to summarize the relevant threats impacting your environment, to prioritize resolving threats based on your exposure levels, or to find threat actors that might be targeting your industry. Read more about [Copilot for Security in threat intelligence](/defender/threat-intelligence/using-copilot-threat-intelligence-defender-xdr).
107115

108116
:::image type="content" source="/defender/media/copilot-in-defender/TI/copilot-defender-threat-intel-small.png" alt-text="Screenshot of the Copilot pane in threat intelligence in Defender XDR." lightbox="/defender/media/copilot-in-defender/TI/copilot-defender-threat-intel-full.png":::
109117

110-
## Data security and feedback in Copilot
118+
<a name='access-security-copilot-in-microsoft-365-defender'></a>
111119

112-
Copilot continuously evolves using [data](/security-copilot/privacy-data-security#customer-data-and-system-generated-logs) that is [stored](/security-copilot/privacy-data-security#customer-data-storage-location), [processed](/security-copilot/privacy-data-security#location-for-prompt-evaluation), and [shared](/security-copilot/privacy-data-security#customer-data-sharing-preferences) depending on the settings defined by your administrator. Microsoft ensures that your data is always protected and secure when using Copilot. To learn more about data security and privacy in Copilot, see [Privacy and data security in Copilot](/security-copilot/privacy-data-security).
120+
## Access Copilot in Defender
113121

114-
Because of its continuing evolution, Copilot might miss some things. Reviewing and [providing feedback](/security-copilot/rai-faqs-security-copilot#what-are-the-limitations-of-security-copilot-how-can-users-minimize-the-impact-of-security-copilots-limitations-when-using-the-system) about the results helps improve Copilot's future responses.
122+
To ensure that you have access to Copilot in Defender, see the [Copilot for Security purchase and licensing information](/security-copilot/faq-security-copilot). Once you have access to Copilot for Security, the key features become available in the Microsoft Defender portal.
123+
124+
## Sample Copilot in Defender prompts
125+
126+
In the Microsoft Defender portal, Copilot in Defender provides prompts to help you navigate and use some of the capabilities of Copilot. The prompts are designed to help you understand the capabilities of Copilot and how to use them effectively. Here are some examples of prompts you might see in the Microsoft Defender portal:
127+
128+
Advanced hunting prompts:
129+
130+
:::image type="content" source="/defender/media/copilot-in-defender/sample-prompt-adv-hunting-small.png" alt-text="Screenshot highlighting the Copilot prompts in the advanced hunting page." lightbox="/defender/media/copilot-in-defender/sample-prompt-adv-hunting.png":::
131+
132+
Threat intelligence prompts:
133+
134+
:::image type="content" source="/defender/media/copilot-in-defender/sample-prompt-threat-intel-small.png" alt-text="Screenshot highlighting the Copilot prompts in the threat intelligence page." lightbox="/defender/media/copilot-in-defender/sample-prompt-threat-intel.png":::
135+
136+
## Provide feedback
115137

116138
All Copilot in Defender capabilities have an option for providing feedback. To provide feedback, perform the following steps:
117139

@@ -120,6 +142,12 @@ All Copilot in Defender capabilities have an option for providing feedback. To p
120142
3. Select **Needs improvement** if you assessed the result as lacking or incomplete. You can provide more information about your assessment in the next dialog box and submit this assessment to Microsoft.
121143
4. You can also report the results if it contains questionable or ambiguous information by selecting **Inappropriate**. Provide more information about the results in the next dialog box and select Submit.
122144

145+
## Privacy and data security
146+
147+
Copilot continuously evolves using [data](/security-copilot/privacy-data-security#customer-data-and-system-generated-logs) that is [stored](/security-copilot/privacy-data-security#customer-data-storage-location), [processed](/security-copilot/privacy-data-security#location-for-prompt-evaluation), and [shared](/security-copilot/privacy-data-security#customer-data-sharing-preferences) depending on the settings defined by your administrator. Microsoft ensures that your data is always protected and secure when using Copilot. To learn more about data security and privacy in Copilot, see [Privacy and data security in Copilot](/security-copilot/privacy-data-security).
148+
149+
Because of its continuing evolution, Copilot might miss some things. Reviewing and [providing feedback](/security-copilot/rai-faqs-security-copilot#what-are-the-limitations-of-security-copilot-how-can-users-minimize-the-impact-of-security-copilots-limitations-when-using-the-system) about the results helps improve Copilot's future responses.
150+
123151
<a name='microsoft-365-defender-plugin-in-security-copilot'></a>
124152

125153
## Plugins in Copilot for Security
@@ -132,7 +160,8 @@ Copilot uses [preinstalled Microsoft plugins](/security-copilot/manage-plugins#p
132160
- [Use guided responses when responding to incidents](security-copilot-m365d-guided-response.md)
133161
- [Run script analysis](security-copilot-m365d-script-analysis.md)
134162
- [Analyze files](copilot-in-defender-file-analysis.md)
135-
- [Generate device summary](copilot-in-defender-device-summary.md)
163+
- [Generate device summaries](copilot-in-defender-device-summary.md)
164+
- [Generate identity summaries](security-copilot-defender-identity-summary.md)
136165
- [Generate KQL queries](advanced-hunting-security-copilot.md)
137166
- [Create incident reports](security-copilot-m365d-create-incident-report.md)
138167
- [Use threat intelligence](/defender/threat-intelligence/security-copilot-and-defender-threat-intelligence)
153 KB
Loading
380 KB
Loading
181 KB
Loading
451 KB
Loading

0 commit comments

Comments
 (0)