Study guide
Technical reference and lesson notes
Purpose of This Lesson
Security Copilot can use Microsoft Defender XDR incident data to produce a rapid incident summary and answer focused follow-up questions. This workflow is useful when an analyst needs to understand the scope and storyline of an incident before performing deeper investigation or coordinating response actions.
The lesson demonstrates a single-prompt workflow: locate an incident in Defender XDR, copy its incident ID into the Defender Incident Summary prompt in Security Copilot, review the generated summary, and ask targeted questions about specific behaviors or prevention measures.
Key Concepts
Microsoft Defender XDR incidents
Microsoft Defender XDR groups related alerts into incidents. An incident can contain activity from multiple devices, operating systems, users, and attack stages. In the example, the incident included alerts related to:
- Execution of a suspicious executable on a Windows virtual machine
- Defense evasion involving
windowscmd.exeand suspicious file cleanup - Suspicious PHP execution on Linux
- Digital currency mining
- Execution from a suspicious location
The incident was classified as high severity and contained five alerts generated within an approximately eight-second window. The alert grouping provided a broader attack narrative than any single alert would have provided.
Security Copilot Defender Incident Summary
The Defender Incident Summary prompt accepts a Microsoft Defender incident ID. Security Copilot uses the incident information available in Defender to generate a natural-language summary that can describe:
- Severity and incident title
- Number and timing of associated alerts
- Affected devices, users, and operating systems
- Observed processes or executables
- Suspected attack behaviors and stages
- A concise interpretation of how the events fit together
The prompt is not a replacement for the incident record. It is an analyst-assistance feature that helps condense existing Defender data into a more readable starting point.
Follow-up prompts
After the initial summary, an analyst can ask focused questions about a particular behavior, such as digital currency mining, or request defensive recommendations for the affected virtual machine. This supports an iterative investigation workflow rather than requiring the analyst to formulate one complex prompt at the beginning.
Examples of useful follow-up objectives include:
- Explain the digital currency mining activity
- Identify how the activity may relate to the broader incident
- Recommend controls to reduce the likelihood of recurrence
- Clarify whether a behavior represents one alert or a broader incident pattern
Microsoft Security Operations Context
A practical investigation flow is:
- Open Microsoft Defender XDR at
security.microsoft.com. - Navigate to the incident investigation area and open the incident list.
- Select the relevant incident and record its incident ID.
- Open Security Copilot at
securitycopilot.microsoft.com. - Select the Defender Incident Summary prompt.
- Supply the incident ID and submit the prompt.
- Validate the generated narrative against the incident and its underlying alerts.
- Ask focused follow-up questions when a behavior requires clarification.
- Continue with normal triage, evidence review, containment, and response procedures.
Microsoft frequently changes portal navigation and page layout. The names and location of investigation features may differ from the interface shown in training, but the operational pattern remains the same: obtain the incident identifier from Defender XDR and use it as the input to the incident-summary prompt.
Interpreting the example incident
The example illustrates why incident-level analysis matters. The activity crossed Windows and Linux environments and involved multiple behaviors, including suspicious execution, defense evasion, and unauthorized resource use for digital currency mining. The rapid creation of five alerts suggested coordinated activity rather than unrelated isolated events.
The summary described the activity as a multi-stage attack involving multiple endpoints. An analyst should still inspect the individual alerts and affected entities to confirm details, determine the initial access or execution path, identify the responsible account, and establish whether the activity is ongoing.
Exam-Relevant Takeaways
- Security Copilot’s Defender Incident Summary prompt requires a Defender incident ID.
- The incident ID is obtained from the incident record in Microsoft Defender XDR.
- Defender XDR incidents can correlate multiple alerts into a broader attack story.
- An incident may include activity across different operating systems and endpoints.
- Security Copilot can summarize an incident and answer follow-up questions about a specific behavior.
- A generated summary is an investigation aid; it should be validated against the underlying incident and alerts.
- The example used a single prompt, not a promptbook.
- Security Copilot capacity is measured in Security Compute Units (SCUs). Available SCU capacity can affect performance and response time.
- Recommendations produced by Copilot may include endpoint protection, updated antimalware, cloud-delivered protection, execution restrictions, multifactor authentication, EDR-based process monitoring, and monitoring of outbound connections.
Tool / Feature Decision Guide
| Need | Appropriate action | Why |
|---|---|---|
| Obtain the incident identifier | Open the incident in Microsoft Defender XDR | The Defender Incident Summary prompt requires the incident ID. |
| Quickly understand a complex incident | Use Security Copilot’s Defender Incident Summary prompt | It condenses correlated alerts into an incident-level narrative. |
| Investigate one behavior in greater detail | Ask a focused follow-up prompt | Narrow questions can provide additional context about a behavior such as mining. |
| Confirm the evidence behind a summary | Review the original incident and its alerts in Defender XDR | Copilot’s narrative should not replace source telemetry or alert validation. |
| Improve response capacity or responsiveness | Review available SCU capacity | Security Copilot performance is influenced by available Security Compute Units. |
| Prevent recurrence on a compromised VM | Combine endpoint protection, execution controls, identity protection, EDR monitoring, and network monitoring | Digital currency mining and similar abuse often require layered controls. |
Common Exam Traps
- Confusing an incident ID with an alert ID: The prompt demonstrated here asks for the Defender incident ID, not one of the IDs of the alerts contained within the incident.
- Treating the summary as the investigation: A generated narrative is a starting point. Analysts must verify affected entities, processes, timestamps, and alert evidence in Defender XDR.
- Assuming one operating system: Defender incidents can combine Windows and Linux activity. Do not limit investigation or containment to the first endpoint mentioned.
- Ignoring alert correlation: Five alerts in a short time window may represent one coordinated incident rather than five independent cases.
- Confusing a prompt with a promptbook: The example uses a single Defender Incident Summary prompt and follow-up questions, not a promptbook.
- Assuming recommendations prove root cause: Prevention suggestions are general defensive guidance. They do not establish how the attacker entered, which account was compromised, or whether the threat is still active.
- Overlooking capacity considerations: SCU availability can affect the responsiveness of Security Copilot.
Real-World SOC Analyst Notes
- Preserve the original incident context before taking action. Record the incident ID, severity, alert count, affected devices, users, and important timestamps.
- Use Copilot to accelerate orientation and prioritization, but use Defender evidence for containment and escalation decisions.
- When a summary identifies a compromised account, investigate the account’s activity and authentication history before resetting credentials or disabling access. Coordinate with the identity team when required.
- For suspected mining, examine process execution, persistence, outbound connections, resource consumption, and whether other systems show similar activity.
- Cross-platform incidents require coordination across Windows and Linux administration teams. A Windows-only response may leave the Linux portion of the attack active.
- Document which recommendations were generated by Copilot and which were confirmed by telemetry. This distinction improves handoff quality and auditability.
- Apply prevention changes through normal change-control procedures. Broad execution restrictions, endpoint policy changes, or identity controls can affect production workloads.
- Treat automation and remediation recommendations cautiously when the incident affects shared virtual machines, service accounts, or tenant-wide policies.
- If the Copilot response is slow or incomplete, consider available SCU capacity and continue using the underlying Defender incident and alerts rather than waiting indefinitely.
Quick Reference Summary
- Source of the ID: Microsoft Defender XDR incident record
- Copilot feature: Defender Incident Summary
- Input: Defender incident ID
- Output: Natural-language summary of correlated incident activity
- Follow-up capability: Ask focused questions about behaviors or prevention
- Example scope: High-severity, multi-stage activity across Windows and Linux
- Example evidence: Five alerts generated within about eight seconds
- Validation rule: Confirm Copilot’s interpretation against the incident and underlying alerts
- Capacity consideration: Security Compute Units influence Copilot performance
Flashcards
Q: Which identifier should an analyst provide to Security Copilot’s Defender Incident Summary prompt?
A: Provide the incident ID from the Microsoft Defender XDR incident record, not an individual alert ID.
Q: Where does an analyst obtain the incident ID used by the Defender Incident Summary prompt?
A: Open the incident in Microsoft Defender XDR and record the incident ID shown on the incident record.
Q: When is the Defender Incident Summary prompt most useful?
A: Use it to quickly understand a complex or multi-alert incident and obtain an initial attack narrative before deeper investigation.
Q: Why should an analyst review the underlying Defender alerts after receiving a Copilot summary?
A: The summary is an assistance and orientation tool. The analyst must validate its interpretation against the original alerts, entities, processes, and timestamps.
Q: What does it mean when Defender correlates several alerts into one incident?
A: The alerts are presented as related activity that may form a broader attack story, rather than being treated only as isolated detections.
Q: What exam trap is associated with an incident containing several alerts?
A: Do not confuse the incident ID with the IDs of its component alerts or assume that every alert represents an unrelated investigation.
Q: How can an analyst investigate one suspicious behavior after generating an incident summary?
A: Ask Security Copilot a focused follow-up question about that behavior, such as the digital currency mining activity, and then validate the answer in Defender.
Q: How did the example demonstrate cross-platform investigation?
A: The incident included Windows execution and defense-evasion activity as well as suspicious PHP execution on Linux, showing that one incident can span operating systems.
Q: What did the approximately eight-second window and five alerts suggest in the example?
A: They supported the interpretation of rapid, coordinated malicious activity rather than unrelated events spread over a long period.
Q: What is the difference between the workflow shown and a promptbook workflow?
A: The workflow used one Defender Incident Summary prompt followed by conversational questions; it did not use a promptbook.
Q: What are Security Compute Units relevant to in this workflow?
A: SCUs provide the capacity used by Security Copilot, and available capacity can affect performance and response time.
Q: Which control areas can help reduce the risk of unauthorized digital currency mining on a VM?
A: Layered controls include endpoint protection, current antimalware and cloud protection, execution restrictions, EDR process monitoring, identity protection, and outbound connection monitoring.
Q: Why should a suspected mining incident not be handled as only a malware-detection problem?
A: Mining may involve compromised accounts, suspicious processes, unauthorized resource use, and network activity, so endpoint, identity, process, and network evidence should all be considered.
Q: What should an analyst do if the Copilot-generated prevention advice is broad or generic?
A: Treat it as a starting point, determine which recommendations address confirmed evidence, and implement changes through appropriate validation and change-control processes.
Practice Questions
Question 1
A SOC analyst wants Security Copilot to summarize a Defender XDR incident containing several related alerts. Which input is required for the Defender Incident Summary prompt?
A. The name of the affected virtual machine
B. The incident ID from Defender XDR
C. The SCU capacity assigned to the tenant
D. The ID of the first alert generated
Correct answer: B
The prompt is demonstrated using the incident ID obtained from the Microsoft Defender XDR incident record. An individual alert ID is not the correct substitute.
Question 2
An incident contains Windows ransomware-related execution, suspicious command-line cleanup, Linux PHP execution, and digital currency mining alerts generated within seconds. What is the best initial use of Security Copilot?
A. Close the alerts because Defender already correlated them
B. Use Defender Incident Summary to create an incident-level narrative, then validate the underlying alerts
C. Run a tenant-wide policy change immediately
D. Investigate only the Windows endpoint because it generated the first alert
Correct answer: B
The incident-level summary helps the analyst understand the correlated activity and scope. The original alerts still need to be reviewed before containment or policy changes.
Question 3
After reviewing an incident summary, the analyst wants more detail about the digital currency mining behavior. Which action best matches the demonstrated workflow?
A. Start a separate incident without reviewing the existing incident
B. Ask a focused follow-up question about the mining activity
C. Replace the incident ID with the VM’s device ID
D. Use only a promptbook because follow-up questions are not supported
Correct answer: B
Security Copilot can continue the investigation conversationally with a focused question about a specific behavior. The answer should still be checked against the relevant alert evidence.
Question 4
Security Copilot responds slowly while an analyst is requesting an incident summary. Which factor from the lesson may affect the experience?
A. The number of Linux users in the incident
B. Available Security Compute Units
C. Whether the incident contains exactly one alert
D. The display resolution of the Defender portal
Correct answer: B
Security Compute Unit capacity affects Security Copilot performance. The analyst should also continue using the Defender incident and alerts as the authoritative investigation source.
Question 5
A Copilot response recommends endpoint protection, multifactor authentication, EDR process monitoring, and outbound connection monitoring after suspected mining on a VM. What is the most appropriate SOC interpretation?
A. The recommendations prove that MFA was the attack entry point
B. The recommendations are layered defensive guidance that must be mapped to confirmed evidence and implemented safely
C. The recommendations automatically contain the threat
D. Only the endpoint protection recommendation is relevant because mining is malware
Correct answer: B
The recommendations address multiple possible control gaps, but they do not establish root cause or perform containment automatically. Analysts should validate the incident, coordinate with relevant teams, and apply changes through appropriate operational controls.