Security Copilot Capabilities

 









How Does Security Copilot Works? 

Both an immersive standalone experience and user-friendly embedded experiences found in other Microsoft security products provide access to Security Copilot's capabilities. Together, the proprietary Microsoft technologies and the foundation language model form an underlying system that helps defenders become more capable and efficient. 
  • Microsoft Security Solutions- Security Copilot seamlessly integrates with Microsoft security products like Microsoft Defender XDR, Microsoft Sentinel, and Microsoft Intune. Certain Microsoft security solutions offer embedded experiences that allow users to access Security Copilot and prompting features while working with those solutions.

  • Plugins from Microsoft and Third-Party Security Products- Security Copilot can be extended and integrated with integrated with third-party security products and Microsoft plugins. Plugins provide additional context from incident reports, event logs, alerts, and policies from third-party solutions like ServiceNow as well as Microsoft Security products.

  • Security Copilot also has Access to Threat Intelligence and Authoritative Content through plugins- These plugins have the ability to search through a variety of sources, including vulnerability disclosure publications, Microsoft Defender XDR threat analytics reports, and Microsoft Defender Threat Intelligence articles and intelligence profiles.

Explanation:

  • User prompts from security products are sent to Security Copilot.

  • Security Copilot the preprocesses the input prompt via grounding, which improves the specificity of the prompt to help you get answers and then send the modified version to the language model.

  • Security Copilot takes the response from the language model and post-processes it. This includes accessing plugins to gain contextualized information.

  • Security Copilot returns the response, where the user can review and assess it. 


Conclusion

This description shows that Security Copilot iteratively processes and orchestrates the sophisticated services to help produce results that are relevant to an organization because they are contextually based on the organization's data. 











Comments

Popular posts from this blog

Deployment (Part 3)

Deployment (Part 1)

Deployment (Part 2)