Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
952 changes: 478 additions & 474 deletions .openpublishing.redirection.defender-xdr.json

Large diffs are not rendered by default.

8 changes: 4 additions & 4 deletions defender-xdr/TOC.yml
Original file line number Diff line number Diff line change
Expand Up @@ -196,8 +196,8 @@
items:
- name: Overview
href: advanced-hunting-security-copilot.md
- name: Use the Threat Hunting Agent
href: advanced-hunting-security-copilot-threat-hunting-agent.md
- name: Use the Threat Hunting Assistant
href: advanced-hunting-security-copilot-threat-hunting-assistant.md
- name: Generate KQL queries
href: advanced-hunting-security-copilot-query-assistant.md
- name: Hunt over Microsoft Sentinel data
Expand Down Expand Up @@ -456,8 +456,8 @@
href: security-alert-triage-agent.md
- name: Threat Intelligence Briefing Agent
href: threat-intel-briefing-agent-defender.md
- name: Threat Hunting Agent
href: advanced-hunting-security-copilot-threat-hunting-agent.md
- name: Threat Hunting Assistant
href: advanced-hunting-security-copilot-threat-hunting-assistant.md
- name: Dynamic Threat Detection Agent
href: dynamic-threat-detection-agent.md
- name: Security Analyst Agent
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
title: Microsoft Security Copilot advanced hunting query assistant
description: Learn how Microsoft Security Copilot threat hunting agent can help you generate a KQL query.
description: Learn how Microsoft Security Copilot Threat Hunting Assistant can help you generate a KQL query.
ms.service: defender-xdr
ms.subservice: adv-hunting
ms.author: pauloliveria
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
title: Microsoft Security Copilot Threat Hunting Agent in advanced hunting
description: Learn how Microsoft Security Copilot threat hunting agent can help you investigate threats using natural language.
title: Microsoft Security Copilot Threat Hunting Assistant in advanced hunting
description: Learn how Microsoft Security Copilot Threat Hunting Assistant can help you investigate threats using natural language.
ms.service: defender-xdr
ms.subservice: adv-hunting
ms.author: pauloliveria
Expand All @@ -24,21 +24,19 @@ appliesto:
ai-usage: ai-assisted
---

# Microsoft Security Copilot Threat Hunting Agent in advanced hunting (preview)
# Microsoft Security Copilot Threat Hunting Assistant in advanced hunting

[!INCLUDE [Prerelease](../includes/prerelease.md)]
The Microsoft Security Copilot Threat Hunting Assistant is an AI-powered agent that revolutionizes threat hunting by enabling you to investigate threats using natural language from start to finish. Unlike traditional hunting methods that rely heavily on Kusto query language (KQL) expertise, the Threat Hunting Assistant transforms complex data into actionable insights quickly and intuitively, helping you drive the investigation into actions.

The Microsoft Security Copilot Threat Hunting Agent is an AI-powered agent that revolutionizes threat hunting by enabling you to investigate threats using natural language from start to finish. Unlike traditional hunting methods that rely heavily on Kusto query language (KQL) expertise, the Threat Hunting Agent transforms complex data into actionable insights quickly and intuitively, helping you drive the investigation into actions.
The Threat Hunting Assistant goes beyond query generation by delivering a complete, conversational threat hunting experience. It not only generates queries but also interprets results, surfaces insights, and guides you through full hunting sessions. These capabilities empower analysts of all levels to hunt threats faster, more accurately, and with greater confidence.

The Threat Hunting Agent goes beyond query generation by delivering a complete, conversational threat hunting experience. It not only generates queries but also interprets results, surfaces insights, and guides you through full hunting sessions. These capabilities empower analysts of all levels to hunt threats faster, more accurately, and with greater confidence.

Watch this video to get an overview of the Threat Hunting Agent:
Watch this video to get an overview of the Threat Hunting Assistant:

> [!VIDEO https://learn-video.azurefd.net/vod/player?id=74ef2c98-5dc7-406b-9b30-25e158ced334]

## Key capabilities

The Threat Hunting Agent provides the following key capabilities:
The Threat Hunting Assistant provides the following key capabilities:

- **Natural language question to natural language answer.** Ask any data-related question in natural language (for example, *Which devices communicated with IPs in France in the last 24 hours?*) and receive direct conversational answers backed by KQL queries and tabular results.

Expand All @@ -53,10 +51,10 @@ The Threat Hunting Agent provides the following key capabilities:
- **Integrated experience.** The agent's outputs are directly added to Advanced hunting components, with generated KQL placed in the editor and results displayed as usual. This gives users full access to all advanced hunting features during investigations, ensuring maximum flexibility.

## Try your first request
To start using the Threat Hunting Agent, follow these steps:
To start using the Threat Hunting Assistant, follow these steps:

>[!NOTE]
> Make sure that the Threat Hunting Agent mode is active. [Get access to Security Copilot in advanced hunting](advanced-hunting-security-copilot.md#get-access)
> Make sure that the Threat Hunting Assistant mode is active. [Get access to Security Copilot in advanced hunting](advanced-hunting-security-copilot.md#get-access)

1. Open the **Advanced hunting** page from the navigation bar in Microsoft Defender portal. The Security Copilot side pane for advanced hunting appears at the right hand side.

Expand All @@ -79,7 +77,7 @@ The agent supports all types of hunting scenarios, including:
- Proactively validating a security hypothesis

## Understand the response
When the Threat Hunting Agent responds to your question, you get a comprehensive answer that includes:
When the Threat Hunting Assistant responds to your question, you get a comprehensive answer that includes:

- **Direct conversational answer:** A natural language response to your question is displayed in the Copilot side pane.

Expand Down Expand Up @@ -129,9 +127,9 @@ After receiving a response, you can continue your hunting session in several way
To start a new hunting session, select the **New chat (+)** icon at the top of the Copilot side pane.

## Provide feedback
You can provide feedback directly in the portal by selecting the feedback icon and choosing your response. Your feedback helps improve the Threat Hunting Agent's capabilities and accuracy.
You can provide feedback directly in the portal by selecting the feedback icon and choosing your response. Your feedback helps improve the Threat Hunting Assistant's capabilities and accuracy.

:::image type="content" source="./media/advanced-hunting-security-copilot/advanced-hunting-security-copilot-agent-feedback.png" alt-text="Screenshot of the advanced hunting page with Copilot feedback buttons highlighted." lightbox="./media/advanced-hunting-security-copilot/advanced-hunting-security-copilot-agent-feedback.png":::

>[!TIP]
> Providing detailed feedback about what worked well or what could be improved helps us continuously enhance the Threat Hunting Agent experience.
> Providing detailed feedback about what worked well or what could be improved helps us continuously enhance the Threat Hunting Assistant experience.
14 changes: 7 additions & 7 deletions defender-xdr/advanced-hunting-security-copilot.md
Original file line number Diff line number Diff line change
Expand Up @@ -35,17 +35,17 @@ The following table describes these capabilities, where they're best used, and t

| Capability | Description |Output |Experience |
| ------------- | ------------- |------------- |------------- |
| [Threat Hunting Agent](advanced-hunting-security-copilot-threat-hunting-agent.md) (preview) | AI-powered conversational threat hunting agent that's best used for complete investigations, multistep hunting, exploratory analysis, and getting direct answers |Conversational answers, Kusto query language (KQL) queries, results, insights, and recommendations|Investigation-focused |
| [Threat Hunting Assistant](advanced-hunting-security-copilot-threat-hunting-assistant.md) | AI-powered conversational Threat Hunting Assistant that's best used for complete investigations, multistep hunting, exploratory analysis, and getting direct answers |Conversational answers, Kusto query language (KQL) queries, results, insights, and recommendations|Investigation-focused |
| [Query assistant](advanced-hunting-security-copilot-query-assistant.md) | Natural language to KQL query generation that's best used for generating queries |KQL query with explanation|Query-focused |

The Threat Hunting Agent and Query assistant empower you to hunt threats faster, more accurately, and with greater confidence without needing to write KQL queries.
The Threat Hunting Assistant and Query assistant empower you to hunt threats faster, more accurately, and with greater confidence without needing to write KQL queries.

## Get access
Users with access to Security Copilot can use these capabilities in advanced hunting.

You can only use one capability at a time. By default, the Threat Hunting Agent is the active mode. To switch to Query assistant mode, in the Security Copilot side pane, select the three-dot menu, then toggle the **Threat Hunting Agent** switch off.
You can only use one capability at a time. By default, the Threat Hunting Assistant is the active mode. To switch to Query assistant mode, in the Security Copilot side pane, select the three-dot menu, then toggle the **Threat Hunting Assistant** switch off.

![Screenshot of Security Copilot in advanced hunting showing the Threat Hunting Agent mode is active.](./media/advanced-hunting-security-copilot/advanced-hunting-security-copilot-access.png)
![Screenshot of Security Copilot in advanced hunting showing the Threat Hunting Assistant mode is active.](./media/advanced-hunting-security-copilot/advanced-hunting-security-copilot-access.png)

>[!NOTE]
>- Switching between modes is only available in specific user environments.
Expand All @@ -55,17 +55,17 @@ You can only use one capability at a time. By default, the Threat Hunting Agent
## Scope of Security Copilot in advanced hunting

### Use case support
The Threat Hunting Agent and Query assistant both fully support generation of simple to medium complexity queries, which includes filter operation, and/or aggregation. Complex use cases (queries with joins, filtering, and aggregation) are supported, but we recommend validating their accuracy. Help us improve by [providing feedback on Security Copilot in Microsoft Defender](security-copilot-in-microsoft-365-defender.md#provide-feedback) with incorrect queries or response examples.
The Threat Hunting Assistant and Query assistant both fully support generation of simple to medium complexity queries, which includes filter operation, and/or aggregation. Complex use cases (queries with joins, filtering, and aggregation) are supported, but we recommend validating their accuracy. Help us improve by [providing feedback on Security Copilot in Microsoft Defender](security-copilot-in-microsoft-365-defender.md#provide-feedback) with incorrect queries or response examples.

### Best practices
Use the following best practices when prompting the Threat Hunting Agent or Query assistant:
Use the following best practices when prompting the Threat Hunting Assistant or Query assistant:

- **Be unambiguous.** Ask questions with a clear subject. For example, "logins" could mean device logins or cloud logins.
- **Ask one question at a time.** Ask for a single task or type of information at a time. Don't expect the AI model to perform several unrelated tasks at once. You can always ask follow-up questions instead of combining unrelated asks into a single prompt.
- **Be specific.** If you know anything about the data you're looking for, provide that information in your question.

### Supported tables
The Threat Hunting Agent and Query assistant support the following tables in advanced hunting:
The Threat Hunting Assistant and Query assistant support the following tables in advanced hunting:

| Microsoft Defender tables | Microsoft Sentinel tables |
| ------------- | ------------- |
Expand Down
6 changes: 3 additions & 3 deletions defender-xdr/security-copilot-agents-defender.md
Original file line number Diff line number Diff line change
Expand Up @@ -70,7 +70,7 @@ This section details the Microsoft Security Copilot agents that are available in

- [Security Alert Triage Agent (Preview)](#security-alert-triage-agent-preview)
- [Threat Intelligence Briefing Agent](#threat-intelligence-briefing-agent)
- [Threat Hunting Agent](#threat-hunting-agent)
- [Threat Hunting Assistant](#threat-hunting-agent)
- [Security Analyst Agent](#security-analyst-agent)
- [Dynamic Threat Detection Agent](#dynamic-threat-detection-agent)

Expand Down Expand Up @@ -134,9 +134,9 @@ When running the Threat Intelligence Briefing Agent with an [agent identity](thr
> [!IMPORTANT]
> Allow time for permission updates to synchronize across Microsoft Defender services before running the agent.

### Threat Hunting Agent
### Threat Hunting Assistant

The [Threat Hunting Agent](advanced-hunting-security-copilot-threat-hunting-agent.md) revolutionizes threat hunting by enabling you to investigate threats using natural language from start to finish. It not only generates KQL queries but also interprets results, surfaces insights, and guides you through full hunting sessions. These capabilities empower you to hunt threats faster, more accurately, and with greater confidence.
The [Threat Hunting Assistant](advanced-hunting-security-copilot-threat-hunting-assistant.md) revolutionizes threat hunting by enabling you to investigate threats using natural language from start to finish. It not only generates KQL queries but also interprets results, surfaces insights, and guides you through full hunting sessions. These capabilities empower you to hunt threats faster, more accurately, and with greater confidence.

:::image type="content" source="./media/advanced-hunting-security-copilot/advanced-hunting-security-copilot-agent-answer.png" alt-text="Screenshot of the Copilot pane in advanced hunting with the answer highlighted." lightbox="./media/advanced-hunting-security-copilot/advanced-hunting-security-copilot-agent-answer.png":::

Expand Down
2 changes: 1 addition & 1 deletion defender-xdr/whats-new.md
Original file line number Diff line number Diff line change
Expand Up @@ -102,7 +102,7 @@ You can also get product updates and important notifications through the [messag

- (Preview) Microsoft Security Copilot in Microsoft Defender now includes the Dynamic Threat Detection Agent, an always-on, adaptive backend service that uncovers hidden threats across Defender and Microsoft Sentinel environments. [Learn more](dynamic-threat-detection-agent.md)
- (GA) The [Microsoft Security Copilot Threat Intelligence Briefing Agent in Microsoft Defender](threat-intel-briefing-agent-defender.md) is now generally available. It generates threat intelligence briefings based on the latest threat actor activity and both internal and external vulnerability information in a matter of minutes, helping security teams save time by creating customized, relevant reports.
- (Preview) Microsoft Security Copilot in Microsoft Defender now lets you hunt for threats by using natural language with the [Threat Hunting Agent](advanced-hunting-security-copilot-threat-hunting-agent.md). This agent delivers a complete, conversational threat hunting experience by not only generating queries but also interpreting results, surfacing insights, and guiding you through full hunting sessions.
- (GA) Microsoft Security Copilot in Microsoft Defender now lets you hunt for threats by using natural language with the [Threat Hunting Assistant](advanced-hunting-security-copilot-threat-hunting-assistant.md). This agent delivers a complete, conversational threat hunting experience by not only generating queries but also interpreting results, surfacing insights, and guiding you through full hunting sessions.
- (Preview) The following advanced hunting schema tables are now available for preview:
- The [`CampaignInfo`](advanced-hunting-campaigninfo-table.md) table contains information about email campaigns identified by Microsoft Defender for Office 365.
- The [`FileMaliciousContentInfo`](advanced-hunting-filemaliciouscontentinfo-table.md) table contains information about files that Microsoft Defender for Office 365 processed in SharePoint Online, OneDrive, and Microsoft Teams.
Expand Down
2 changes: 1 addition & 1 deletion sentinel/microsoft-sentinel-defender-portal.md
Original file line number Diff line number Diff line change
Expand Up @@ -61,7 +61,7 @@ The following tables compare Microsoft Sentinel capabilities in the Azure portal
| **Capability area** | **Sentinel in Azure portal** | **Sentinel in Defender portal** | **Benefits** |
|----|----|----|----|
| Advanced hunting | Sentinel-only (Log Analytics) | Unified [advanced hunting](https://go.microsoft.com/fwlink/p/?linkid=2264410) for SIEM, Defender, and the data lake, with [Security Copilot in advanced hunting](/defender-xdr/advanced-hunting-security-copilot) for KQL generation. Supports hunting in the tenant and workspaces and reuse of existing Sentinel workspace queries and functions. | Broader dataset, richer context, no context-switching |
| AI-assisted SOC (Security Copilot) | Not available | Native Security Copilot: [automated incident summary](/defender-xdr/security-copilot-m365d-incident-summary), [guided response actions](/defender-xdr/security-copilot-m365d-guided-response), [script analysis](/defender-xdr/security-copilot-m365d-script-analysis), [file analysis](/defender-xdr/copilot-in-defender-file-analysis), [incident reports](/defender-xdr/security-copilot-m365d-create-incident-report), and [autonomous Security Copilot agents](/defender-xdr/security-copilot-agents-defender) for alert triage, threat intelligence briefing, and [threat hunting](/defender-xdr/advanced-hunting-security-copilot-threat-hunting-agent). [Included capacity for E5/E7 customers](/copilot/security/security-copilot-inclusion). | Faster investigation, lower skill barrier, agentic defense |
| AI-assisted SOC (Security Copilot) | Not available | Native Security Copilot: [automated incident summary](/defender-xdr/security-copilot-m365d-incident-summary), [guided response actions](/defender-xdr/security-copilot-m365d-guided-response), [script analysis](/defender-xdr/security-copilot-m365d-script-analysis), [file analysis](/defender-xdr/copilot-in-defender-file-analysis), [incident reports](/defender-xdr/security-copilot-m365d-create-incident-report), and [autonomous Security Copilot agents](/defender-xdr/security-copilot-agents-defender) for alert triage, threat intelligence briefing, and [threat hunting](/defender-xdr/advanced-hunting-security-copilot-threat-hunting-assistant). [Included capacity for E5/E7 customers](/copilot/security/security-copilot-inclusion). | Faster investigation, lower skill barrier, agentic defense |
| Post-incident recommendations | Not available | Tailored recommendations via [Exposure Management](/unified-secops-platform/overview-msem-strategy), including attack path analysis to identify exploitable vulnerabilities. | Proactive posture improvement |

 
Expand Down