你当前正在访问 Microsoft Azure Global Edition 技术文档网站。 如果需要访问由世纪互联运营的 Microsoft Azure 中国技术文档网站,请访问 https://docs.azure.cn

具有 Microsoft Sentinel 的 Security Copilot

智能 Microsoft Security Copilot 副驾驶® 是一个平台,可帮助你以机器级的速度和规模保护你的组织。 Microsoft Sentinel庞大的安全数据为 Copilot 提供了一个很好的来源,可帮助分析事件并生成搜寻查询。

结合你启用的其他 Security Copilot 源,Microsoft Sentinel 事件和数据可让你更全面地了解组织面临的威胁及其相关上下文。

开始前须知

如果你不熟悉Security Copilot,应该通过阅读以下文章来熟悉它:

Security Copilot 与 Microsoft Sentinel 的集成

此集成主要支持通过 https://securitycopilot.microsoft.com访问的独立体验,你可以在类似聊天的体验中进行交互,以汇总事件并获取有关安全数据的其他答案。 有关更多信息,请参阅智能 Microsoft Security Copilot 副驾驶® 体验

关键功能

Microsoft Sentinel 数据在 Defender 门户中与 Security Copilot 集成,具体如下:

  • 当你还拥有 Microsoft Defender XDR 时,Microsoft Defender XDR 中的 Copilot 可受益于与 Microsoft Sentinel 集成的统一事件。
  • 在独立体验中,Microsoft Sentinel提供了以下插件来与 Security Copilot 集成:
    Microsoft Sentinel (预览版)
    Microsoft Sentinel 的自然语言转 KQL(预览版)

启用与 Microsoft Sentinel 的 Security Copilot 集成

若要最大限度地发挥 Security Copilot 与 Microsoft Sentinel 集成的作用,请执行以下操作:

  • 为Security Copilot配置默认Microsoft Sentinel工作区
  • 将Microsoft Sentinel工作区连接到Microsoft Defender XDR

配置默认Microsoft Sentinel工作区

通过将Microsoft Sentinel工作区配置为默认值,提高提示准确性。

  1. 导航到 https://securitycopilot.microsoft.com/ 的 Security Copilot。

  2. 在提示栏中打开 来源

  3. “管理插件”页上,将开关设置为“打开

  4. 选择Microsoft Sentinel (预览) 插件上的齿轮图标。

    Microsoft Sentinel插件的个性化选择齿轮图标的屏幕截图。

  5. 配置默认工作区名称。

    Microsoft Sentinel插件的插件个性化选项的屏幕截图。

提示

当工作区与配置的默认值不匹配时,请在提示符中指定工作区。

例如:What are the top 5 high priority Sentinel incidents in workspace "soc-sentinel-workspace"?

将 Microsoft Sentinel 与 Defender 中的 Copilot 集成

使用 Microsoft Defender 门户和 Microsoft Sentinel 中的数据,获得内置的 Security Copilot 体验。 Microsoft Sentinel 的唯一数据源会流入 Microsoft Defender XDR 统一事件,使 Copilot in Defender 能够最大限度地发挥其功能。

例如:

Defender 门户中包含 Copilot 嵌入式体验的 Microsoft Sentinel 事件的屏幕截图。

有关详细信息,请参阅以下资源:

在高级搜寻中将 Microsoft Sentinel 与 Security Copilot 集成

适用于 Microsoft Sentinel 的自然语言转 KQL(预览版)插件使用 Microsoft Sentinel 数据生成并运行 KQL 搜寻查询。 此功能在Microsoft Defender门户的独立体验和高级搜寻部分中提供。

注意

在统一Microsoft Defender门户中,可以提示Security Copilot为Defender XDR表和Microsoft Sentinel表生成高级搜寻查询。 目前并非所有Microsoft Sentinel表都受支持。

有关详细信息,请参阅使用 Security Copilot 进行高级搜寻

Microsoft Sentinel 示例提示

Microsoft Sentinel事件调查提示簿视为创建有效提示的起点。 此提示手册提供有关特定事件的报告,以及相关警报、信誉分数、用户和设备。

指南 提示
引导 Copilot 提供便于人类阅读的信息,而不是返回对象 ID。 Show me Sentinel incidents that were closed as a false positive. Supply the Incident number, Incident Title, and the time they were created.
Copilot 知道你是谁。 使用代词“me”查找与你相关的事件。 以下提示针对分配给你的事件。 What Sentinel incidents created in the last 24 hours are assigned to me? List them with highest priority incidents at the top.
将提示响应缩小到单个事件时,Copilot 会知道上下文。 Tell me about the entities associated with that incident.
Copilot 擅长总结。 描述要汇总其提示和响应的特定受众。 Write an executive report summarizing this investigation. It should be suited for a nontechnical audience.

有关更多提示指南和示例,请参阅以下资源:

提供反馈

你的反馈对于指导产品的当前和计划开发至关重要。 提供此反馈的最佳方式是直接在产品中提供。 在每个已完成的提示符底部选择 “此响应如何?” ,然后选择以下任一选项:

  • 看起来正确 - 根据你的评估,如果结果准确,请勾选此项。
  • 需要改进 - 根据评估,选择结果中是否有任何详细信息不正确或不完整。
  • 不适当 - 选择结果是否包含可疑、模棱两可或可能有害的信息。

对于每个反馈选项,可以在显示的下一个对话框中提供详细信息。 尽可能,尤其是当结果为 “需要改进”时,请写几句话来解释如何改进结果。 如果您输入了专门针对 Azure 防火墙的提示词,但结果与之无关,请注明这一点。

安全 Copilot 中的隐私和数据安全

若要了解 Security Copilot 如何处理你的提示词以及从服务中检索的数据(提示词输出),请参阅 智能 Microsoft Security Copilot 副驾驶® 中的隐私和数据安全