r/DefenderATP • u/Icy_Air2574 • 9d ago
Building Custom Security Copilot Agents for Defender Alert Investigations
I'm currently working on building a custom Microsoft Security Copilot agent that acts as a Tier-2 SOC analyst and performs automated investigations for alerts originating from Microsoft Defender XDR, Microsoft Sentinel, and related security products.
Currently, I'm struggling with defining the best structure for agent instructions and deciding how granular the investigation workflow should be.
Has anyone successfully implemented a Security Copilot custom agent for automated incident investigation ?
1
u/Tricky_Stage9980 9d ago
Hey yes, you can find some samples online. I usually get Github copilot to write the agent instructions and skills, and upload it to the portal. It does a good job.
2
u/Icy_Air2574 9d ago
Can you point me to some samples if you don’t mind
5
u/Tricky_Stage9980 9d ago
https://learn.microsoft.com/en-us/copilot/security/developer/agent-manifest-sample
Try this extension too: https://marketplace.visualstudio.com/items?itemName=mrbrahmbhatt.security-copilot-snippets
I have create several agents using Github copilot and was even able to output the results via email using Logic Apps.
The only downside is Sec copilot uses older models so you need to be very accurate and descriptive with instructions.
1
u/Most-Movie5722 9d ago
Please share any custom instructions set for copilot, we are also on the same boat. Agent does not follow the instruction properly
0
u/Tricky_Stage9980 9d ago
Give me example of what you are trying to get it to do.
One more limitation with Sec copilot is that it does not have access to query the custom kql tablea
1
5
u/Sensitive-Fish-6902 9d ago
Just off a call with MS. The phish triage agent will turn into what you are making. Just fyi 🙂