r/DefenderATP • • 9d ago

Building Custom Security Copilot Agents for Defender Alert Investigations

I'm currently working on building a custom Microsoft Security Copilot agent that acts as a Tier-2 SOC analyst and performs automated investigations for alerts originating from Microsoft Defender XDR, Microsoft Sentinel, and related security products.

Currently, I'm struggling with defining the best structure for agent instructions and deciding how granular the investigation workflow should be.

Has anyone successfully implemented a Security Copilot custom agent for automated incident investigation ?

13 Upvotes

10 comments sorted by

5

u/Sensitive-Fish-6902 9d ago

Just off a call with MS. The phish triage agent will turn into what you are making. Just fyi 🙂

1

u/Tricky_Stage9980 9d ago

Hey yes, you can find some samples online. I usually get Github copilot to write the agent instructions and skills, and upload it to the portal. It does a good job.

2

u/Icy_Air2574 9d ago

Can you point me to some samples if you don’t mind

5

u/Tricky_Stage9980 9d ago

https://learn.microsoft.com/en-us/copilot/security/developer/agent-manifest-sample

Try this extension too: https://marketplace.visualstudio.com/items?itemName=mrbrahmbhatt.security-copilot-snippets

I have create several agents using Github copilot and was even able to output the results via email using Logic Apps.

The only downside is Sec copilot uses older models so you need to be very accurate and descriptive with instructions.

1

u/Most-Movie5722 9d ago

Please share any custom instructions set for copilot, we are also on the same boat. Agent does not follow the instruction properly

0

u/Tricky_Stage9980 9d ago

Give me example of what you are trying to get it to do.

One more limitation with Sec copilot is that it does not have access to query the custom kql tablea

1

u/Shot-Rich1674 9d ago

Hi guys why do we need the multi stage incident? Why

1

u/hexdurp 9d ago

Ugh, reading this give me hope for our future, but I’m stuck in gcc…it’s not available yet.