Agent Foskett Investigation • Microsoft Security Copilot • Defender XDR • AI-Assisted Investigation

The AI Gave The Right Answer... To The Wrong Question

The analyst copied the alert into Microsoft Security Copilot.

One prompt.

One accurate answer.

One investigation closed.

Unfortunately...

It was the wrong question.

Agent Foskett investigating an incomplete Microsoft Security Copilot answer while hidden identity, email and endpoint evidence continues in the background
AI-Assisted Investigation

Security Copilot answered exactly what it was asked. The evidence outside the prompt kept telling a much larger story.

Ask questions that expand the investigation
Correlate identity, endpoint, email and cloud activity
Use AI to accelerate judgement—not replace it

The AI answered perfectly

The response was accurate, relevant and completely insufficient.
The prompt was clearThe analyst asked one direct question about whether the alert contained evidence of malware.
The response was correctNo malicious file, payload or recognised malware execution was present in the evidence supplied.
The investigation still failedThe absence of malware was mistaken for the absence of compromise.

What the analyst asked

A narrow question produced a narrow answer.
security-copilot-session.txt
  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6
  7. 7
  8. 8
  9. 9
ANALYST PROMPT
Is this malware?

SECURITY COPILOT RESPONSE
No evidence of malware was identified in the supplied alert.

CASE STATUS
Closed

The questions nobody asked

The alert did not contain malware. The incident did not need it.
Was the identity compromised?Valid credentials, token theft or MFA approval could have given an attacker access without malware.
Was persistence created?New authentication methods, inbox rules, scheduled tasks or application consent could preserve access.
Was OAuth consent granted?A malicious or overprivileged application could continue accessing data after the original session ended.
Was the mailbox changed?Forwarding, inbox rules and message access may reveal business email compromise activity.
Were files downloaded?SharePoint and OneDrive activity could show collection and exfiltration using legitimate cloud services.
Did privilege change?Role assignments or group membership changes could expand the attacker's reach without dropping a file.

Security Copilot was not wrong

AI can only reason across the evidence, scope and intent provided to it.
It answered the exact questionThe result accurately addressed malware because malware was the only subject of the prompt.
It did not invent a wider caseThe analyst had not asked it to build a timeline, find related entities or examine other security domains.
The stopping decision was humanThe investigation ended because the analyst treated one answer as the complete case.

Better prompts create better investigations

Replace confirmation questions with prompts that widen the evidence and test competing explanations.
Instead of: Is this malware?Ask: Build a complete timeline of suspicious activity before and after this alert.
Instead of: Is this malicious?Ask: Identify unusual identity, endpoint, email and cloud activity associated with this user and device.
Instead of: Explain the alertAsk: Correlate this alert with related incidents, sign-ins, process activity, mailbox changes and file access.
Ask for missing evidenceRequest the data sources, entities or time ranges needed before a confident conclusion can be reached.
Ask for alternative explanationsHave Copilot compare legitimate administrative activity against identity compromise and attacker persistence.
Ask for recommended next stepsUse the response to plan verification, containment and additional investigation—not to bypass them.

The investigation Security Copilot helped reveal

Once the scope expanded, the apparently harmless alert became the first clue in a cloud-based compromise.
ai-assisted-investigation-timeline.txt
  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6
  7. 7
  8. 8
  9. 9
  10. 10
08:14  Defender alert generated
08:15  Initial prompt asks only about malware
08:16  No malware identified
08:24  Entra sign-in linked to an unfamiliar session
08:29  New mailbox forwarding rule discovered
08:33  OAuth consent grant identified
08:38  SharePoint download activity confirmed
08:44  New MFA method found
08:51  Incident escalated and session revoked

Microsoft Security Copilot investigation workflow

Experienced analysts use Copilot repeatedly throughout an investigation rather than asking one question and stopping.
1. Summarise the alertEstablish the affected entities, detection logic, evidence and immediate risk.
2. Expand the entitiesInvestigate the user, device, IP address, application, mailbox and cloud resources connected to the alert.
3. Build the timelineCorrelate events before and after the alert to identify initial access, persistence and impact.
4. Cross security domainsMove between Defender XDR, Microsoft Entra, Exchange, SharePoint, OneDrive and endpoint telemetry.
5. Test the conclusionAsk what evidence supports the theory, what contradicts it and what remains unknown.
6. Verify before actingConfirm critical findings in the underlying portals and evidence before containment or closure.

Agent Foskett's investigation mindset

AI makes investigation faster. It does not decide where curiosity should stop.
Do not ask only: Is the alert malicious?A binary answer can hide the wider behaviour, intent and impact surrounding the alert.
Ask: What happened before and after?Build enough context to understand how access began, what changed and what the actor attempted next.
Ask: What have we not examined?The missing data source, overlooked entity or untested assumption may contain the decisive clue.

What analysts should verify

Copilot responses should guide investigation activity and be checked against the original evidence.
Verify the evidence scopeConfirm which alerts, incidents, logs, plugins and time ranges were available to the session.
Verify important claimsOpen the underlying events and confirm identities, timestamps, actions and affected resources.
Verify the closure decisionEnsure unanswered questions, missing telemetry and unresolved activity are recorded before closing the case.

Investigation findings

The AI response was not the failure. The investigation stopped before the evidence did.
No malware was presentThe original answer remained accurate throughout the investigation.
A compromise was still activeIdentity abuse, cloud persistence and data access continued through legitimate services.
The better question found the incidentBroader prompts exposed the relationships and timeline that the first prompt never requested.
AI does not replace the investigator.
It accelerates the analyst who knows which question to ask next.
Visit the Security Copilot Academy

Final thought

Microsoft Security Copilot can examine enormous amounts of security evidence quickly. The investigator still decides where to look, what to challenge and when the case is truly complete.
The answer was rightNo malware had been identified in the supplied alert.
The question was too smallIt excluded the identity, cloud and persistence evidence that proved the compromise.
The investigator kept askingAgent Foskett never asks AI to solve the case. He asks it to help find the clues everyone else overlooked.
Develop IT. Protect IT.
GEMXIT PTY LTD | GEMXIT UK LTD
Talk to GEMXIT

The AI Gave The Right Answer To The Wrong Question

This Agent Foskett investigation examines how Microsoft Security Copilot can return an accurate answer while a security investigation still fails. A narrow prompt about malware overlooked identity compromise, OAuth consent, mailbox changes, cloud data access and attacker persistence.

Microsoft Security Copilot Prompting And Investigation

The investigation explains how security analysts can improve prompts by requesting complete timelines, related entities, cross-domain correlation, missing evidence, alternative explanations and recommended verification steps across Microsoft Defender XDR and Microsoft Entra.

AI-Assisted Security Operations

GEMXIT helps organisations use Microsoft Security Copilot, Microsoft Defender XDR, Microsoft Entra, Exchange Online, SharePoint, OneDrive and endpoint telemetry to accelerate investigations while maintaining human verification and analyst judgement.