Agent Foskett Academy • Microsoft Security Copilot • Module 4 • Lesson 34

Lesson 34 — Security Copilot in Daily Operations

Security Copilot becomes most valuable when it stops being an occasional tool and becomes part of a disciplined security operations workflow.

Analysts can use Copilot to accelerate shift handovers, incident review, threat hunting, reporting, knowledge transfer and investigation preparation while keeping evidence validation and human judgement at the centre of every decision.

This lesson builds a practical daily operating model for using Security Copilot consistently, safely and effectively across the SOC.

Copilot should reduce the time spent assembling the story — not the time spent checking whether the story is true.
Agent Foskett Security Copilot in Daily Operations lesson
What you will learn

Turn Security Copilot into a repeatable part of everyday SOC operations.

✓ Shift handovers and incident review
✓ Hunting and investigation support
✓ Reporting and knowledge transfer
✓ Analyst development and validation

Daily Security Copilot operating cycle

Start of shift

Review handover, open incidents and priority alerts

Copilot organises current evidence and outstanding questions

Analyst validates important claims against original telemetry

Investigate and hunt using focused prompts and KQL

Record decisions, actions, confidence and unresolved evidence

Prepare technical and business-facing updates

Capture useful prompts, queries and lessons learned

Produce a structured handover for the next analyst

Improve promptbooks, detections and operational knowledge

Where Copilot fits in daily SOC work

ActivityCopilot contributionHuman responsibility
Shift handoverSummarise open incidents, actions and unresolved questions.Confirm accuracy, priorities and ownership.
Incident reviewExplain alerts, entities, timelines and relationships.Validate evidence and decide investigation direction.
Threat huntingDevelop hypotheses, KQL ideas and investigation pivots.Test queries, interpret results and challenge assumptions.
ReportingDraft technical and executive summaries.Approve facts, impact, language and distribution.
Knowledge transferExplain unfamiliar concepts and organise notes.Verify guidance and preserve organisational context.
Analyst developmentExplain queries, techniques and reasoning.Build independent judgement rather than dependency.

Learning objectives

Understand where Security Copilot fits into daily SOC operations; improve handovers and incident review; accelerate hunting and reporting; strengthen knowledge transfer; preserve validation and human judgement.

Operationalise the workflow

Security Copilot creates sustainable value when it becomes part of defined analyst processes rather than an occasional tool used only during difficult incidents.

Start-of-shift review

Use Copilot to organise open incidents, recent changes, pending actions and unresolved questions inherited from the previous shift.

Validate the handover

Check generated summaries against incident records, analyst notes and current alert status before using them as operational truth.

Prioritise outstanding work

Use Copilot to help identify high-impact unresolved incidents, then confirm priority against severity, business impact and organisational policy.

Incident queue review

Rapidly summarise alerts, entities, timelines and recent changes so analysts can decide where deeper investigation is required.

Ask what changed

For ongoing incidents, focus prompts on evidence added since the last review rather than repeatedly generating the same summary.

Ask what remains unknown

Good operational prompts expose unanswered questions, missing telemetry and assumptions as well as known facts.

Review related entities

Correlate users, devices, IP addresses, applications, mailboxes and cloud resources that may connect apparently separate alerts.

Build and challenge timelines

Use Copilot to organise events chronologically, then verify timestamps, gaps and conflicting evidence against source telemetry.

Maintain investigation notes

Record confirmed facts, working hypotheses, queries, actions, confidence and unresolved questions throughout the shift.

Daily threat hunting

Turn observations from incidents, intelligence and previous shifts into focused hunting hypotheses.

Generate KQL carefully

Copilot can accelerate query development, but analysts must validate tables, fields, syntax, joins, filters and returned results.

Refine from results

Use representative returned rows to choose the next pivot instead of asking Copilot to speculate about unseen data.

Reuse validated queries

Document useful hunting queries and incorporate them into team knowledge, promptbooks or detections where appropriate.

Hunt after incidents

Use validated behaviours and indicators from resolved incidents to search for related activity elsewhere.

Reporting during the shift

Turn validated technical findings into concise updates for SOC leads, management and business stakeholders.

Technical reporting

Preserve evidence, affected entities, queries, actions, confidence and remaining investigation work.

Executive reporting

Focus on business impact, containment status, current risk, decisions required and next actions.

Separate audiences

Generate the level of technical detail appropriate to the recipient rather than sending the same report to everyone.

Never invent certainty

Review generated language for unsupported claims such as confirmed compromise when evidence only shows suspicious activity.

Knowledge transfer

Use Copilot to explain unfamiliar security concepts, telemetry and investigation techniques while analysts work.

Explain KQL

Break queries into operators, filters, joins and expected output, then compare the explanation with actual returned results.

Capture organisational knowledge

Generic AI knowledge cannot replace local context about critical systems, administrators, approved software and business processes.

Improve runbooks

Recurring questions and investigation steps can reveal gaps in internal documentation and procedures.

Improve promptbooks

Convert successful prompt sequences into reusable team workflows with defined validation gates.

Analyst development

Use Copilot as an interactive learning aid that explains reasoning rather than simply providing conclusions.

Junior analysts

Explain concepts and suggest investigation pivots while requiring the analyst to validate evidence independently.

Experienced analysts

Accelerate repetitive analysis, challenge working theories and explore alternative investigation paths.

Avoid skill atrophy

Analysts should remain capable of reading telemetry, validating KQL and investigating without blindly relying on generated output.

Use Copilot as a challenger

Ask for alternative explanations, contradictory evidence and missing information rather than only support for the current theory.

End-of-shift handover

Organise the current investigation state into a consistent handover that the outgoing analyst validates.

Include current status

State which incidents remain active, contained, awaiting evidence or ready for closure.

Include completed actions

Record containment, remediation, queries, communications and approvals already performed.

Include open questions

Tell the next analyst what is not yet understood, not only what has already been discovered.

Include next actions

Specify the next investigation or response step and its owner where known.

Include confidence

Distinguish confirmed findings from likely interpretations and untested hypotheses.

Include business context

Preserve maintenance windows, critical users, system dependencies and operational constraints across shifts.

Operational guardrails

Define where Copilot may assist, what information may be used, which outputs require review and who approves consequential actions.

Protect sensitive information

Follow organisational requirements for confidential, personal and regulated investigation data.

Use least privilege

Access to security data, plugins and integrated services should match analyst responsibilities.

Preserve auditability

Important investigation decisions and actions should remain attributable to authorised people and systems.

Keep humans in the loop

High-impact containment, identity, endpoint and cloud actions should follow the organisation's approval process.

Common mistake: emergency-only use

Analysts gain more value when familiar Copilot workflows are practised during normal operations.

Common mistake: summarising everything

Large summaries without a specific operational question can add noise instead of reducing it.

Common mistake: copy and paste operations

Moving generated text between systems without validation can propagate incorrect conclusions.

Common mistake: no shared standards

If every analyst prompts differently, investigation quality and handovers may become inconsistent.

Common mistake: measuring prompt count

Prompt volume says little about investigation quality, time saved or security outcomes.

Common mistake: accepting the first answer

Operational investigations usually require iterative prompts, source review and alternative hypotheses.

Build team prompt standards

Define reusable structures for incident summaries, hunting, handovers, reporting and evidence validation.

Build review gates

Specify where analysts must verify source evidence before continuing or taking action.

Build a feedback loop

Capture prompts that worked, prompts that failed and situations where Copilot added little value.

Review operational value

Measure whether Copilot reduces repetitive effort while improving consistency, investigation depth and response outcomes.

Final analyst judgement

Security Copilot can become part of the daily SOC rhythm, but evidence, context and authorised human judgement remain the foundation.

Example start-of-shift prompt

Prepare a start-of-shift operational review from the available security evidence.

For each active incident include:
1. Incident identifier and current severity
2. Affected users, devices and resources
3. Confirmed findings only
4. Actions completed during the previous shift
5. Outstanding investigation questions
6. Missing or incomplete telemetry
7. Current containment status
8. Next recommended investigation step
9. Assigned owner where available
10. Confidence and alternative explanations

Separate confirmed evidence from inference.
Do not mark an incident resolved unless source data supports closure.

Agent Foskett investigation: “The night shift knew something I didn't”

A suspicious identity incident passed from the night shift

The handover note said: “likely VPN — monitor”

Agent Foskett used Copilot to organise the overnight evidence

The sign-in was followed by a new OAuth consent

A mailbox rule appeared shortly afterwards

The wider sequence had not survived the handover

The original evidence was checked again

The OAuth application was not approved

The mailbox rule redirected selected messages

The incident was escalated and tokens were revoked

The application and malicious rule were removed

The handover template was changed

Every shift now recorded evidence, uncertainty and the next unanswered question
A good handover does not merely tell the next analyst what you found. It tells them where the investigation still needs to go.

Daily operations checklist

StageQuestionValidation action
Start of shiftWhat changed?Compare summaries with incident records.
PriorityWhat needs attention first?Confirm severity and business impact.
InvestigationWhat supports the theory?Open source telemetry.
HuntingWhat should we search for elsewhere?Validate KQL and scope.
ReportingWho needs the information?Match detail to audience.
HandoverWhat remains unresolved?Record confidence, owners and next actions.
GovernanceWere significant actions approved?Preserve decisions and audit records.

Key takeaways

  • Integrate Security Copilot into defined SOC processes.
  • Preserve evidence, uncertainty, ownership and next actions in handovers.
  • Use Copilot to accelerate incident review, hunting, KQL and reporting.
  • Validate generated claims against original telemetry.
  • Use Copilot to strengthen knowledge transfer and analyst development.
  • Standardise useful prompts and validation gates.
  • Protect sensitive information and preserve auditability.
  • Measure security outcomes and analyst efficiency rather than prompt volume.
  • Keep human judgement responsible for consequential decisions.

Related Agent Foskett resources

Lesson 34 moves Security Copilot from individual investigation assistance into a repeatable daily SOC operating model.

Continue Module 4 — Operational Security Copilot

The next lesson examines whether Copilot is actually improving analyst efficiency and security outcomes.

Security Copilot in daily SOC operations

Security Copilot can assist with shift handovers, incident review, hunting, reporting, knowledge transfer and analyst development while analysts validate evidence and retain responsibility for decisions.