Lesson 34 — Security Copilot in Daily Operations
Security Copilot becomes most valuable when it stops being an occasional tool and becomes part of a disciplined security operations workflow.
Analysts can use Copilot to accelerate shift handovers, incident review, threat hunting, reporting, knowledge transfer and investigation preparation while keeping evidence validation and human judgement at the centre of every decision.
This lesson builds a practical daily operating model for using Security Copilot consistently, safely and effectively across the SOC.

What you will learn
Turn Security Copilot into a repeatable part of everyday SOC operations.
Daily Security Copilot operating cycle
↓
Review handover, open incidents and priority alerts
↓
Copilot organises current evidence and outstanding questions
↓
Analyst validates important claims against original telemetry
↓
Investigate and hunt using focused prompts and KQL
↓
Record decisions, actions, confidence and unresolved evidence
↓
Prepare technical and business-facing updates
↓
Capture useful prompts, queries and lessons learned
↓
Produce a structured handover for the next analyst
↓
Improve promptbooks, detections and operational knowledge
Where Copilot fits in daily SOC work
| Activity | Copilot contribution | Human responsibility |
|---|---|---|
| Shift handover | Summarise open incidents, actions and unresolved questions. | Confirm accuracy, priorities and ownership. |
| Incident review | Explain alerts, entities, timelines and relationships. | Validate evidence and decide investigation direction. |
| Threat hunting | Develop hypotheses, KQL ideas and investigation pivots. | Test queries, interpret results and challenge assumptions. |
| Reporting | Draft technical and executive summaries. | Approve facts, impact, language and distribution. |
| Knowledge transfer | Explain unfamiliar concepts and organise notes. | Verify guidance and preserve organisational context. |
| Analyst development | Explain queries, techniques and reasoning. | Build independent judgement rather than dependency. |
Learning objectives
Understand where Security Copilot fits into daily SOC operations; improve handovers and incident review; accelerate hunting and reporting; strengthen knowledge transfer; preserve validation and human judgement.
Operationalise the workflow
Security Copilot creates sustainable value when it becomes part of defined analyst processes rather than an occasional tool used only during difficult incidents.
Start-of-shift review
Use Copilot to organise open incidents, recent changes, pending actions and unresolved questions inherited from the previous shift.
Validate the handover
Check generated summaries against incident records, analyst notes and current alert status before using them as operational truth.
Prioritise outstanding work
Use Copilot to help identify high-impact unresolved incidents, then confirm priority against severity, business impact and organisational policy.
Incident queue review
Rapidly summarise alerts, entities, timelines and recent changes so analysts can decide where deeper investigation is required.
Ask what changed
For ongoing incidents, focus prompts on evidence added since the last review rather than repeatedly generating the same summary.
Ask what remains unknown
Good operational prompts expose unanswered questions, missing telemetry and assumptions as well as known facts.
Review related entities
Correlate users, devices, IP addresses, applications, mailboxes and cloud resources that may connect apparently separate alerts.
Build and challenge timelines
Use Copilot to organise events chronologically, then verify timestamps, gaps and conflicting evidence against source telemetry.
Maintain investigation notes
Record confirmed facts, working hypotheses, queries, actions, confidence and unresolved questions throughout the shift.
Daily threat hunting
Turn observations from incidents, intelligence and previous shifts into focused hunting hypotheses.
Generate KQL carefully
Copilot can accelerate query development, but analysts must validate tables, fields, syntax, joins, filters and returned results.
Refine from results
Use representative returned rows to choose the next pivot instead of asking Copilot to speculate about unseen data.
Reuse validated queries
Document useful hunting queries and incorporate them into team knowledge, promptbooks or detections where appropriate.
Hunt after incidents
Use validated behaviours and indicators from resolved incidents to search for related activity elsewhere.
Reporting during the shift
Turn validated technical findings into concise updates for SOC leads, management and business stakeholders.
Technical reporting
Preserve evidence, affected entities, queries, actions, confidence and remaining investigation work.
Executive reporting
Focus on business impact, containment status, current risk, decisions required and next actions.
Separate audiences
Generate the level of technical detail appropriate to the recipient rather than sending the same report to everyone.
Never invent certainty
Review generated language for unsupported claims such as confirmed compromise when evidence only shows suspicious activity.
Knowledge transfer
Use Copilot to explain unfamiliar security concepts, telemetry and investigation techniques while analysts work.
Explain KQL
Break queries into operators, filters, joins and expected output, then compare the explanation with actual returned results.
Capture organisational knowledge
Generic AI knowledge cannot replace local context about critical systems, administrators, approved software and business processes.
Improve runbooks
Recurring questions and investigation steps can reveal gaps in internal documentation and procedures.
Improve promptbooks
Convert successful prompt sequences into reusable team workflows with defined validation gates.
Analyst development
Use Copilot as an interactive learning aid that explains reasoning rather than simply providing conclusions.
Junior analysts
Explain concepts and suggest investigation pivots while requiring the analyst to validate evidence independently.
Experienced analysts
Accelerate repetitive analysis, challenge working theories and explore alternative investigation paths.
Avoid skill atrophy
Analysts should remain capable of reading telemetry, validating KQL and investigating without blindly relying on generated output.
Use Copilot as a challenger
Ask for alternative explanations, contradictory evidence and missing information rather than only support for the current theory.
End-of-shift handover
Organise the current investigation state into a consistent handover that the outgoing analyst validates.
Include current status
State which incidents remain active, contained, awaiting evidence or ready for closure.
Include completed actions
Record containment, remediation, queries, communications and approvals already performed.
Include open questions
Tell the next analyst what is not yet understood, not only what has already been discovered.
Include next actions
Specify the next investigation or response step and its owner where known.
Include confidence
Distinguish confirmed findings from likely interpretations and untested hypotheses.
Include business context
Preserve maintenance windows, critical users, system dependencies and operational constraints across shifts.
Operational guardrails
Define where Copilot may assist, what information may be used, which outputs require review and who approves consequential actions.
Protect sensitive information
Follow organisational requirements for confidential, personal and regulated investigation data.
Use least privilege
Access to security data, plugins and integrated services should match analyst responsibilities.
Preserve auditability
Important investigation decisions and actions should remain attributable to authorised people and systems.
Keep humans in the loop
High-impact containment, identity, endpoint and cloud actions should follow the organisation's approval process.
Common mistake: emergency-only use
Analysts gain more value when familiar Copilot workflows are practised during normal operations.
Common mistake: summarising everything
Large summaries without a specific operational question can add noise instead of reducing it.
Common mistake: copy and paste operations
Moving generated text between systems without validation can propagate incorrect conclusions.
Common mistake: no shared standards
If every analyst prompts differently, investigation quality and handovers may become inconsistent.
Common mistake: measuring prompt count
Prompt volume says little about investigation quality, time saved or security outcomes.
Common mistake: accepting the first answer
Operational investigations usually require iterative prompts, source review and alternative hypotheses.
Build team prompt standards
Define reusable structures for incident summaries, hunting, handovers, reporting and evidence validation.
Build review gates
Specify where analysts must verify source evidence before continuing or taking action.
Build a feedback loop
Capture prompts that worked, prompts that failed and situations where Copilot added little value.
Review operational value
Measure whether Copilot reduces repetitive effort while improving consistency, investigation depth and response outcomes.
Final analyst judgement
Security Copilot can become part of the daily SOC rhythm, but evidence, context and authorised human judgement remain the foundation.
Example start-of-shift prompt
For each active incident include:
1. Incident identifier and current severity
2. Affected users, devices and resources
3. Confirmed findings only
4. Actions completed during the previous shift
5. Outstanding investigation questions
6. Missing or incomplete telemetry
7. Current containment status
8. Next recommended investigation step
9. Assigned owner where available
10. Confidence and alternative explanations
Separate confirmed evidence from inference.
Do not mark an incident resolved unless source data supports closure.
Agent Foskett investigation: “The night shift knew something I didn't”
↓
The handover note said: “likely VPN — monitor”
↓
Agent Foskett used Copilot to organise the overnight evidence
↓
The sign-in was followed by a new OAuth consent
↓
A mailbox rule appeared shortly afterwards
↓
The wider sequence had not survived the handover
↓
The original evidence was checked again
↓
The OAuth application was not approved
↓
The mailbox rule redirected selected messages
↓
The incident was escalated and tokens were revoked
↓
The application and malicious rule were removed
↓
The handover template was changed
↓
Every shift now recorded evidence, uncertainty and the next unanswered question
Daily operations checklist
| Stage | Question | Validation action |
|---|---|---|
| Start of shift | What changed? | Compare summaries with incident records. |
| Priority | What needs attention first? | Confirm severity and business impact. |
| Investigation | What supports the theory? | Open source telemetry. |
| Hunting | What should we search for elsewhere? | Validate KQL and scope. |
| Reporting | Who needs the information? | Match detail to audience. |
| Handover | What remains unresolved? | Record confidence, owners and next actions. |
| Governance | Were significant actions approved? | Preserve decisions and audit records. |
Key takeaways
- Integrate Security Copilot into defined SOC processes.
- Preserve evidence, uncertainty, ownership and next actions in handovers.
- Use Copilot to accelerate incident review, hunting, KQL and reporting.
- Validate generated claims against original telemetry.
- Use Copilot to strengthen knowledge transfer and analyst development.
- Standardise useful prompts and validation gates.
- Protect sensitive information and preserve auditability.
- Measure security outcomes and analyst efficiency rather than prompt volume.
- Keep human judgement responsible for consequential decisions.
Related Agent Foskett resources
Continue Module 4 — Operational Security Copilot
Security Copilot in daily SOC operations
Security Copilot can assist with shift handovers, incident review, hunting, reporting, knowledge transfer and analyst development while analysts validate evidence and retain responsibility for decisions.
