Exercise: Investigate and respond with Security Copilot

Completed

In this exercise, you investigate a security incident using Microsoft Security Copilot by launching a simulated phishing attack, then using Copilot to analyze the resulting alerts and generate remediation recommendations.

Exercise scenario

You're a security analyst at Contoso Healthcare preparing for an upcoming security audit. To validate your incident response capabilities and test Microsoft Security Copilot, you'll launch a simulated phishing attack using Attack Simulation Training, allow it to generate security alerts, then use Copilot to investigate the "incident" as if it were real.

This exercise demonstrates real-world investigation workflows while ensuring no actual security risks to your environment.

Prerequisites

Before starting this exercise, ensure you have:

  • Microsoft 365 E5, A5, or Microsoft Defender for Office 365 Plan 2 license
  • Access to Microsoft Defender portal (https://security.microsoft.com)
  • Security Copilot enabled in your tenant with at least 1 SCU provisioned
  • Security Administrator or Security Operator role
  • At least one test user account you can target with simulation (can be your own account)

Important

This exercise uses Attack Simulation Training, which generates real alerts without actual security risk. The simulated attacks are safe and will not compromise your environment.

Task 1: Launch a simulated phishing attack

Step 1: Navigate to Attack Simulation Training

  1. Open Microsoft Defender portal: https://security.microsoft.com
  2. Sign in with your admin credentials
  3. Go to Email & collaboration > Attack simulation training
  4. Select Simulations tab

Step 2: Create a new phishing simulation

  1. Select + Launch a simulation
  2. Select technique: Choose Credential Harvest
    • This simulates a phishing email that attempts to steal credentials
  3. Select Next

Step 3: Name your simulation

  1. Simulation name: Copilot Investigation Exercise - Credential Harvest
  2. Description: Simulated phishing attack for testing Copilot investigation capabilities
  3. Select Next

Step 4: Select payload

  1. Choose a pre-built payload or select Create a payload
  2. For quick setup, select a built-in payload like:
    • "Password expiring" themed email
    • "IT Security Alert" themed email
  3. Review the payload preview to see what the phishing email looks like
  4. Select Next

Step 5: Target users

  1. Include users and groups:
    • Select Add users or Add groups
    • Add your test user account (or yourself if using your own tenant)
    • Recommended: Add 2-3 test users to generate multiple alerts
  2. Select Next

Step 6: Configure landing page

  1. Choose Microsoft default landing page (Credential Harvest)
    • This simulates a fake login page
  2. Select Next

Step 7: Configure end user training (optional)

  1. For this exercise, select No training to focus on investigation
    • In production, you'd assign training to users who open the link
  2. Select Next

Step 8: Schedule simulation

  1. Launch details: Select Launch this simulation as soon as I'm finished
    • Simulated emails will be sent immediately
  2. Select Next

Step 9: Review and launch

  1. Review all simulation settings
  2. Select Submit to launch the simulation

Result: Simulated phishing emails are sent to target users. These emails will generate alerts when users interact with them.

Note

It may take 5-15 minutes for simulated emails to arrive and generate alerts. You can proceed to Task 2 while waiting.

Task 2: Wait for and verify simulation delivery

Step 1: Check simulation status

  1. In Attack simulation training, go to Simulations tab
  2. Find your simulation: "Copilot Investigation Exercise - Credential Harvest"
  3. Status should show In progress or Completed
  4. Select the simulation name to view details

Step 2: Check for delivered emails

  • View the Simulation report to see:
    • Users targeted
    • Emails delivered
    • Users who opened the email
    • Users who clicked the link

Step 3: (Optional) Select the simulated phishing link yourself

If you included yourself as a target:

  1. Check your email inbox for the simulated phishing email
  2. Open the email (safe - it's a simulation)
  3. Select the phishing link (safe - goes to Microsoft-controlled landing page)
  4. On the fake login page, enter fake credentials (e.g., username: test, password: test123)
  5. Submit the fake form

This interaction generates security alerts that Copilot can investigate.

Verification: Simulation status should show at least one user clicked or submitted credentials.

Task 3: Locate the security alerts generated by simulation

Step 1: Navigate to Alerts

  1. In Microsoft Defender portal, go to Incidents & alerts > Alerts
  2. Look for alerts related to your simulation, such as:
    • "Phishing simulation link clicked"
    • "Simulated attack email opened"
    • "User submitted credentials on simulation landing page"

Step 2: Check for auto-generated incident

  1. Go to Incidents & alerts > Incidents
  2. Look for an incident that may have been automatically created
  3. If no incident exists, you can manually create one (see Step 3)

Step 3: Create an incident from alerts (if needed)

If alerts weren't automatically grouped into an incident:

  1. Go to Alerts queue
  2. Select the checkbox next to simulation-related alerts
  3. Select Create incident at the top
  4. Incident name: Simulated Credential Harvest Investigation
  5. Severity: Medium
  6. Select Create incident

Result: You now have an incident to investigate using Copilot.

Task 4: Investigate the incident with Security Copilot

Step 1: Open the incident

  1. Go to Incidents & alerts > Incidents
  2. Select on your incident: "Simulated Credential Harvest Investigation"
  3. The incident details page opens

Step 2: Open Copilot and review automatic summary

  1. Look for the Copilot pane on the right side of the screen
    • If not visible, select the Copilot button in the top-right corner
  2. Review Copilot's automatic incident summary

Expected summary content:

  • Attack type: Credential harvest phishing simulation
  • Affected users: [List of users who received the email]
  • Timeline: When emails were sent, opened, clicked
  • Status: Simulation (marked as safe, not actual threat)

Step 3: Ask Copilot clarifying questions

In the Copilot prompt bar, try these natural language queries:

Prompt 1: "Which users clicked the phishing link?"

Expected response: Lists users who clicked, with timestamps.

Prompt 2: "Did any users submit credentials on the fake login page?"

Expected response: Shows which users entered data on the simulation landing page.

Prompt 3: "What was the content of the phishing email?"

Expected response: Describes the email theme, sender, subject line, and social engineering tactics used.

Prompt 4: "What domains or URLs were used in this attack?"

Expected response: Lists the URLs from the phishing email and landing page (Microsoft-controlled simulation domains).

Step 4: Analyze the attack chain

Prompt: "Explain the attack chain for this incident"

Expected response: Copilot describes the sequence of events:

  1. Phishing email sent with urgent message
  2. User opened email
  3. User clicked link in email
  4. User redirected to fake login page
  5. User entered credentials (if applicable)

Verification: You should understand the complete attack flow and user interactions.

Task 5: Assess user risk and behavior

Step 1: Check user security posture

Prompt: "Are the affected users high-risk accounts?"

Expected response: Copilot may check Microsoft Entra ID to determine if affected users have:

  • Administrator privileges
  • Access to sensitive data
  • History of risky sign-ins

Prompt: "Has [username] clicked phishing links before?"

Expected response: Shows historical simulation results or real phishing attempts for that user.

Step 2: Evaluate organizational risk

Prompt: "How many users in the organization would likely fall for this phishing attack?"

Expected response: Based on simulation results and click rates, Copilot estimates organizational vulnerability.

Step 3: Compare to industry benchmarks

Prompt: "How does our phishing susceptibility compare to industry average?"

Expected response: Copilot may provide context on typical click rates and how your organization compares.

Verification: You should understand which users are most vulnerable to social engineering attacks.

Task 6: Generate remediation recommendations

Step 1: Ask for response actions

Prompt: "What actions should I take to reduce phishing risk?"

Expected response: Copilot provides recommendations such as:

  • Enroll users who clicked in security awareness training
  • Deploy anti-phishing policies in Microsoft Defender for Office 365
  • Enable additional email authentication (SPF, DKIM, DMARC)
  • Configure safe links and safe attachments policies
  • Implement multifactor authentication (MFA) for all users

Step 2: Request specific policy configurations

Prompt: "How do I configure anti-phishing policies to block similar attacks?"

Expected response: Step-by-step guidance to:

  1. Navigate to Microsoft Defender portal > Email & collaboration > Policies & rules
  2. Create or edit anti-phishing policy
  3. Enable impersonation protection
  4. Configure mailbox intelligence settings
  5. Set actions for detected phishing (quarantine, move to junk folder)

Step 3: Get training recommendations

Prompt: "What training should I assign to users who clicked the link?"

Expected response: Specific Microsoft training modules or custom training content recommendations.

Verification: You should have a clear remediation plan to reduce future phishing risk.

Exercise summary

In this exercise, you:

  • Launched a simulated phishing attack using Attack Simulation Training
  • Generated real security alerts without compromising your environment
  • Investigated the simulated incident using Security Copilot's natural language interface
  • Asked clarifying questions to understand attack details and user behavior
  • Assessed organizational phishing risk and identified vulnerable users
  • Generated remediation recommendations for policies and training

Key takeaways:

  • Attack Simulation Training provides safe, realistic scenarios for practicing incident response
  • Security Copilot uses natural language queries to simplify complex security investigations
  • AI-powered analysis helps identify affected users, understand attack patterns, and assess organizational risk
  • Copilot generates actionable remediation recommendations based on investigation findings
  • Combining simulated attacks with Copilot investigation creates repeatable security validation workflows

Troubleshooting

Issue: Copilot doesn't show incident summary automatically
Solution: Ensure Security Copilot is enabled and you have at least 1 SCU provisioned. Check that Microsoft Defender XDR plugin is turned on in Copilot settings.

Issue: "Attack Simulation Training is not available"
Solution: Verify you have Microsoft 365 E5/A5 or Defender for Office 365 Plan 2 license. Attack Simulation Training is not available in all license tiers.

Issue: Simulated emails are not generating alerts
Solution: Wait 15-30 minutes after simulation launch. Check that Defender for Office 365 policies are not blocking simulation emails. Verify users actually clicked the phishing link.

Issue: Cannot find simulation-related alerts
Solution: In Alerts queue, use filter "Source: Attack simulation" or search for "simulation" in alert titles. Alerts may be categorized as Informational severity.

Issue: Copilot says "I don't have enough information"
Solution: Be more specific in your prompts. Include simulation names, user names, or time ranges. Try asking "Show me alerts from the past 24 hours related to phishing."

Issue: No incident was created from simulation alerts
Solution: Manually create an incident by selecting alerts and clicking "Create incident." Group all simulation-related alerts together.

Next steps

With hands-on investigation experience using simulated attacks, you're ready to test your knowledge in the knowledge check unit and review key takeaways in the module summary.