Reconstructing AI activity in investigations
ID: a0624091-da50-5d12-a5e1-e04692a8c0b8
STIX ID: report--a0624091-da50-5d12-a5e1-e04692a8c0b8
Feed Name: Microsoft Security
Date Published: 2026-06-09
Date Updated: 2026-06-10
Author: Phillip Misner and Microsoft AI Red Team
The report introduces a Microsoft investigator playbook for Microsoft 365 Copilot and Azure AI services that standardizes how security teams reconstruct AI interactions using telemetry from Purview, Defender, and Sentinel. It outlines a scope–context–signal methodology, provides KQL queries, schema references, and detection patterns, and helps investigators determine what happened, what data was accessed, and whether activity indicates normal use, policy violations, or compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
