logo

Reconstructing AI activity in investigations 

ID: a0624091-da50-5d12-a5e1-e04692a8c0b8

STIX ID: report--a0624091-da50-5d12-a5e1-e04692a8c0b8

Feed Name: Microsoft Security

Date Published: 2026-06-09

Date Updated: 2026-06-10

Author: Phillip Misner and Microsoft AI Red Team

...
...

The report introduces a Microsoft investigator playbook for Microsoft 365 Copilot and Azure AI services that standardizes how security teams reconstruct AI interactions using telemetry from Purview, Defender, and Sentinel. It outlines a scope–context–signal methodology, provides KQL queries, schema references, and detection patterns, and helps investigators determine what happened, what data was accessed, and whether activity indicates normal use, policy violations, or compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.