Community guidelines
Be specific and constructive. No vendor spam — promoting your own product belongs in a listing. Anyone can read; posting needs a free account.
Our Microsoft Sentinel rep is pushing Security Copilot as an add on. The demo summarizes alerts, writes KQL queries and suggests next steps. It looks nice, but our problem is noisy data and weak playbooks. Has this actually reduced investigation time for anyone, or does it just write confident summaries of bad alerts??
tbh, it helped with the boring parts, mainly timeline summaries and turning plain English into a first query. It did not fix detection quality. If the alert has missing host context, the AI still has missing host context. We got value only after connecting asset, identity and case data.
Don't let the vendor use mean time to close as the only success metric. People close low value alerts faster and the chart looks amazing. We sampled cases and checked whether the conclusion was supported by evidence. The model invented a cause often enough that analysts still had to verify everything.
That's my concern. I can probably get budget for a pilot, not for another data project. What would you measure in the first month??
Pick two repeatable workflows. Measure analyst time, query edits, missed evidence and wrong recommendations. Keep the model read only. If it cannot show where each claim came from, do not put the summary in the incident record. A narrow win is better than buying an AI tier for every alert.