Pith. sign in

REVIEW 2 cited by

AI-Driven Guided Response for Security Operation Centers with Microsoft Copilot for Security

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2407.09017 v4 pith:PHI65UDP submitted 2024-07-12 cs.LG cs.CRcs.IR

classification cs.LGcs.CRcs.IR
keywords securityacrossincidentsevaluationguidedmicrosoftpositiveresponse
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Security operation centers contend with a constant stream of security incidents, ranging from straightforward to highly complex. To address this, we developed Microsoft Copilot for Security Guided Response (CGR), an industry-scale ML architecture that guides security analysts across three key tasks -- (1) investigation, providing essential historical context by identifying similar incidents; (2) triaging to ascertain the nature of the incident -- whether it is a true positive, false positive, or benign positive; and (3) remediation, recommending tailored containment actions. CGR is integrated into the Microsoft Defender XDR product and deployed worldwide, generating millions of recommendations across thousands of customers. Our extensive evaluation, incorporating internal evaluation, collaboration with security experts, and customer feedback, demonstrates that CGR delivers high-quality recommendations across all three tasks. We provide a comprehensive overview of the CGR architecture, setting a precedent as the first cybersecurity company to openly discuss these capabilities in such depth. Additionally, we release GUIDE, the largest public collection of real-world security incidents, spanning 13M evidences across 1M incidents annotated with ground-truth triage labels by customer security analysts. This dataset represents the first large-scale cybersecurity resource of its kind, supporting the development and evaluation of guided response systems and beyond.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. SHIELD: APT Detection and Intelligent Explanation Using LLM

    cs.CR 2025-02 conditional novelty 6.0 of 10

    SHIELD combines LOF anomaly detection, provenance graph clustering, and LLM chain-of-thought analysis to detect APT attacks and generate interpretable kill-chain summaries.

  2. Rule-ATT&CK Mapper (RAM): Mapping SIEM Rules to TTPs Using LLMs

    cs.CR 2025-02 conditional novelty 6.0 of 10

    A multi-stage LLM agent pipeline (RAM) maps structured SIEM rules to MITRE ATT&CK techniques, achieving AR 0.75 and AP 0.52 with GPT-4-Turbo on recent Splunk rules.

Pith tools