Microsoft Defender XDR
General

Script analysis with Microsoft Copilot in Microsoft Defender

In brief

The page metadata was refreshed, the device timeline reference was clarified, and the Copilot feedback image description was updated.

What Defender admins need to know

Administrators can use the revised wording to help users find script analysis and identify the Copilot feedback control.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Script analysis with Microsoft Copilot in Microsoft Defender

Key script analysis features

You can access the script analysis capability within the attack story below the incident graph on an incident page and in the device timeline view. For more information, see Investigate the device timeline.

To begin analysis, perform the following steps:

Provide feedback on script analysis

Microsoft highly encourages you to provide feedback to Copilot, as it's crucial for a capability's continuous improvement. You can provide feedback on the results by selecting the feedback icon Screenshot of the feedback control used to submit feedback for Copilot responses in Defender cards. found at the end of the script analysis card.

Related content