Automate·Advanced·45 min·Updated Sep 30, 2026

Investigate a security incident and draft the response timeline

Use Security Copilot to support an incident investigation and produce a structured, defensible response timeline as the investigation unfolds.

Download PDF

Microsoft 365

Prerequisites

Active access to the relevant security logs and alert data for the incident under investigation

Business Outcome

Faster, more complete incident documentation during and after a security event, when accuracy and speed both matter.

Handle with care

Security incident detailsAccount/log data

This timeline links real account identifiers, sign-in logs, and attack-pattern details — exactly what an active attacker would want if it leaked mid-investigation. Keep it restricted to the incident response team until the investigation closes, even internally.

Workflow Overview

The apps run in this order.

Word
Teams
Security Copilot

Step 1: Start the timeline the moment the incident is confirmedScSecurity Copilot

Have Security Copilot begin correlating alerts and log entries around the incident's start time as soon as it's confirmed, rather than reconstructing the timeline from memory after the fact.

Step 2: Ask for a structured, evidence-linked timelineScSecurity Copilot

Request specific timestamped entries — first alert, actions taken, systems affected, containment steps — each linked back to the source log or alert, not a narrative summary that can't be individually verified.

Prompt idea:

Build an incident timeline for the suspicious login activity flagged on account jdoe@company.com starting at 2:14am. Pull the relevant sign-in logs and alert data, and list each event with its exact timestamp and source log reference.

Step 3: Update it live as the investigation progressesScSecurity Copilot

Keep feeding new findings and containment actions into the same timeline as the response continues, rather than building a separate summary at the end that has to be reconciled with real-time notes.

Step 4: Have the incident lead validate before it's finalizedWord

Export the timeline into Word and have the incident lead read it against the raw logs entry by entry, not just skim for overall plausibility.

This becomes the official record for the post-incident review and any external or regulatory reporting, so an unverified timestamp or misattributed action here carries real consequences later.

Check the work

  • Verify every timestamped entry against the actual source log — an incident timeline with an inaccurate detail undermines the whole investigation.
  • Confirm no gap in the timeline was silently filled with an assumption instead of being marked as unknown.
  • Cross-check the timeline against any parallel notes taken by responders during the live incident.

Source: Microsoft Copilot Scenario Library — IT (2026)

Expected Outcome

A structured, evidence-linked timeline of the incident — detection, actions taken, resolution — ready for the post-incident review.

✓

AI is the right call here

Pulling a specific account's sign-in logs for a time window is a filtered query. Correlating that against alert data from separate systems into one coherent, evidence-linked timeline as a live investigation unfolds is the synthesis a single log query doesn't give you.

Related Workflows

Related Playgrounds

WORK WITH LIMINALS

Ready to roll this out beyond one person?

Workflows like this tend to raise real governance and licensing questions once more than one person is using them — that's exactly what we help with.