Purple Team

CRT02 Using Security Copilot and Defender XDR to Streamline Your SOC

11/18/2025

9:15am - 10:30am

Level: Introductory to Intermediate

John O'Neill, Sr.

Chief Technologist

AWS Solutions

In this focused 75-minute session, we’ll explore the integration and optimization of Microsoft Security Copilot and Defender XDR within a Security Operations Center (SOC) environment. The session will impart actionable knowledge on leveraging the AI-driven capabilities of Security Copilot alongside the extended detection and response (XDR) features of Defender XDR to enhance threat detection, automate responses, and streamline security workflows. By the end of the session, participants will be equipped with knowledge of advanced techniques to utilize these powerful tools in unison, significantly improving their organization's security posture while reducing the operational load on their security teams.

You will learn:

  • About configuring and tuning Defender XDR for threat monitoring
  • About correlating and analyzing security data with Security Copilot
  • About creating synergistic defenses that accelerates incident response times