Detect and Respond to Risky AI Data Activity
Close the loop — turn AI audit signals, insider-risk indicators, and communication-compliance findings into investigation and response, bridged into Defender XDR and Sentinel.
Core capabilities
-
Capture the prompt-and-response audit trail that every AI data investigation starts from
-
Identify users with risky AI behavior and correlate the signals into Defender XDR incidents for unified investigation
-
Detect regulatory, inappropriate, or risky content in prompts and responses that policy violations produce
-
Detect jailbreak, prompt-injection, and credential-leak attacks against agents and drive the security response
Supporting capabilities 3
-
Provide the risk context and activity baseline that response teams triage against
-
Preserve and export AI interaction evidence once an incident is confirmed
-
Correlate Copilot and AI activity with broader SIEM telemetry for end-to-end hunting and response