Security

Security Copilot

Microsoft · #2 most active of 8 in Security

Compare →

Security-specific copilot wired into Defender, Sentinel, Intune and Entra.

100

Trust score · Verified

2 data points checked · 2026-09-06

Model stack: VerifiedEntry price: UnverifiableVersion: VerifiedHow this works →

Current version

Security Copilot

Entry cost

from $4/mo

Changes / 30d

9

The short answers · verified September 12, 2026

What is the latest version of Security Copilot?
The current shipped version of Security Copilot is Security Copilot, as of September 12, 2026.
How much does Security Copilot cost?
Security Copilot starts at $4 per month on its cheapest paid tier, as of September 12, 2026.
What AI model does Security Copilot use?
Security Copilot runs primarily on Specialized language model.

Source: Microsoftwww.microsoft.com · Reusable under CC BY 4.0 — cite Tomorrow

Capabilities

  • Incident summarization
  • KQL generation
  • Agent library
  • Defender integration
  • Security Copilot Agents
  • Phishing Triage Agent
  • Conditional Access Optimization Agent
  • Incident Summarization
  • Response Guidance
  • Natural Language Translation to KQL
  • Script Reverse-Engineering
  • Stakeholder Reporting
  • Partner Plugins
  • agentic automation
  • incident triage
  • vulnerability remediation
  • phishing triage
  • script building
  • stakeholder reporting
  • natural language translation
  • Security Copilot agents
  • Phishing triage
  • Vulnerability remediation
  • Alert triage
  • Natural language translation for scripts
  • Stakeholder reporting
  • SIEM integration
  • multi-agent workflows
  • alert triage
  • reverse-engineering scripts
  • embedded skills
  • promptbooks
  • Multi-agent workflows
  • Script translation
  • Threat hunting
  • AI agents
  • Triage complex alerts
  • Step-by-step response guidance
  • phishing triage agent
  • incident investigation
  • script reverse-engineering
  • partner-built agents
  • community-built agents
  • agents
  • script generation
  • threat hunting
  • Script generation
  • Reverse-engineering scripts
  • Natural language queries
  • Agents
  • Incident Investigation
  • Phishing Triage
  • Alert Triage
  • Vulnerability Remediation
  • Microsoft Sentinel Integration
  • Microsoft Defender Integration
  • Microsoft Intune Integration
  • Script building
  • Script reverse-engineering
  • Natural language translation
  • Threat intelligence
  • Embedded AI skills
  • Promptbooks
  • Incident investigation
  • Script building and reverse-engineering
  • remediation guidance
  • natural language query translation
  • Phishing triage agent
  • Remediation guidance
  • Natural language query translation
  • Third-party integrations
  • malware script translation
  • plugins
  • Incident investigation and remediation
  • natural language queries
  • incident context summaries
  • AI-driven guidance
  • Natural language translation to script
  • Natural language KQL generation
  • security-specific skills
  • Conditional access optimization agent
  • Custom agent builder
  • Building and reverse-engineering scripts
  • Natural language script translation
  • Incident summary
  • Step-by-step remediation guidance
  • AI-powered cybersecurity
  • malware analysis
  • Security agents
  • Incident reporting
  • Script Building
  • Natural Language Translation
  • global threat intelligence
  • script translation
  • natural language query generation
  • incident summarization

Pricing

Paid capacity provisioning required, or included in Microsoft 365 E5/E7 plans. Pricing details not explicitly published on this page.

Entry price over time

8/7/2026 · $49/12/2026 · $4

Geek mode

Models under the hood

  • Specialized language model

    Provider undisclosed

    disclosed
  • Specialized language model with security-specific capabilities

    Microsoft

    inferred
  • Specialized security language model

    Microsoft

    inferred
  • specialized security-specific language model

    Microsoft

    inferred

Context window

Public API

yes

Multi-model routing

no

Shared model stack

Other tracked products running on the same foundation models — a quick read on how much of the catalog moves when one of these models changes.

  • Specialized language modelProvider undisclosed · 1 product
  • Specialized language model with security-specific capabilitiesMicrosoft · 1 product
  • Specialized security language modelMicrosoft · 1 product
  • specialized security-specific language modelMicrosoft · 1 product

green disclosed · amber inferred · grey unattributed. Aliases are folded into one model; provider concentration counts only models with an established vendor.

Reported scale

Reference data. Each figure is whatever the source actually said — weekly users, downloads, revenue run-rate — with its own definition and date. These are not comparable between tools and are never used to rank anything.

No public usage figure on record for this product.

Public market scorecard

Microsoft investor relations

Microsoft trades as NASDAQ: MSFT. Figures below are as reported for Q4 FY2026 on Jul 29, 2026; market levels are the close on Aug 6, 2026 and are a reference marker, not a live quote.

Q4 FY2026 revenue

$81B

+17% YoY

Azure growth
~+34% YoY
AI services a large share of the beat
Microsoft 365 Copilot
majority of Fortune 500
company stated
Capex
~$30B in the quarter

Market reference

Share price~$520
12-month change+22%
Market cap~$3.9T
Live quote

Also in Security

All Security
Charlotte AI

CrowdStrikeUnited States

17

Agentic SOC analyst

Version
Charlotte AI
Cost
Free for qualifying CrowdStrike customers (50 credits/mo). Paid pricing not published.
Model
Bring your own models / choice of models
Cortex AgentiX

Palo Alto NetworksUnited States

8

Agentic security automation

Version
Cortex AgentiX
Cost
Pricing is not publicly listed. Contact Palo Alto Networks to request a demo and get a custom quote.
Model
Undisclosed
Torq HyperSOC

TorqIsrael

8

Autonomous SOC fabric

Version
Torq AI SOC Platform
Cost
Pricing is not publicly listed. Contact sales / request a demo for pricing.
Model
Torq SOC Brain
Dropzone AI

Dropzone AIUnited States

6

Autonomous alert investigation

Version
Agentic SOC
Cost
Pricing is not publicly listed. Contact for demo.
Model
LLM
Wiz Defend

WizUnited States

4

Cloud detection and response

Version
Wiz Defend
Cost
Pricing not publicly listed. Contact Wiz for a demo/quote.
Model
Undisclosed
Abnormal AI

Abnormal SecurityUnited States

2

Behavioral email defense

Version
Attune AI
Cost
Pricing is not publicly listed. Contact Abnormal Security to request a demo and custom quote.
Model
Attune AI

Change history

  • capability

    New capabilities: natural language query generation, incident summarization

    94 tracked96 tracked · +natural language query generation, incident summarization

    source
  • capability

    New capabilities: global threat intelligence, script translation

    92 tracked94 tracked · +global threat intelligence, script translation

    source
  • model

    Security Copilot added Specialized language model with security-specific capabilities to its model stack

    Specialized language model, Specialized security language model, specialized security-specific language modelSpecialized language model, Specialized language model with security-specific capabilities, Specialized security language model, specialized security-specific language model

    source
  • capability

    New capabilities: Script Building, Natural Language Translation

    90 tracked92 tracked · +Script Building, Natural Language Translation

    source
  • capability

    New capabilities: Security agents, Incident reporting

    88 tracked90 tracked · +Security agents, Incident reporting

    source
  • capability

    New capabilities: AI-powered cybersecurity, malware analysis

    86 tracked88 tracked · +AI-powered cybersecurity, malware analysis

    source
  • capability

    New capabilities: Natural language script translation, Incident summary, Step-by-step remediation guidance

    83 tracked86 tracked · +Natural language script translation, Incident summary, Step-by-step remediation guidance

    source
  • capability

    New capabilities: Building and reverse-engineering scripts

    82 tracked83 tracked · +Building and reverse-engineering scripts

    source
  • capability

    New capabilities: Conditional access optimization agent, Custom agent builder

    80 tracked82 tracked · +Conditional access optimization agent, Custom agent builder

    source
  • capability

    New capabilities: security-specific skills

    79 tracked80 tracked · +security-specific skills

    source
  • capability

    New capabilities: Natural language KQL generation

    78 tracked79 tracked · +Natural language KQL generation

    source
  • capability

    New capabilities: Natural language translation to script

    77 tracked78 tracked · +Natural language translation to script

    source
  • capability

    New capabilities: AI-driven guidance

    76 tracked77 tracked · +AI-driven guidance

    source
  • capability

    New capabilities: incident context summaries

    75 tracked76 tracked · +incident context summaries

    source
  • capability

    New capabilities: natural language queries

    74 tracked75 tracked · +natural language queries

    source
  • capability

    New capabilities: Incident investigation and remediation

    73 tracked74 tracked · +Incident investigation and remediation

    source
  • capability

    New capabilities: malware script translation, plugins

    71 tracked73 tracked · +malware script translation, plugins

    source
  • capability

    New capabilities: Phishing triage agent, Remediation guidance, Natural language query translation

    67 tracked71 tracked · +Phishing triage agent, Remediation guidance, Natural language query translation, Third-party integrations

    source
  • capability

    New capabilities: remediation guidance, natural language query translation

    65 tracked67 tracked · +remediation guidance, natural language query translation

    source
  • capability

    New capabilities: Embedded AI skills, Promptbooks, Incident investigation

    61 tracked65 tracked · +Embedded AI skills, Promptbooks, Incident investigation, Script building and reverse-engineering

    source
  • capability

    New capabilities: Threat intelligence

    60 tracked61 tracked · +Threat intelligence

    source
  • model

    Security Copilot added specialized security-specific language model to its model stack

    Specialized language model, Specialized security language modelSpecialized language model, Specialized security language model, specialized security-specific language model

    source
  • capability

    New capabilities: Script building, Script reverse-engineering, Natural language translation

    57 tracked60 tracked · +Script building, Script reverse-engineering, Natural language translation

    source
  • capability

    New capabilities: Agents, Incident Investigation, Phishing Triage

    49 tracked57 tracked · +Agents, Incident Investigation, Phishing Triage, Alert Triage, Vulnerability Remediation, Microsoft Sentinel Integration, Microsoft Defender Integration, Microsoft Intune Integration

    source
  • capability

    New capabilities: Script generation, Reverse-engineering scripts, Natural language queries

    46 tracked49 tracked · +Script generation, Reverse-engineering scripts, Natural language queries

    source
  • capability

    New capabilities: agents, script generation, threat hunting

    43 tracked46 tracked · +agents, script generation, threat hunting

    source
  • capability

    New capabilities: phishing triage agent, incident investigation, script reverse-engineering

    38 tracked43 tracked · +phishing triage agent, incident investigation, script reverse-engineering, partner-built agents, community-built agents

    source
  • capability

    New capabilities: AI agents, Triage complex alerts, Step-by-step response guidance

    35 tracked38 tracked · +AI agents, Triage complex alerts, Step-by-step response guidance

    source
  • capability

    New capabilities: Multi-agent workflows, Script translation, Threat hunting

    32 tracked35 tracked · +Multi-agent workflows, Script translation, Threat hunting

    source
  • model

    Security Copilot added Specialized security language model to its model stack

    Specialized language modelSpecialized language model, Specialized security language model

    source
  • capability

    New capabilities: reverse-engineering scripts, embedded skills, promptbooks

    29 tracked32 tracked · +reverse-engineering scripts, embedded skills, promptbooks

    source
  • capability

    New capabilities: multi-agent workflows, alert triage

    27 tracked29 tracked · +multi-agent workflows, alert triage

    source
  • capability

    New capabilities: Security Copilot agents, Phishing triage, Vulnerability remediation

    20 tracked27 tracked · +Security Copilot agents, Phishing triage, Vulnerability remediation, Alert triage, Natural language translation for scripts, Stakeholder reporting, SIEM integration

    source
  • model

    QA auto-correction: model stack updated to Specialized language model after a unanimous jury read of the source page

    GPT-5, Specialized security language modelSpecialized language model

    source
  • capability

    New capabilities: agentic automation, incident triage, vulnerability remediation

    13 tracked20 tracked · +agentic automation, incident triage, vulnerability remediation, phishing triage, script building, stakeholder reporting, natural language translation

    source
  • version

    Security Copilot moved to Security Copilot

    2026 releaseSecurity Copilot

    source
  • model

    Security Copilot added Specialized security language model to its model stack

    GPT-5GPT-5, Specialized security language model

    source
  • capability

    New capabilities: Security Copilot Agents, Phishing Triage Agent, Conditional Access Optimization Agent

    4 tracked13 tracked · +Security Copilot Agents, Phishing Triage Agent, Conditional Access Optimization Agent, Incident Summarization, Response Guidance, Natural Language Translation to KQL, Script Reverse-Engineering, Stakeholder Reporting, Partner Plugins

    source
Subscribe to Security Copilot changes

Security Copilot compared

Straight head-to-head pages against the busiest products in Security.

How to cite this page

Free to cite and reuse under CC BY 4.0. Permalink: https://tomorrow.aliensquad.ai/tools/security-copilot

APA
Tomorrow. (2026). Security Copilot — version, pricing and model stack [Data set entry]. AlienSquad. Retrieved 2026-09-13, from https://tomorrow.aliensquad.ai/tools/security-copilot
BibTeX
@misc{tomorrow-tools-security-copilot,
  author       = {{Tomorrow}},
  title        = {Security Copilot — version, pricing and model stack},
  year         = {2026},
  publisher    = {AlienSquad},
  howpublished = {\url{https://tomorrow.aliensquad.ai/tools/security-copilot}},
  note         = {Accessed: 2026-09-13}
}