Copilot - Plugin Enabled After Being Disabled

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Detects when a Copilot plugin is re-enabled after being previously disabled. This could indicate a possible attacker restoring their backdoor. This rule identifies security control bypass scenarios where disabled plugins are reactivated, potentially indicating malicious activity or policy violations.

Attribute Value
Type Hunting Query
Solution Microsoft Copilot
ID b2c3d4e5-f6a7-48b9-c0d1-e2f3a4b5c6d7
Severity Medium
Tactics DefenseEvasion
Techniques T1562
Required Connectors MicrosoftCopilot
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
CopilotActivity ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries · Back to Microsoft Copilot