To identify which Microsoft 365 Copilot interactions were performed by the compromised executive account with the minimum administrative effort, you should use Audit (Standard) (or simply Audit) within the Microsoft Purview portal. Reference: https://learn.microsoft.com/en-us/purview/audit-copilot