Skip to content

Active Threat Response

When external API users and MDR/XDR analysts identify malicious devices, they can use Sophos Central APIs to isolate those devices across Sophos Switches and AP6 access points.

MDR/XDR Threat Feed

The MDR/XDR Threat Feed lists isolated hosts across all AP6 access points and Sophos Switches managed in Sophos Central.

Click the radio button next to AP6 to turn ATR on or off for AP6 access points.

Note

Active Threat Response (ATR) overrides any MAC Filtering configured on the access point's SSIDs. You can't use the Allowed list to allow MAC addresses blocked by ATR.

Click the radio button next to Switch to turn ATR on or off for Sophos Switches.

Isolated devices

You can see information about devices connected to your access points and switches.

The MAC address column lists the MAC addresses of devices.

The Switch and AP6 columns show the isolation status of devices:

  • A green check mark Green check mark icon. indicates that a device is isolated.
  • A hyphen Hyphen icon. indicates that a device isn't isolated.