Skip to content
Looking for the Security Operations help?

Cases in Sophos MDR

This page explains how case management works in Sophos MDR. It covers how cases change from legacy MDR, the differences between customer-managed and Sophos-managed cases, and what actions you can take in each scenario.

Overview

A case can be managed in one of the following ways:

  • Customer-managed: You manage the case and have access to all fields and capabilities available in the case. The Sophos MDR team doesn't work on the case.
  • Sophos-managed: The Sophos MDR team manages the case. Only MDR analysts have access to all fields and capabilities.

When a case becomes customer-managed or Sophos-managed, this setting cannot be changed. To switch ownership, you must create a new case.

Key changes

The new Sophos MDR introduces the following case management updates:

  • You explicitly choose who manages a case when you create it manually.
  • Automatically created cases require Managed By to be set before the Manage Case controls are available.
  • Only Investigation and Other case types can be customer-managed. All other case types are Sophos-managed.
  • Managed By can't be changed after it's set.
  • Key findings and comments can still be edited before Managed By is set.

Case management

A case can be managed by Sophos MDR or by your organization. This is shown by one of the following Managed By values:

  • Self: This is a customer-managed case. Your organization manages the case and can use the fields and workflow actions available for that case type.
  • Sophos MDR: This is a Sophos-managed case. Some fields and workflow actions are restricted to the MDR team.

Warning

After you set Managed By, it can't be changed. Make sure you choose the correct option before continuing.

The assignee of a case identifies the user or group responsible for the next action. Changing the assignee doesn't change Managed By.

How Managed By is set

How a case is created determines how Managed By is set:

  • Manually created cases: You must set Managed By when creating the case. Some case types are set to Sophos-managed automatically. See Create and add to cases.
  • Cases automatically created from Sophos rules: You must set Managed By before the Manage Case controls are available. See Set who manages an MDR case.
  • Cases automatically created from customer rules: Managed By is set to Self automatically. See Automatic cases.
  • Split cases: You must set Managed By using the same rules that apply to manually created cases. See Split and merge cases.

For details on setting who manages a case, see Set who manages an MDR case.

Additional case management details:

  • The Self value is only available for Investigation and Other case types. All other MDR case types are Sophos-managed.
  • If two users try to set Managed By at the same time, the first saved value is used.
  • Until Managed By is set, case management actions are unavailable.
  • You can still edit key findings and comments before Managed By is set.

MDR case type behavior

MDR cases use the following case types and management options.

Case type Customer-created? Managed By options
Investigation Yes Sophos or Customer
Other Yes Sophos or Customer
Threat Hunt Yes Sophos only
Health Check Yes Sophos only
Incident No Sophos only

If your tenant shows other MDR-related case types, they are Sophos-managed unless the case type specifically allows Self as a Managed By option.

Customer-managed cases

In a customer-managed case, your organization manages the investigation. You can do the following actions, depending on the case type and your permissions:

  • Update the case status to available values.
  • Assign the case to users in your tenant.
  • Add comments, links, and attachments.
  • Perform response actions.
  • Manage the investigation workflow.
  • Split or merge cases, when the action is available for the case.

Sophos-managed cases

In a Sophos-managed case, some fields and actions are unavailable to customer users.

You can close the case when closure is available. Other actions, such as changing status, editing key findings, adding evidence, or changing restricted case details, may be unavailable.

Allowed actions

The following actions are available:

  • View case details.
  • Add comments and collaborate with Sophos.
  • Reassign the case to Sophos.
  • Close the case.

Restricted actions

The following actions are unavailable:

  • Split or merge cases.
  • Change the case status, except for closing the case.
  • Add new evidence, such as events or detections.
  • Edit key findings.

Case status and verdict

Cases may show the following statuses, depending on the case type:

Status Description
New The case has been created.
In Progress The case is in progress.
Customer Action Required The case is waiting for customer action.
Awaiting Sophos Assignment The case is waiting for the MDR team to assign it internally.
Closed The case is closed.
Case verdict Description
True Positive – Benign Activity was correctly identified, but it either doesn't compromise the targeted system or data, or it's been mitigated.
True Positive – Malicious A confirmed security incident. Activity indicates that your organization's systems or data have been compromised or that measures put in place to protect them have failed.
Inconclusive Activity might be valid, but remediation actions might not be possible.
False Positive Activity that is misidentified and non-malicious.

Close a case

When you close a case, its related detections are resolved and labeled based on the verdict you choose. For MDR customers, the verdicts and their corresponding detection labels are as follows:

Case verdict Detection resolution status
True Positive – Benign True Positive – Benign
True Positive – Malicious True Positive – Malicious
Inconclusive Not Actionable
False Positive False Positive

Reopen a case

Within 30 days after a case is closed, you can reopen the case in these ways:

  • Sophos-managed case: Tag Sophos (@sophos) in a comment on the case.
  • Customer-managed case: Change the status of the case from Closed.

After 30 days, the case cannot be reopened. You must create a new case.

Notifications and inactivity rules

For Sophos-managed cases, if action is needed from you, the MDR team sets the case status to Customer Action Required. This starts the inactivity timer.

If you don't take action on the case, the following happens:

  • You receive an email reminder every 24 hours until you take action.
  • The case is automatically closed after five days of inactivity.

Actions that reset the inactivity timer

If you take one of the following actions, the inactivity timer resets to zero and starts again:

  • Add a comment.
  • Perform a response action.
  • Change the assignee.
  • Add a link or attachment.

Best practices

Follow these best practices while working with cases in Sophos MDR:

  • Decide early who should manage the case. This can't be changed later.
  • Take action promptly on Sophos-managed cases to avoid automatic closure.
  • Use comments (including @sophos) to collaborate and re-engage the MDR team when needed.
  • Choose the most appropriate case type when creating a new case to ensure efficient handling.