Cases in Sophos MDR
This page explains how case management works in Sophos MDR. It covers how cases change from legacy MDR, the differences between customer-managed and Sophos-managed cases, and what actions you can take in each scenario.
Overview
A case can be managed in one of the following ways:
- Customer-managed: You manage the case and have access to all fields and capabilities available in the case. The Sophos MDR team doesn't work on the case.
- Sophos-managed: The Sophos MDR team manages the case. Only MDR analysts have access to all fields and capabilities.
When a case becomes customer-managed or Sophos-managed, this setting cannot be changed. To switch ownership, you must create a new case.
Key changes
The new Sophos MDR introduces the following case management updates:
- You explicitly choose who manages a case when you create it manually.
- Automatically created cases require Managed By to be set before the Manage Case controls are available.
- Only Investigation and Other case types can be customer-managed. All other case types are Sophos-managed.
- Managed By can't be changed after it's set.
- Key findings and comments can still be edited before Managed By is set.
Case management
A case can be managed by Sophos MDR or by your organization. This is shown by one of the following Managed By values:
- Self: This is a customer-managed case. Your organization manages the case and can use the fields and workflow actions available for that case type.
- Sophos MDR: This is a Sophos-managed case. Some fields and workflow actions are restricted to the MDR team.
Warning
After you set Managed By, it can't be changed. Make sure you choose the correct option before continuing.
The assignee of a case identifies the user or group responsible for the next action. Changing the assignee doesn't change Managed By.
How Managed By is set
How a case is created determines how Managed By is set:
- Manually created cases: You must set Managed By when creating the case. Some case types are set to Sophos-managed automatically. See Create and add to cases.
- Cases automatically created from Sophos rules: You must set Managed By before the Manage Case controls are available. See Set who manages an MDR case.
- Cases automatically created from customer rules: Managed By is set to Self automatically. See Automatic cases.
- Split cases: You must set Managed By using the same rules that apply to manually created cases. See Split and merge cases.
For details on setting who manages a case, see Set who manages an MDR case.
Additional case management details:
- The Self value is only available for Investigation and Other case types. All other MDR case types are Sophos-managed.
- If two users try to set Managed By at the same time, the first saved value is used.
- Until Managed By is set, case management actions are unavailable.
- You can still edit key findings and comments before Managed By is set.
MDR case type behavior
MDR cases use the following case types and management options.
| Case type | Customer-created? | Managed By options |
|---|---|---|
| Investigation | Yes | Sophos or Customer |
| Other | Yes | Sophos or Customer |
| Threat Hunt | Yes | Sophos only |
| Health Check | Yes | Sophos only |
| Incident | No | Sophos only |
If your tenant shows other MDR-related case types, they are Sophos-managed unless the case type specifically allows Self as a Managed By option.
Customer-managed cases
In a customer-managed case, your organization manages the investigation. You can do the following actions, depending on the case type and your permissions:
- Update the case status to available values.
- Assign the case to users in your tenant.
- Add comments, links, and attachments.
- Perform response actions.
- Manage the investigation workflow.
- Split or merge cases, when the action is available for the case.
Sophos-managed cases
In a Sophos-managed case, some fields and actions are unavailable to customer users.
You can close the case when closure is available. Other actions, such as changing status, editing key findings, adding evidence, or changing restricted case details, may be unavailable.
Allowed actions
The following actions are available:
- View case details.
- Add comments and collaborate with Sophos.
- Reassign the case to Sophos.
- Close the case.
Restricted actions
The following actions are unavailable:
- Split or merge cases.
- Change the case status, except for closing the case.
- Add new evidence, such as events or detections.
- Edit key findings.
Case status and verdict
Cases may show the following statuses, depending on the case type:
| Status | Description |
|---|---|
| New | The case has been created. |
| In Progress | The case is in progress. |
| Customer Action Required | The case is waiting for customer action. |
| Awaiting Sophos Assignment | The case is waiting for the MDR team to assign it internally. |
| Closed | The case is closed. |
| Case verdict | Description |
|---|---|
| True Positive – Benign | Activity was correctly identified, but it either doesn't compromise the targeted system or data, or it's been mitigated. |
| True Positive – Malicious | A confirmed security incident. Activity indicates that your organization's systems or data have been compromised or that measures put in place to protect them have failed. |
| Inconclusive | Activity might be valid, but remediation actions might not be possible. |
| False Positive | Activity that is misidentified and non-malicious. |
Close a case
When you close a case, its related detections are resolved and labeled based on the verdict you choose. For MDR customers, the verdicts and their corresponding detection labels are as follows:
| Case verdict | Detection resolution status |
|---|---|
| True Positive – Benign | True Positive – Benign |
| True Positive – Malicious | True Positive – Malicious |
| Inconclusive | Not Actionable |
| False Positive | False Positive |
Reopen a case
Within 30 days after a case is closed, you can reopen the case in these ways:
- Sophos-managed case: Tag Sophos (
@sophos) in a comment on the case. - Customer-managed case: Change the status of the case from Closed.
After 30 days, the case cannot be reopened. You must create a new case.
Notifications and inactivity rules
For Sophos-managed cases, if action is needed from you, the MDR team sets the case status to Customer Action Required. This starts the inactivity timer.
If you don't take action on the case, the following happens:
- You receive an email reminder every 24 hours until you take action.
- The case is automatically closed after five days of inactivity.
Actions that reset the inactivity timer
If you take one of the following actions, the inactivity timer resets to zero and starts again:
- Add a comment.
- Perform a response action.
- Change the assignee.
- Add a link or attachment.
Best practices
Follow these best practices while working with cases in Sophos MDR:
- Decide early who should manage the case. This can't be changed later.
- Take action promptly on Sophos-managed cases to avoid automatic closure.
- Use comments (including
@sophos) to collaborate and re-engage the MDR team when needed. - Choose the most appropriate case type when creating a new case to ensure efficient handling.