Skip to content
Looking for the Security Operations help?

Active Threat Response

Active Threat Response (ATR) provides API-triggered responses to automatically isolate malicious hosts across the network. It extends threat intelligence from Sophos MDR, Sophos XDR, Sophos NDR, and third-party solutions to the access layer, helping prevent lateral movement from wired, wireless, managed, and unmanaged hosts. Sophos AP6 access points registered with Sophos Fusion and covered by a valid support and services license can use ATR.

The ATR APIs are available in Sophos Fusion. The ATR API ingests threat feed data, allowing MDR analysts and network administrators to quickly isolate malicious hosts across the network.

See Active Threat Response.