Security Operations
Sophos XDR (Extended Detection and Response) is a comprehensive platform for detecting, investigating, and responding to security threats across your environment. Below are the main features available in the Security Operations section of Sophos Fusion.
-
Overview
Track and triage the latest detections, monitor ongoing cases, and analyze activity trends across your organization.
-
Detect
Review detection details, events, and entities to determine if activity should be investigated further.
-
Investigate
Use cases to gather related information together and share it with your team.
-
Search
Use the following search features to find detections and events and to search devices for signs of threats.
-
Automate
Automating manual tasks provides you with more time to review cases and respond to suspicious activity more efficiently.
-
Integrate
Integrate Sophos products and third-party security products to send data to the Sophos Data Lake.
-
Enrich
Access Threat Intelligence produced by the Sophos Counter Threat Unit™ (CTU) and create custom Enrichments to open third-party websites to look up information about potential threats.
-
Next-Gen SIEM
Sophos Next-Gen SIEM is a compliance-focused extension for Sophos XDR and Sophos MDR.
-
Classic view
The Threat Analysis Center is the classic view of Security Operations within Sophos XDR, and it's still available.