Skip to content

Detectors

Detectors in Sophos XDR are the analytics that continuously evaluate collected telemetry to identify suspicious or malicious activity. Each detector encapsulates detection logic designed to recognize a specific threat behavior, tactic, or technique by analyzing events from endpoint, network, identity, cloud, and log sources, often enriched with context, such as asset details and threat intelligence.

When a detector’s conditions are met, it generates a detection that includes supporting evidence, affected entities, and severity to help analysts quickly validate and respond. Sophos XDR includes detectors that continuously monitor normalized data from your environment for malicious activity. For more information on the available detectors, see Detector types.

Detector Explorer

Detector Explorer lets you browse the full list of Sophos XDR detectors and countermeasures and provides details of each, including the detection logic explanation and associated MITRE tactics and techniques. For more information, see Detector Explorer.