Skip to content

Using actions

You run actions on entities in Sophos XDR. When you triage detections or cases in your tenant, select an entity to perform a configured action on it. For more information about entities, see Entities.

You can perform actions from an individual entity details page, from a table of entities, or from a case.

Tip

You can perform an action on multiple entities at once in the Response tab in cases.

On an entity details page, click Actions to see the actions available for that entity. Click an action to run it.

Actions menu on an entity details page.

In a table of entities—as in the Entities tab of detection details or the Entities sub-tab of a case's Evidence tab—click the three dots in the Actions column to see the actions available for that entity. Click an action to run it.

Actions menu on an entities table.

In cases, you can run actions either on entities associated with the case or on the case itself.

  • In the Response tab of a case, click Run Action in the Actions column and then choose one or more entities to run the action on. For more details, see Response tab.

    Response tab showing the Run Action option.

  • You can find actions that run on the case itself by clicking the three dots in a case's summary view or the Actions menu on the full case details page.

To check an action’s status after you run it, open the action details page and click View Executions. For more information, see View executions.