Skip to content

BlackBerry CylanceOPTICS

You can integrate BlackBerry CylanceOPTICS with Sophos XDR so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

BlackBerry CylanceOPTICS product overview

BlackBerry CylanceOPTICS is an AI-powered endpoint detection and response (EDR) solution that extends the threat prevention capabilities of BlackBerry's endpoint security platform. It uses on-device artificial intelligence and machine learning to continuously analyze endpoint activity, detect threats with root-cause context, and drive automated, playbook-based response.

What we ingest

Sophos XDR collects BlackBerry CylanceOPTICS data over HTTPS by polling the CylanceOPTICS detections API. The integration authenticates with a Cylance service account (an Application ID and Application Secret, with the Cylance Tenant ID and Protect API base URL) to obtain a bearer token, then retrieves detections on a recurring time window:

  • CylanceOPTICS detections: Endpoint detection records, each carrying the detection rule and category, severity, status, the affected device and logged-on user, the associated process and file artifacts, the triggering event trace, and any automated response actions.

Event and data types

We ingest the following event and data types from BlackBerry CylanceOPTICS:

  • Endpoint detections: Threats and suspicious behaviors CylanceOPTICS identifies on protected devices through its built-in and custom detection rules, such as file execution and process activity, including the affected device, artifacts, severity, and response actions. Normalized to third-party security alert telemetry.

Data provided by this integration

Data provided by BlackBerry CylanceOPTICS gets normalized to the following schemas:

  • thirdpartyalert

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation