Jamf
You can integrate Jamf Protect with Sophos XDR so that it sends data to Sophos for analysis.
This page gives you an overview of the integration.
Jamf Protect product overview
Jamf Protect is an endpoint security tool designed to enhance and safeguard Apple device environments. It provides real-time threat detection, incident response, and security compliance tailored specifically for macOS systems.
What we ingest
Sophos XDR collects Jamf Protect data over HTTPS by polling the Jamf Protect GraphQL API, authenticating with a Jamf Protect API client (a client ID and secret, with your Jamf Protect tenant base URL) to obtain a bearer token. The following data is collected:
- Threat detections: Jamf Protect analytic alerts raised on protected macOS devices, each carrying the detection name and description, severity, mapped MITRE ATT&CK techniques, the affected device and user, and the related process, binary, and file context.
Event and data types
We ingest the following event and data types from Jamf Protect:
- Endpoint threat detections: Behavioral and threat detections Jamf Protect raises on macOS endpoints, such as reverse shell creation, persistence via LaunchAgent, and suspicious process or binary activity, mapped to MITRE ATT&CK techniques. Normalized to third-party security alert telemetry.
Data provided by this integration
Data provided by Jamf Protect gets normalized to the following schemas:
thirdpartyalert
For more information about using schemas in Data Lake Search, see Schemas and logical types.