Mimecast API v2
You can integrate Mimecast API v2 (Email Security Cloud Gateway) with Sophos XDR so that it sends data to Sophos for analysis.
This page gives you an overview of the integration.
This page refers to Mimecast API v2. Sophos XDR does not support Mimecast API v1.
Mimecast API v2 product overview
Mimecast API v2 (Email Security Cloud Gateway) is a cloud-based solution that defends against a multitude of email-borne threats, including phishing, malware, and spam. Through its centralized platform, it offers multi-layered detection mechanisms, ensuring the safety of inbound and outbound emails while providing real-time threat intelligence and rapid incident response.
What we ingest
Sophos XDR collects Mimecast Email Security Cloud Gateway data over HTTPS by polling Mimecast's API for your account, using the integration credentials (an Application ID, Application Key, Client ID, and Client Secret for Mimecast API v2). Mimecast returns each feed as JSON or NDJSON-style log entries, and we ingest them in the order Mimecast delivers them, following Mimecast's pagination until the requested time range is complete. We use the following Mimecast log feeds:
- Targeted Threat Protection (TTP): Mimecast's targeted-threat findings feed, covering Attachment Protect detonation or scan results, URL Protect rewritten-link click events, and Impersonation Protect detections.
Mimecast sends these records exactly as the API returns them. Which categories and fields appear depends on which Mimecast products you have licensed and enabled (for example, Email Security with TTP Attachment Protect, URL Protect, and Impersonation Protect), what your policies log, and which feeds your account exposes to API consumers.
Event and data types
We ingest the following event and data types from Mimecast API v2:
- Attachment Protect: Sandboxed attachment scanning and detonation results, including verdict, action, file name, file hash, and affected message context. Normalized to email telemetry.
- URL Protect: Rewritten-link click events from Mimecast URL Protect, including the original URL, the rewritten URL, click outcome, user, and policy. Normalized to email telemetry and HTTP telemetry.
- Impersonation Protect: Targeted impersonation detections, including matched indicators, similarity factors, action, and message context. Normalized to email telemetry.
Data provided by this integration
Data provided by Mimecast API v2 gets normalized to the following schemas:
emailhttp
For more information about using schemas in Data Lake Search, see Schemas and logical types.