| Sophos X-Ops threat feeds |
To configure Sophos X-Ops threat feeds. |
Sample Configuration | |
---|---|
Parameter | Mandatory | Default | Description |
---|---|---|---|
ThreatProtectionStatus | No | Enable/Disable Sophos X-Ops threat feeds. ThreatProtectionStatus confines to:
| |
Policy | Yes | Log Only | Select the action that the Sophos X-Ops threat feeds should use if a threat has been detected. Policy confines to:
Applicable only if 'Sophos X-Ops threat feeds' is enabled. |
Host | No | Add or select the source networks or hosts that should be exempt from being scanned for threats by Active Threat Response. Host confines to:
Applicable for Sophos X-Ops, MDR and Third-party threat feeds. | |
Threat | No | Add destination IP addresses or domain names that you want to skip from being scanned for threats by Active Threat Response. Threat confines to:
Applicable for Sophos X-Ops, MDR and Third-party threat feeds. | |
InspectContent | No | Specify the settings to inspect content based on the trust status. InspectContent confines to:
|
Operation | Status | Message |
---|---|---|
Sophos X-Ops threat feeds | 200 | Operation Successful. | Sophos X-Ops threat feeds | 500 | Operation Fail. |