Sophos XDR gives highly effective instruments and menace intelligence that allow organizations to detect, examine, and reply to suspicious exercise earlier than energetic adversaries can affect their programs. With over 40,000 prospects already utilizing our XDR capabilities to raise their defenses, Sophos is a longtime world chief in prolonged detection and response.
We’re delighted to announce a number of important enhancements to Sophos XDR that additional speed up detection and response, together with expanded know-how integrations that leverage current safety investments and new instruments and optimized workflows to research threats extra effectively.
Expanded third-party integrations
The extra you see, the sooner you possibly can act. Sophos XDR customers can now leverage telemetry from an much more intensive vary of third-party (non-Sophos) safety instruments, enabling organizations to get extra ROI from their current know-how investments whereas rushing up safety operations.
The newly-expanded know-how companion ecosystem integrations embrace identification, community, firewall, e-mail, cloud, productiveness, and endpoint safety applied sciences. Endpoint and Microsoft integrations are included with Sophos XDR subscriptions at no extra value.
With Sophos XDR, suspicious indicators from each Sophos and non-Sophos merchandise are ingested, filtered, correlated, and prioritized – permitting prospects to see extra worth from their current instruments than XDR options that solely use third-party telemetry to counterpoint endpoint detections.
Community Detection and Response (NDR) is now out there for Sophos XDR
Sophos NDR (Community Detection and Response) repeatedly screens community site visitors to detect a variety of safety dangers, together with rogue units, unprotected units, insider threats, zero-day assaults, and threats involving IoT and OT units.
Sophos NDR was launched earlier this yr as an non-obligatory add-on for the Sophos MDR (Managed Detection and Response) service, and we’re delighted to announce that Sophos NDR is now additionally out there for Sophos XDR for organizations who handle their very own detection and response actions.
New and improved case administration capabilities
Sophos XDR mechanically creates circumstances primarily based on detections to assist organizations prioritize their investigations. Along with enhancing computerized case creation, new and improved case administration capabilities assist analysts higher handle their investigation workload and collaborate with different workforce members extra effectively.
Key enhancements embrace:
- Case Pocket book. Analysts can simply doc and manage their work as they progress via an investigation by logging observations and findings and including media for added context.
- Exercise Log. An in depth file of exercise for every case permits analysts to simply see actions that different workforce members have taken as a part of an investigation.
- Case Abstract. Analysts can now enter a short synopsis of every case, enabling their workforce to see a concise overview of investigations at a look.
- Enhanced MITRE ATT&CK Framework mapping. Sophos XDR mechanically maps detections to MITRE ATT&CK Techniques, enabling analysts to establish potential gaps in defenses and prioritize enhancements. On this launch, MITRE Framework mappings at the moment are collated throughout all detections inside a single case, with extra detailed TTP particulars supplied.
- Coming Quickly: New analyst response actions. Utilizing the brand new XDR case administration toolset, analysts can now include potential threats with the clicking of a button. New analyst response actions will assist organizations speed up menace containment by way of Sophos’ XDR-integrated merchandise and by way of new third-party know-how integrations. For instance, utilizing the brand new integration with Okta, analysts can shortly and simply droop customers, clear consumer periods, and expire consumer passwords, all from the Sophos XDR platform.
New Detections consumer expertise
Sophos XDR identifies suspicious actions that want speedy consideration, mechanically prioritizing detections throughout a number of assault surfaces primarily based on danger.
The consumer expertise for Detections has been redesigned in Sophos XDR, offering a transparent view of essentially the most essential knowledge at a look, with handy entry to enrichment pivots and actions to speed up investigations.
New simplified (SQL-less) XDR search
Examine and hunt threats at pace. The brand new XDR search instrument permits analysts to shortly discover particular knowledge within the Sophos knowledge lake by trying to find indicators of compromise and different knowledge similar to IP addresses or usernames.
An intuitive search builder, plus free-text and prompted-Lucene choices, permits customers of all ability ranges to seek out the info they want sooner with out SQL experience!
Acknowledged by business consultants and prospects
Sophos XDR continues to garner excessive reward from prospects and business consultants for superior detection, investigation, and response capabilities.
Sophos is one in every of solely ten distributors acknowledged within the 2023 Gartner Market Information for XDR, was named a Chief within the G2 Grid for XDR, earned the place as the only real chief in Omdia’s vendor comparability for Complete XDR, and delivered distinctive ends in the 2023 MITRE Engenuity ATT&CK Evaluations (Spherical 5: Turla).
Elevate your defenses towards energetic adversaries
You may also take it for a take a look at drive in your personal surroundings with a no-obligation 30-day free trial – out there from our web site or (for current Sophos prospects) immediately inside the Sophos Central console in simply a few clicks.