We are pleased to announce that the Sophos XDR Detections dashboard is now available for all Intercept X Advanced with XDR and Intercept X Advanced for Server with XDR customers.
The dashboard provides a prioritized list of suspect activity and vulnerable configurations that warrant immediate attention. The prioritized list makes it easy for admins to focus on the important issues and reduce time spent on investigating low-risk events.
Suspect activities are ranked on a 1-10 risk scale (10 being the highest risk), highlighting a description of the detection and how it maps to the MITRE ATT&CK framework. Additional details include the time of the event, associated processes, executed command lines, file hashes, device, user, and more.
While digging into the details of a suspicious item, itās easy to take further action with a context-aware list of deeper investigation options and immediate actions that can be performed.
Watch the video to see this powerful new functionality in action.
Trying out the Sophos XDR Detections dashboard
Itās easy to try out Sophos XDR and the new Detections dashboard. If your customers are new to XDR, they’ll also get the opportunity to use powerful threat hunting capabilities that answer important security and IT operations questions such as āis RDP unnecessarily enabled on any devices?ā and āhas my software rollout successfully completed?ā
Existing XDR customers āĀ they donāt need to take any action unless they have disabled uploads to the Sophos Data Lake. To turn on uploads select āGlobal Settingsā, then under Endpoint or Server Protection (or both) select the āData Lake uploadsā setting and toggle the āUpload to the Data Lakeā on.
New customers ā if they have a Sophos Central account they can start a trial of XDR functionality via the in-product trial tab. In the left hand column select āFree Trialsā and then āIntercept X Advanced with XDRā or āIntercept X Advanced for Server with XDRā. Then follow the above instructions for enabling the Sophos Data Lake.
If customers donāt have a Sophos Central account they can start trials for their endpointsĀ andĀ servers on the Sophos.com website.
Selling Sophos XDR
Head over to the Sophos Partner Portal to find a collection of useful sales and marketing tools that help you sell and promote Sophos XDR.