Sophos is a cybersecurity company offering endpoint protection, next-gen firewall, managed detection and response (MDR), email security, and cloud security products for mid-market and enterprise organizations.
Vendors looking to integrate Sophos can access endpoint protection events, MDR alerts, and threat data through Synqly's normalized connector. Build a Sophos integration to incorporate Sophos security telemetry into SIEM, ticketing, and incident response workflows.
Configuration for Sophos Endpoint.
[Configuration guide](https://docs.synqly.com/guides/provider-configuration/sophos-setup)
Integration Use Cases
Get Endpoint
Gets a single endpoint assets matching the UID from the token-linked EDR source.
Quarantine Endpoints
Connect or disconnect one or more endpoints assets to the network, allowing or disallowing connections.
Query Alerts
Returns a list of alerts that match the query from the token-linked EDR source.
Query Applications
Returns a list of applications matching the query from the token-linked EDR source.
Query Endpoints
Returns a list of endpoint assets matching the query from the token-linked EDR source.
Query Posture Score
Returns the posture score of the endpoint assets that match the query from the token-linked EDR source.
Query Threat Events
Returns a list of threats that match the query from the token-linked EDR source.