Sophos, a global leader in next-generation cybersecurity, has announced the launch of Sophos XDR, the industry’s only extended detection and response (XDR) solution that synchronizes native endpoint, server, firewall, and email security.
With this comprehensive and integrated approach, Sophos XDR provides a holistic view of an organization’s environment with the richest data set and deep analysis for threat detection, investigation and response.
Sophos has also published new research, “Intervention halts a ProxyLogon-enabled attack,” detailing an attack against a large organization that began when the adversaries compromised an Exchange server using the recent ProxyLogon exploit. The research shows how the attackers moved laterally through the network and, over a two-week period, stole account credentials; compromised domain controllers; secured a foothold on multiple machines; deployed a commercial remote access tool to retain access to hacked machines; and delivered a number of malicious programs.
Sophos XDR extends visibility across Sophos’ next-generation portfolio of solutions for an in-depth picture of threats. At the heart of Sophos XDR is the industry’s richest data set. Sophos XDR offers two types of data retention, including up to 90 days of on-device data, plus 30 days of cross-product data in the cloud-based data lake. The unique approach of blending on-device and data lake forensics provides the broadest and most in-depth contextualized insights that can be leveraged by security analysts through Sophos Central and via open application programming interfaces (APIs) for ingestion into security information and event management (SIEM); security orchestration, automation and response (SOAR); professional service automation (PSA); and remote monitoring and management (RMM) systems.
The data lake hosts critical information from Intercept X, Intercept X for Server, Sophos Firewall, and Sophos Email. Sophos Cloud Optix and Sophos Mobile will also feed into the data repository later this year. Security and IT teams can easily access this data to run cross-product threat hunts and investigations, and to quickly drill into granular details of past and present attacker activity. The availability of offline access to historical data further protects against lost or impacted devices.
Sophos XDR and EDR are part of the Sophos adaptive cybersecurity ecosystem (ACE), a new open security architecture that optimizes threat prevention, detection and response. Sophos ACE leverages automation and analytics, as well as the collective input of Sophos products, partners, customers, developers, and other security industry vendors to create protection that continuously improves ¬– a virtuous cycle that is constantly learning and advancing.
Sophos ACE is built upon the data lake, correlating actionable insights from Sophos solutions and services as well as threat intelligence from SophosLabs, Sophos AI and the Sophos Managed Threat Response team. Open APIs enable customers, partners and developers to build tools and solutions that interact with the system and to take advantage of existing integrations. Sophos is leading the industry with this approach and already integrates with many vendors.
Sophos XDR, as well as the updated EDR capabilities for Intercept X Advanced with EDR and Intercept X Advanced for Server with EDR are available worldwide on May 19 through Sophos partners. Partners and customers can easily manage all XDR and EDR product solutions on the cloud-based Sophos Central platform via a single user interface.