
Sophos MDR- & XDR-Sensoren, Connectoren und Integrationen
Third-Party Integration Packs erweitern Sophos MDR und Sophos XDR um Telemetrie-, Alarm- und Ereignisdaten aus externen Lösungen. So erhalten Sie mehr Sichtbarkeit, zusätzlichen Kontext und eine bessere Grundlage für Erkennung und Reaktion.
Die Einrichtung und Verwaltung erfolgt zentral über Sophos Central.
Sensoren erfassen Daten direkt auf Endpoints, Servern oder Workloads.
Connectoren binden externe Systeme per API, Syslog oder Log-Collector an.
Beide Ansätze ergänzen sich und schaffen ein umfassenderes Bild Ihrer IT-Umgebung.
Machen Sie mehr aus Ihren Sicherheitsdaten
Sie möchten wissen, welche Sophos MDR- und XDR-Integrationen zu Ihrer bestehenden IT-Umgebung passen? Wir unterstützen Sie bei der Auswahl, Einrichtung und sicheren Anbindung Ihrer Systeme.
Achtung: Keine Gewähr auf Vollständigkeit oder Richtigkeit, Änderungen jederzeit möglich.
Public-Cloud-Integrationen für Sophos MDR & XDR
Hersteller
Produkt
Unterstützte Funktionen
AppOmni
AppOmni
API-Integration (Telemetrie aus SaaS-Plattformen)
AWS
AWS (CloudTrail)
API-Integration (Cloud-Audit-Logs)
AWS
AWS (Security Hub)
API-Integration (Cloud Security Alerts)
Orca Security
Orca Security
API-Integration (Cloud-Workload- und Konfigurations-Alerts)
Trend Micro
Cloud App Security
PI-Integration (Cloud-App-Schutz-Events)
E-Mail-Integrationen für Sophos MDR & XDR
Hersteller
Produkt
Unterstützte Funktionen
Mimecast
Mimecast Email Security 1.0
API-Integration (E-Mail-Logs und Bedrohungsdaten)
Mimecast
Mimecast Email Security 2.0
API-Integration (E-Mail-Logs und Bedrohungsdaten)
Proofpoint
Targeted Attack Protection (TAP)
API-Integration (E-Mail-Angriffserkennung)
Trend Micro
Email Security
API-Integration (Mail-Gateway- und Phishing-Alerts)
Endpoint-Integrationen für Sophos MDR & XDR
Hersteller
Produkt
Unterstützte Funktionen
Broadcom (Symantec)
Symantec Endpoint Security
API-/Log-Integration (Endpoint-Alerts)
CrowdStrike
CrowdStrike Falcon
API-Integration (Endpoint-Telemetrie und Alerts)
BlackBerry (Cylance)
CylanceOPTICS
API-Integration (EDR-Telemetrie, Prozess- und Bedrohungsdaten)
Jamf
Jamf Protect
API-Integration (macOS Endpoint-Telemetrie)
SentinelOne
Singularity Endpoint
API-Integration (Endpoint-Alerts und Status)
Trend Micro
Vision One
API-Integration (Threat-Detection-Telemetrie)
Firewall-Integrationen für Sophos MDR & XDR
Hersteller
Produkt
Unterstützte Funktionen
Barracuda
Barracuda
Log-Integration (Syslog) in den Data Lake
Check Point
Checkpoint Quantum Firewall
Log-Integration (Firewall-Logs) via Collector
Cisco
Cisco Firepower
Log-Integration (NGFW-Traffic und -Alerts) via Collector
Cisco
Cisco Meraki (API)
API-Integration (Cloud Networking Events)
Cisco
Cisco Meraki (Log Collector)
Log-Integration (Geräte- und Security-Logs) via Collector
F5
BIG-IP ASM
Log-Integration (WAF-Sicherheitsereignisse) via Collector
Forcepoint
Forcepoint
Log-Integration (Firewall-Logs) via Collector
Fortinet
Fortigate
Log-Integration (Firewall- und UTM-Logs) via Collector
Fortinet
FortiAnalyzer (API)
API-Integration (zentrale Firewall-/Security-Events)
Fortinet
FortiAnalyzer (Log Collector)
Log-Integration (zentrale Firewall-Logdaten) via Collector
Palo Alto Networks
PAN-OS
Log-Integration (Firewall-Events) via Collector
SonicWall
SonicOS
Log-Integration (UTM- und Firewall-Logs) via Collector
Ubiquiti
UniFi
Log-Integration (Netzwerk-/Security-Logs) via Collector
WatchGuard
Firebox
Log-Integration (UTM-Logs) via Collector
Identity-Integrationen für Sophos MDR & XDR
Hersteller
Produkt
Unterstützte Funktionen
Auth0
Auth0
API-Integration (Identity-Telemetrie)
Cisco
Duo
API-Integration (Authentifizierungs-Logs)
Cisco
Cisco ISE
Log-Integration (Network Access Logs) via Collector
ManageEngine
AD Audit Plus
Log-Integration (Active-Directory Audit Logs) via Collector
Okta
API-Integration (Auth-Logs)
Network-Integrationen für Sophos MDR & XDR
Hersteller
Produkt
Unterstützte Funktionen
Aryaka
Aryaka
Log-Integration (Netzwerk-Traffic und -Events) via Collector
Armis
Armis
API-Integration (Asset- und Alarm-Telemetrie)
Cato Networks
Cato
Log-Integration (Netzwerk-Security-Events) via Collector
Cisco
Cisco Umbrella
API-Integration (DNS Security Events)
Darktrace
Darktrace Detect
API-Integration (Netzwerk- und Anomalie-Alerts)
Secutec
Secutec
API-/Log-Integration (DNS-Anfragen und -Filter)
Thinkst
Thinkst Canary
API-Integration (Canary-Alarmmeldungen)
Vectra
Vectra AI
API-Integration (KI-basierte Bedrohungsalarme)
Zscaler
Zscaler ZIA
API-Integration (Web-/DNS-/Security-Events)
Backup-&-Recovery-Integrationen für Sophos MDR & XDR
Hersteller
Produkt
Unterstützte Funktionen
Acronis
API-Integration (Sicherheitsereignisse/Telemetrie)
Rubrik
API-Integration (Backup-Sicherheitsereignisse)
Veeam
Integration zur Ereignis-/Alarm-Übernahme (Protokollsammler, On-Premise)
Productivity-Integrationen für Sophos MDR & XDR
Hersteller
Produkt
Unterstützte Funktionen
API-Integration (Audit- und Sicherheits-Logs aus Google Workspace)
Microsoft
API-Integration (M365 Unified Audit Log)
Microsoft
Microsoft 365 Response Actions
Reaktionsmaßnahmen (Response Actions) über Microsoft 365
Microsoft
MS Graph Security API v2
API-Integration (Microsoft Security Alerts)
Microsoft
MS Graph Security API (Legacy)
API-Integration (Legacy)
Hinweis: Verfügbarkeit und Funktionsumfang einzelner Integrationen können sich je nach Region, Produktversion und Sophos-Roadmap ändern. Haben Sie Fragen oder möchten Sie Unterstützung bei der Auswahl und Anbindung der passenden Integrationen? Kontaktieren Sie uns gerne – wir beraten Sie individuell.
