← Back to search

sophos-mcp

solomonneas Scanned 30d ago

Model Context Protocol server for the Sophos Central EDR/MDR/XDR platform

C
74.2 / 100

Versions

1.0.0latest
Apr 30, 2026
PermissionsTool SafetyAuthAnnotationsCode QualityStabilitySpecVuln HistoryAuthorTransparencyCommunity

Tools 31

search_events
annotations: none low

Search Sophos Central security events by type, severity, endpoint, source, and date range — the primary SIEM event feed

get_event
annotations: none low

Get full details of a specific Sophos Central security event including customer data, IOCs, and endpoint context

list_event_types
annotations: none low

List available Sophos Central security event types and their descriptions — useful for building event search queries

get_audit_logs
annotations: none low

Get the admin audit trail from Sophos Central — tracks all administrative actions including policy changes, user management, and configuration updates

run_query
annotations: none low

Execute a Live Discover SQL query (osquery) on one or more Sophos Central endpoints — for real-time investigation and threat hunting

list_saved_queries
annotations: none low

List saved Live Discover queries in Sophos Central — includes built-in and custom queries with their SQL and supported platforms

get_query_results
annotations: none low

Retrieve results from a completed Live Discover query run — returns tabular data from each endpoint

list_query_categories
annotations: none low

List available Live Discover query categories with descriptions and example queries — helps discover what you can query

list_detections
annotations: none low

List Sophos EDR/XDR detections with optional filters for severity, type, endpoint, and date range

get_detection
annotations: none low

Get full details of a Sophos EDR/XDR detection including process tree, MITRE ATT&CK mapping, indicators, and raw event data

get_threat_cases
annotations: none low

List Sophos threat cases — groups of related EDR/XDR detections that form a single incident narrative

get_case_detections
annotations: none low

Get all detections within a Sophos threat case — shows every detection that contributed to the case

update_case_status
annotations: none low

Update the status of a Sophos threat case and optionally assign it to an analyst

list_alerts
annotations: none low

List Sophos Central alerts with optional filters for severity, category, product, and date range

get_alert
annotations: none low

Get full details of a specific Sophos Central alert including description, managed agent info, and available response actions

acknowledge_alert
annotations: none low

Acknowledge a Sophos Central alert — marks it as reviewed without resolving it

resolve_alert
annotations: none low

Resolve and close a Sophos Central alert with a description of the action taken

get_alert_actions
annotations: none low

List available response actions for a specific Sophos Central alert — determines what actions can be performed

list_policies
annotations: none low

List Sophos Central endpoint, server, and firewall policies with optional type filter

get_policy
annotations: none low

Get full configuration details of a specific Sophos Central policy including all settings and scope

get_policy_settings
annotations: none low

Get specific settings within a Sophos Central policy — extracts and formats individual configuration sections for easier analysis

list_exclusions
annotations: none low

List global and policy-specific scanning exclusions in Sophos Central — important for security audits and troubleshooting false positives

list_tenants
annotations: none low

List managed tenants in Sophos Central — MSP/partner view of all managed organizations with status and billing info

get_tenant
annotations: none low

Get full details of a managed tenant including contact info, license details, and data region

get_tenant_health
annotations: none low

Get overall security health score for a tenant — endpoint protection coverage, active threats, and compliance metrics

list_endpoints
annotations: none low

List Sophos Central managed endpoints with optional filters for hostname, health status, OS platform, type, group, tamper protection, and isolation state

get_endpoint
annotations: none low

Get full details of a specific Sophos Central endpoint including health status, assigned products, tamper protection, isolation state, and associated person

isolate_endpoint
annotations: none low

Network isolate a Sophos Central endpoint for incident response — the endpoint can only communicate with Sophos Central

unisolate_endpoint
annotations: none low

Remove network isolation from a Sophos Central endpoint, restoring normal network connectivity

scan_endpoint
annotations: none low

Trigger a full on-demand antivirus scan on a Sophos Central endpoint

get_endpoint_software
annotations: none low

List installed software on a Sophos Central endpoint — useful for vulnerability assessment and software inventory

Permissions 2

network medium
Server uses network capabilities via: fetch()
env_vars low
Server uses env_vars capabilities via: process.env

Scan Findings 75

info
Required env vars (6) manifest_parser · 80%
info
Sandbox failed to start for output poisoning scan output_poisoning · 100%
medium
Permission: network access detected permission_analyzer · 70%
low
Tool 'search_events' has no annotations annotation_checker · 100%
low
Tool 'get_event' has no annotations annotation_checker · 100%
low
Tool 'list_event_types' has no annotations annotation_checker · 100%
low
Tool 'get_audit_logs' has no annotations annotation_checker · 100%
low
Tool 'run_query' has no annotations annotation_checker · 100%
low
Tool 'list_saved_queries' has no annotations annotation_checker · 100%
low
Tool 'get_query_results' has no annotations annotation_checker · 100%
low
Tool 'list_query_categories' has no annotations annotation_checker · 100%
low
Tool 'list_detections' has no annotations annotation_checker · 100%
low
Tool 'get_detection' has no annotations annotation_checker · 100%
low
Tool 'get_threat_cases' has no annotations annotation_checker · 100%
medium
OAuth implementation without PKCE auth_checker · 75%
info
Sandbox failed to start for behavioral verification behavioral_verifier · 100%
low
Tool 'get_case_detections' has no annotations annotation_checker · 100%
low
Tool 'update_case_status' has no annotations annotation_checker · 100%
low
Tool 'list_alerts' has no annotations annotation_checker · 100%
low
Tool 'get_alert' has no annotations annotation_checker · 100%
low
Tool 'acknowledge_alert' has no annotations annotation_checker · 100%
low
Tool 'resolve_alert' has no annotations annotation_checker · 100%
low
Tool 'get_alert_actions' has no annotations annotation_checker · 100%
low
Tool 'list_policies' has no annotations annotation_checker · 100%
low
Tool 'get_policy' has no annotations annotation_checker · 100%
low
Tool 'get_policy_settings' has no annotations annotation_checker · 100%
low
Tool 'list_exclusions' has no annotations annotation_checker · 100%
low
Tool 'list_tenants' has no annotations annotation_checker · 100%
low
Tool 'get_tenant' has no annotations annotation_checker · 100%
low
Tool 'get_tenant_health' has no annotations annotation_checker · 100%
low
Tool 'list_endpoints' has no annotations annotation_checker · 100%
low
Tool 'get_endpoint' has no annotations annotation_checker · 100%
low
Tool 'isolate_endpoint' has no annotations annotation_checker · 100%
low
Tool 'unisolate_endpoint' has no annotations annotation_checker · 100%
low
Tool 'scan_endpoint' has no annotations annotation_checker · 100%
low
Tool 'get_endpoint_software' has no annotations annotation_checker · 100%
medium
Vulnerable dependency: @modelcontextprotocol/sdk@1.12.1 (GHSA-345p-7cg4-v4c7) dependency_analyzer · 95%
medium
Vulnerable dependency: @modelcontextprotocol/sdk@1.12.1 (GHSA-8r9q-7v3j-jr4g) dependency_analyzer · 95%
medium
Vulnerable dependency: @modelcontextprotocol/sdk@1.12.1 (GHSA-w48q-cv73-mx4w) dependency_analyzer · 95%
info
package.json metadata manifest_parser · 100%
info
Tool: search_events manifest_parser · 70%
info
Tool: get_event manifest_parser · 70%
info
Tool: list_event_types manifest_parser · 70%
info
Tool: get_audit_logs manifest_parser · 70%
info
Tool: run_query manifest_parser · 70%
info
Tool: list_saved_queries manifest_parser · 70%
info
Tool: get_query_results manifest_parser · 70%
info
Tool: list_query_categories manifest_parser · 70%
info
Tool: list_detections manifest_parser · 70%
info
Tool: get_detection manifest_parser · 70%
info
Tool: get_threat_cases manifest_parser · 70%
info
Tool: get_case_detections manifest_parser · 70%
info
Tool: update_case_status manifest_parser · 70%
info
Tool: list_alerts manifest_parser · 70%
info
Tool: get_alert manifest_parser · 70%
info
Tool: acknowledge_alert manifest_parser · 70%
info
Tool: resolve_alert manifest_parser · 70%
info
Tool: get_alert_actions manifest_parser · 70%
info
Tool: list_policies manifest_parser · 70%
info
Tool: get_policy manifest_parser · 70%
info
Tool: get_policy_settings manifest_parser · 70%
info
Tool: list_exclusions manifest_parser · 70%
info
Tool: list_tenants manifest_parser · 70%
info
Tool: get_tenant manifest_parser · 70%
info
Tool: get_tenant_health manifest_parser · 70%
info
Tool: list_endpoints manifest_parser · 70%
info
Tool: get_endpoint manifest_parser · 70%
info
Tool: isolate_endpoint manifest_parser · 70%
info
Tool: unisolate_endpoint manifest_parser · 70%
info
Tool: scan_endpoint manifest_parser · 70%
info
Tool: get_endpoint_software manifest_parser · 70%
info
Transport: stdio manifest_parser · 90%
low
Permission: env_vars access detected permission_analyzer · 90%
info
SBOM generated: 283 components sbom_generator · 100%
medium
No build provenance detected (SLSA L0) slsa_assessor · 90%