sophos-mcp
Model Context Protocol server for the Sophos Central EDR/MDR/XDR platform
Versions
1.0.0latestTools 31
search_events Search Sophos Central security events by type, severity, endpoint, source, and date range — the primary SIEM event feed
get_event Get full details of a specific Sophos Central security event including customer data, IOCs, and endpoint context
list_event_types List available Sophos Central security event types and their descriptions — useful for building event search queries
get_audit_logs Get the admin audit trail from Sophos Central — tracks all administrative actions including policy changes, user management, and configuration updates
run_query Execute a Live Discover SQL query (osquery) on one or more Sophos Central endpoints — for real-time investigation and threat hunting
list_saved_queries List saved Live Discover queries in Sophos Central — includes built-in and custom queries with their SQL and supported platforms
get_query_results Retrieve results from a completed Live Discover query run — returns tabular data from each endpoint
list_query_categories List available Live Discover query categories with descriptions and example queries — helps discover what you can query
list_detections List Sophos EDR/XDR detections with optional filters for severity, type, endpoint, and date range
get_detection Get full details of a Sophos EDR/XDR detection including process tree, MITRE ATT&CK mapping, indicators, and raw event data
get_threat_cases List Sophos threat cases — groups of related EDR/XDR detections that form a single incident narrative
get_case_detections Get all detections within a Sophos threat case — shows every detection that contributed to the case
update_case_status Update the status of a Sophos threat case and optionally assign it to an analyst
list_alerts List Sophos Central alerts with optional filters for severity, category, product, and date range
get_alert Get full details of a specific Sophos Central alert including description, managed agent info, and available response actions
acknowledge_alert Acknowledge a Sophos Central alert — marks it as reviewed without resolving it
resolve_alert Resolve and close a Sophos Central alert with a description of the action taken
get_alert_actions List available response actions for a specific Sophos Central alert — determines what actions can be performed
list_policies List Sophos Central endpoint, server, and firewall policies with optional type filter
get_policy Get full configuration details of a specific Sophos Central policy including all settings and scope
get_policy_settings Get specific settings within a Sophos Central policy — extracts and formats individual configuration sections for easier analysis
list_exclusions List global and policy-specific scanning exclusions in Sophos Central — important for security audits and troubleshooting false positives
list_tenants List managed tenants in Sophos Central — MSP/partner view of all managed organizations with status and billing info
get_tenant Get full details of a managed tenant including contact info, license details, and data region
get_tenant_health Get overall security health score for a tenant — endpoint protection coverage, active threats, and compliance metrics
list_endpoints List Sophos Central managed endpoints with optional filters for hostname, health status, OS platform, type, group, tamper protection, and isolation state
get_endpoint Get full details of a specific Sophos Central endpoint including health status, assigned products, tamper protection, isolation state, and associated person
isolate_endpoint Network isolate a Sophos Central endpoint for incident response — the endpoint can only communicate with Sophos Central
unisolate_endpoint Remove network isolation from a Sophos Central endpoint, restoring normal network connectivity
scan_endpoint Trigger a full on-demand antivirus scan on a Sophos Central endpoint
get_endpoint_software List installed software on a Sophos Central endpoint — useful for vulnerability assessment and software inventory
Permissions 2
network medium env_vars low