For the complete documentation index, see llms.txt. This page is also available as Markdown.

Sophos Intercept X

Connect Sophos Intercept X to Radiant Security to ingest endpoint alerts from Sophos Central for AI triage.

Create API credentials in Sophos Central and use them to connect Sophos Intercept X (Sophos Endpoint) to Radiant Security. Once connected, Radiant ingests Sophos endpoint alerts and runs them through the AI triage pipeline.

At the end of this configuration, you will provide Radiant Security with the following values:

  • Client ID

  • Client Secret

Prerequisites

Create credentials in Sophos Central

1

Log in to Sophos Central

Log in to your Sophos Central Admin account as an Enterprise Super Admin.

2

Open API Credentials Management

Go to My Products > General Settings > API Credentials Management.

3

Add the credential

In the Add Credential dialog, enter the following:

  • A name for the credential (e.g., Radiant Integration)

  • A description for the credential

  • For Role, select Service Principal Forensics

Click Add.

4

Copy the Client ID and Client Secret

Copy the Client ID and Client Secret and store them securely.

Add the data connector in Radiant Security

  1. Log in to Radiant Security.

  2. From the navigation menu, select Settings > Data Connector and click + Add Connector.

  3. Search for and select the Sophos API data feed option, then click Data Feeds.

  4. Under Select your data feeds, select Sophos Intercept X and click Credentials.

  5. Under Credential Name, give the credential an identifiable name (e.g., Sophos Forensics).

  6. Under Required Credentials, paste the Client ID and Client Secret values copied from Sophos Central.

  7. Click Add Connector.

Verify ingestion

After Sophos Intercept X begins forwarding, confirm alerts and events are reaching Radiant.

  1. In Radiant, navigate to Log Management.

  2. Filter by rs_connectorType:"sophos_intercept_x".

  3. Confirm recent alerts and events appear.

Allow several minutes for alerts and events to be parsed, indexed, and available for search.

Last updated

Was this helpful?