Sophos Intercept X

Pull Sophos endpoint data.

Overview

In this guide, you will create new credentials for Sophos Central to allow Radiant Security to pull alerts and events from Sophos Intercept X (Sophos Endpoint).


At the end of this configuration, you will provide Radiant Security with the following values:

  • Client ID
  • Client Secret

Prerequisites

To complete the configuration, you will need to log in as Enterprise Super Admin .

Create credentials for Sophos Central

  1. Log in to your Sophos Central Admin account as an Enterprise Super Admin.
  2. Go to My Products > General Settings > API Credentials Management.
  3. Enter the following information in the Add Credential dialog box:
    • A name of the credential (e.g. Radiant Integration)
    • A description for the credential
    • For Role, select Service Principal ForensicsScreenshot 2025-06-16 at 7.47.15 PM
  4. Click Add.
  5. Note down the Client ID and Client Secret. The Client Secret is displayed only once. Ensure you copy it immediately and store it securely.

    Add the data connector in Radiant Security

    1.   Log in to Radiant Security.
    2.   From the navigation menu, select Settings > Data Connector and click + Add Connector.
    3.   Search for and select the Sophos API data feed option and then click Data Feeds. Screenshot 2025-06-16 at 7.34.24 PM 1

    4.   Under Select your data feeds, select Sophos Intercept X and click Credentials.


    Screenshot 2025-06-16 at 7.34.35 PM

    5.   Under Credential Name, give the credential an identifiable name (e.g. Sophos Forensics).

    6.   Under Required Credentials, add the following values that you copied from the previous section:

    • Client ID
    • Client Secret

    7.   Click Add Connector.

    Screenshot 2025-06-16 at 7.35.22 PM

    We value your opinion. Did you find this article helpful? Share your thoughts by clicking here or reach to our Product and Customer Success teams at support@radiantsecurity.ai 

     

    Last updated: 2025-06-16