Sophos moved into extended detection and response (XDR) today and it also updated its endpoint detection and response (EDR) product.
The XDR move follows several other EDR vendors that have extended their threat visibility and remediation capabilities beyond endpoints and across customers’ entire IT environments. But Sophos XDR brings some differentiated features to the market including on-device and data lake forensics, according to EVP and Chief Product Officer Dan Schiappa.
Also today, Sophos published research about the recent Microsoft Exchange server hack, and how that type of sophisticated, nation-state attack proves the need for in-depth threat visibility via XDR.
“When you see that kind of multi-pronged attack, you see the combination of nation-state tactics with traditional malware, you realize that you need something like an XDR product that has that sight across multiple different inspection points in the ecosystem or you’re going to miss something like that,” Schiappa said. “And so one of the differentiators that we added was the breadth of that aperture.”
Native and API IntegrationsIn moving beyond EDR to XDR, Sophos “opened up the aperture” with integrations beyond its endpoint and server security products and into firewalls and email, Schiappa said. The vendor will also add mobile and cloud security integrations later this year. “So now, pretty much across the entire portfolio, you’ll have the ability to query and threat hunt across these devices in one location, in our data lake,” he said.
Sophos XDR offers two types of data retention, including up to 90 days of on-device data, plus 30 days of cross-product data, in a cloud-based data lake. This combination of on-device and data lake forensics provides better contextualized insights, Schiappa said. Security analysts can access via a centralized dashboard.
In addition to providing threat hunting and remediation across a customer’s IT environment, XDR platforms also usually include, or integrate with, network detection and response (NDR); security information and event management (SIEM); and security orchestration, automation and response (SOAR) systems. For these pieces that aren’t part of its product portfolio, Sophos XDR uses open APIs so customers can ingest additional data from third-party NDR, SIEM, SOAR, professional service automation, and remote monitoring and management systems.
Sophos XDR Query Pivot“We’ve also added something called a query pivot,” Schiappa said. This feature makes it easier and faster for security analysts to investigate and respond to threats by suggesting “sub queries” off of the original investigation, he explained. For example, if an analyst is hunting a piece of malware, the sub query may recommend checking an email inbox as well.
Both Sophos XDR and EDR include this new query pivot feature. They also come with a “cabbed query” feature. “So, for example, when Hafnium broke, we published queries for how to check to see if you are impacted by Hafnium,” Schiappa said.
Comments