What you are evaluating
Confirm the current Sophos Central product and edition instead of relying on older Intercept X packaging. Sophos MDR and the acquired Secureworks portfolio require separate scope and service evaluation.
A useful evaluation context
An evaluation fits mixed endpoint estates or service-provider relationships considering Sophos protection, investigation and optional managed response.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- Endpoint protection and EDR combine prevention with evidence for examining suspicious activity on supported devices.
- Host isolation and live shell are documented response options with platform and authorization requirements.
- Ransomware file rollback and assisted investigation are advertised capabilities that need scenario-specific validation.
Where it fits in the work
- Define a concrete endpoint investigation question and confirm that the selected Sophos EDR configuration supplies the necessary records.
- Use an authorized training host to collect a benign baseline, then compare the relevant events and document remaining uncertainty.
- Review the evidence with the responsible owner, record any approved response and confirm that normal lab operation is restored.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
A learner examines a synthetic alert on a disposable workstation and records the observed process sequence. They prepare a containment decision with the workstation owner and identify which Sophos product supplies each proposed action.
Evidence to look for
Check that the case includes evidence, an approver and a recovery path. Test only supported actions on the lab host and retain the resulting audit records.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- Which current Sophos Central entitlement supplies the required EDR functions on each operating-system release?
- What evidence and permissions are required before an investigator uses live shell or host isolation?
- How do the proposed endpoint package and any Sophos or Taegis service divide investigation responsibilities?
Names you may encounter: Intercept X. Historical names do not establish current availability or feature equivalence.