Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Sophos MDR Detection Triage Explained

Sophos
10/05/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Today, you'll learn about MDR detections, including what they are, how data is collected, and the detection triage process. Let's dive in. Broadly speaking, a detection is any unusual or suspicious activity detected in your environment, including prevention or cleanup events. Our AI-powered threat detection platform identifies multi-stage, multi-vector threats by correlating telemetry across control points, including endpoints, network, cloud, email, identity, and more. The more integrations in data, the greater our visibility and investigation accuracy. Sophos detectors work around the clock to actively monitor your environment in real-time. And, they're continuously enhanced by our engineers as the threat landscape evolves. In the security operations area, the detections page displays the generated detections, classifying them by severity, from informational to critical. Not every detection is malicious. Only high-confidence or high-severity detections may progress into a Sophos MDR case. Use the filters to quickly organize the list of detections to display what's relevant to you. Click on a detection to view the details. Examine the key information in the quick view or expand to the full view for additional details. At any time, you can go to the rules page to create custom detection rules to suit your needs. However, these can only be used for creating customer-managed cases and will not trigger MDR-managed cases. In addition, the Detector Explorer lets you browse the comprehensive list of Sophos threat detection rules and explore the detection logic and associated MITRE ATT&CK tactics and techniques. If a Sophos MDR case is generated from a detection, this triggers a response from the MDR operations team, which is covered in another video. Now you understand what Sophos MDR detections are and how they're generated. I hope you found this useful. The relevant documentation and other comprehensive resources for this video are linked in the video description. Join the Sophos community to stay up to date with Sophos MDR, ask questions, and get answers from Sophos experts. And go to Sophos TechVids for more expert tutorials to help you maximize your products and stay secure. See you next time!

TL;DR

  • Sophos MDR detections cover any unusual or suspicious activity across endpoints, network, cloud, email, and identity, correlated by an AI-powered platform.
  • Not every detection is malicious — only high-confidence or high-severity detections escalate into a formal MDR case handled by the operations team.
  • Customers can create custom detection rules for self-managed cases, but these rules will not trigger MDR-managed responses from the Sophos operations team.

Summary

This short onboarding module from the Sophos MDR series explains how detections work within the Sophos MDR platform — from data ingestion to triage. A detection is defined as any unusual or suspicious activity identified in a customer environment, including prevention and cleanup events. Sophos MDR's AI-powered threat detection platform correlates telemetry across multiple control points — endpoints, network, cloud, email, and identity — to identify multi-stage, multi-vector threats. The broader the integration footprint, the greater the visibility and investigation accuracy. Detections are classified by severity from informational to critical, and only high-confidence or high-severity detections escalate into a formal MDR case handled by the operations team. The video also introduces two self-service capabilities: custom detection rules, which allow customers to create their own rules for customer-managed cases (though these do not trigger MDR-managed responses), and the Detector Explorer, which lets users browse Sophos threat detection logic alongside associated MITRE ATT&CK tactics and techniques. Together, these tools give security teams meaningful transparency into how threats are identified and prioritized within the platform.

Chapters

0:00 - Introduction
0:18 - What Is a Detection?
0:57 - Detection Triage Process
1:26 - Custom Detection Rules
1:39 - Detector Explorer & MITRE ATT&CK

Key Quotes

0:27 "Our AI-powered threat detection platform identifies multi-stage, multi-vector threats by correlating telemetry across control points, including endpoints, network, cloud, email, identity, and more."
0:40 "The more integrations in data, the greater our visibility and investigation accuracy."
1:05 "Not every detection is malicious. Only high-confidence or high-severity detections may progress into a Sophos MDR case."

FAQ

What is the difference between a detection and an MDR case in Sophos MDR?

A detection is any unusual or suspicious activity flagged by the platform, classified by severity from informational to critical. Only high-confidence or high-severity detections progress into a formal MDR case, which then triggers a response from the Sophos MDR operations team.

Can customers create their own detection rules in Sophos MDR?

Yes. Customers can create custom detection rules via the rules page. However, these custom rules can only be used to generate customer-managed cases and will not trigger MDR-managed cases handled by the Sophos operations team.


Categories:
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Security Operations
  • Threat Intelligence
  • Getting Started
  • How-To
  • Demo
  • MDR detection triage
  • AI-powered threat detection
  • Telemetry correlation
  • MITRE ATT&CK mapping
  • Custom detection rules
  • Security operations
  • Threat severity classification
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Sophos MDR Detection Triage Explained

              Industry Events (Sponsor Hosted)

              • Oct
                13

                Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance

                10/13/202601:00 PM ET
                • Oct
                  15

                  Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                  10/15/202611:00 AM ET
                  • Oct
                    20

                    Harnessing Data Governance for AI with Cyera and Snowflake

                    10/20/202611:00 AM ET
                    More events

                    Upcoming Webinar Calendar

                    • 10/13/2026
                      01:00 PM
                      10/13/2026
                      Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance
                      https://www.truthinit.com/index.php/channel/2159/transitioning-from-cjis-to-ferpa-essential-audit-evidence-for-compliance/
                    • 10/15/2026
                      11:00 AM
                      10/15/2026
                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                      https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                    • 10/20/2026
                      11:00 AM
                      10/20/2026
                      Harnessing Data Governance for AI with Cyera and Snowflake
                      https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                    • 10/27/2026
                      01:00 PM
                      10/27/2026
                      The HUMAN Experience: Real-Time Insights into Page Intelligence
                      https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Leveraging CISA’s Zero Trust Maturity Model for an AI-Driven Landscape
                      https://www.truthinit.com/index.php/channel/2149/leveraging-cisas-zero-trust-maturity-model-for-an-ai-driven-landscape/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Aligning Agentic Intent: Understanding Your Agents' Purpose vs. Their Actions
                      https://www.truthinit.com/index.php/channel/2158/aligning-agentic-intent-understanding-your-agents-purpose-vs-their-actions/
                    • 11/05/2026
                      01:00 PM
                      11/05/2026
                      HUMAN Dialogue: Redefining Authentic Trust in the Agentic Internet
                      https://www.truthinit.com/index.php/channel/2160/human-dialogue-redefining-authentic-trust-in-the-agentic-internet/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version