Use Sophos AI Assistant and AI Search in XDR
Sophos AI Assistant and AI Search are XDR investigation tools in Sophos Central. They are not general endpoint-agent features and don’t perform autonomous remediation. AI Search turns natural-language searches into Data Lake queries; AI Assistant guides analysts through a case investigation in a chat.
The complete AI Assistant requires Sophos XDR, Sophos MDR, Sophos MDR Plus, or Sophos Network Detection and Response. Sophos EDR includes AI Case Summary, AI Command Analysis, and AI Search, but not AI Assistant. According to Sophos, full access to the AI features requires the Super Admin or Admin role. Inputs and outputs are currently supported only in English.
Choose the right tool
- AI Search: Searches Detections or Endpoint Data in the Sophos Data Lake. Endpoint Data searches support Windows devices only.
- Security Analyst: Investigates a specific Sophos-managed or Self-managed Case and inherits its Case and Detection context.
- Threat Hunter: Hunts for actors or indicators of compromise in the Data Lake and works only with Self-managed Cases.
- AI Case Summary: Summarises a Case’s Detections, devices, users, MITRE ATT&CK tactics, and possible next steps.
- AI Command Analysis: Explains and de-obfuscates command lines from Detections.
AI Assistant can currently retrieve and analyse XDR-integrated data from Sophos Endpoint and Sophos Server on Windows. It can’t remediate a threat or perform a Response action. Isolation, Live Response, blocking, authorisation, and closing a Case remain deliberate human decisions.
Use AI Search safely
- Open Threat Analysis Center > AI Search.
- Select Detections or Endpoint Data on the left. Endpoint Data requires a Windows device.
- Select a suggested search or enter a question in English. Specify the device, user, indicator, and time range as precisely as possible.
- Select Search and review the results table.
- Expand Generated Query and inspect the generated SQL. Its data source, fields, filters, and time range must match the investigation question.
Without an explicit time range, AI Search defaults to 24 hours. Sophos recommends starting with a few hours or no more than one day, then expanding gradually. Queries spanning days or weeks can become slow or time out, depending on data volume.
The results table shows no more than 1,000 matches. Sophos states that Data Lake data is retained for 90 days, or one year with the Central Data 1-Year Storage Pack add-on licence. A 1,000-row result therefore doesn’t prove that exactly 1,000 events exist, and an empty table doesn’t prove that no activity occurred during the complete incident period.
Use Save Query to store a useful query in the new AI Search category in Live Discover, or Export to download its SQL and results as CSV. Sophos Live Discover and Data Lake queries explains the difference between Live Endpoint and Data Lake, as well as operational query limits.
Start AI Assistant from a case
The safest entry point is a reviewed Case rather than a context-free chat:
- Open Threat Analysis Center > Cases and select the Case ID.
- Review the Detection, affected devices, and relevant time range.
- Select Ask Sophos AI in the upper right. Central opens Security Analyst with the Case context.
- Edit a predefined prompt or ask your own question in English. Enter
/to open prepared and saved prompts. - Ask follow-up questions in the same chat. Assistant considers the current thread; a new chat doesn’t have that conversation context.
Alternatively, open AI > Assistant, select New, then Security Analyst or Threat Hunter. Security Analyst then asks for a Case ID. Ask AI can also add selected rows from a results table as context for a follow-up. Before sending, verify which selection will actually be transferred.
Write a defensible prompt
A good prompt states the objective, scope, and required output. For example:
Compare the detections for endpoint WS-023 during 10 September 2026, 08:00-12:00 UTC. List process names, command lines and hashes, and mark every conclusion that still needs validation.
WS-023 is a neutral example and must be replaced with the device under investigation. Date, time, and time zone must match the Case. Add process names, IP addresses, users, or hashes only when the hypothesis requires them. Saved prompts need a clear alias; both alias and complete prompt must be unique. An owner, purpose, and review date prevent an outdated prompt from becoming an unreviewed Runbook.
Validate and document results
AI responses can be false or misleading. Check claims such as “no other devices are affected” against the Case timeline, Detection details, device data, and query results. In particular, confirm:
- Does the evaluated time range, including its time zone, match the Case?
- Was the affected device providing telemetry during that period?
- Do filters, platform support, or the 1,000-row limit constrain the claim?
- Do raw events support the proposed conclusion and Response?
Responses, individual table rows, complete tables, and queries can be pinned. These Pinned Items remain in the Workbench for the duration of the chat and can include a rationale note. They are a personal working aid, not Case documentation. Feedback buttons rate the specific response; confidential incident details don’t belong in the optional comment field.
You can add one or several verified Assistant responses to the Case’s Notebook tab. Use the plus icon below a single response, or three-dot menu > Select responses > Add to case for several. Threat Hunter asks for the target Case; Security Analyst uses the Case already under investigation.
A private chat is visible only to the person who started it. Other administrators with Case access see only responses added to Notebook. Use the three-dot menu beside the chat title and select Delete to remove the complete thread. Validate required evidence against raw data and record it in the Case or your incident system before deletion; the chat isn’t an audit-proof archive.
Privacy and usage limits
Passwords, private keys, recovery codes, and unnecessary personal data don’t belong in prompts or feedback. Limit context to the investigation question and continue to apply your organisation’s data-classification, retention, and export rules.
Sophos uses Azure OpenAI and Amazon Bedrock. Sophos states that inputs and outputs aren’t used to train the models or improve the third-party services, and that all data transferred to third-party LLM services is encrypted in transit. Existing role-based Central permissions continue to constrain which data a user can access.
Published limits apply over a rolling 24-hour period:
- AI Command Analysis: 50 per user, 250 per tenant
- AI Search: 20 per user, 100 per tenant
- AI Case Summary: 10 per user, 50 per tenant
- AI Assistant threads: 20 per user, 100 per tenant
- individual Assistant messages: 200 per user, 1,000 per tenant
When a limit is reached, the affected feature pauses with HTTP 429. Sophos can change these values, so use the current limits page for operational planning. Critical investigations must always retain a manual path through Cases, Detections, Live Discover, and the underlying telemetry.
Sources
- Sophos Central Admin: AI features FAQs
- Sophos Central Admin: AI assistant
- Sophos Central Admin: AI Search
- Sophos Central Admin: AI responsible use limits
- Sophos XDR Privacy Data Sheet