Sophos NDR: Choose a platform and size the sensor correctly
The platform choice clearly separates virtual and cloud sensors from certified hardware. Measured bandwidth, packets, flows, and additional …
Sophos NDR passively analyzes mirrored network traffic on an Integration Appliance. Because the sensor is not inline, it can also reveal suspicious connections, command-and-control traffic, and activity from unmanaged devices. These guides cover platform selection and traffic mirroring through operations, detections, and investigation. Sophos Firewall NDR Essentials and NDR Active Threat Intelligence are separate SFOS features and are not part of this sensor workflow.
First select and size the platform and sensor, then verify deployment and traffic mirroring. Manage integrations and the appliance inventory in Sophos Fusion (formerly Sophos Central) under Threat Analysis Center > Integrations and My Products > NDR. Use the local Appliance Manager for sensor operations, Threat Analysis Center > Detections for central triage, and the local Investigation Console for sensor hunting. Detections and Cases remain separate workspaces.
Choose the appropriate entitlement and platform, size virtual or certified sensors, deploy on ESXi, Hyper-V, AWS, Nutanix, or certified hardware, and validate SPAN, ERSPAN, mirrored, or cloud traffic all the way to the sensor.
The platform choice clearly separates virtual and cloud sensors from certified hardware. Measured bandwidth, packets, flows, and additional …
The shared Central workflow and separate ESXi and Hyper-V branches cover prerequisites, initial startup, validation, troubleshooting, and a safe …
The AWS deployment separates management and mirrored traffic: CloudFormation creates the appliance, while VPC Traffic Mirroring delivers copies of …
This runbook covers the process from configuring NDR in Sophos Fusion and creating the AHV VM through to the first verified SPAN or ERSPAN packet.
Shared image preparation and separate destructive installation procedures for certified Dell, NUC, and OnLogic systems.
Reliable NDR capture starts with appropriately selected mirror sources and ends with multistage validation. A green status alone proves neither …
Review the appliance inventory, NDR sensors, and co-hosted Log Collectors separately in Sophos Fusion and Appliance Manager, monitor health and capacity, and limit interventions to the smallest affected component.
Sophos Fusion provides inventory information and central actions; the local Appliance Manager shows the status of the appliance, NDR sensor, and log …
An operations runbook for reliable NDR baselines, correctly interpreting at least 2% unicast and more than 10% packet drops, and taking safe capacity …
Classify the NDR dashboard, verify a shared test detection under Threat Analysis Center > Detections, and examine local sensor data in the Investigation Console if necessary. For the triage of detections and cases, the XDR and MDR responsibilities linked below apply.
The NDR Dashboard provides an overview of observed network activity. This guide explains what conclusions the charts support and when another …
This runbook generates a harmless NDR test detection through Appliance Manager and verifies the sensor path, detection content, and complete removal …
This runbook describes requirements, deployment to ESXi or Hyper-V, assignment of one or more NDR integration appliances, and initial access and …
This runbook shows how to examine local NDR data from the dashboard with narrowed-down, read-only ClickHouse queries and check the results.
The Investigation Console has its own local administration and operations layer. This guide protects access, preserves evidence before interventions, …
Isolate faults from the mirror source through the sensor, upload, and investigation; collect diagnostics for support; and explicitly avoid undocumented retirement or deletion steps.
This runbook takes you from a visible symptom through targeted checks to the smallest appropriate action and support escalation—without unvalidated …
Sophos NDR generally requires an NDR integration entitlement. The only exception is MSP Flex, where an existing XDR licence removes the need for the separate Integration Pack. For other contract models, verify the specific entitlement in the affected tenant and contract before deployment. The linked firewall guide covers the licence requirements for the two firewall features.
For tasks outside this sensor path, the following responsibilities apply:
For local sensor hunting, Deploy the Sophos NDR Investigation Console describes access, deployment, and its boundary with the central workspaces.