Skip to content
Avanet

Operate Sophos XDR Cases and Detection Rules

Sophos XDR groups Detections and affected entities into Cases that can be investigated. A Case is not an automatically resolved incident, but the shared workspace for evidence, ownership and Response.

Cases require EDR, XDR or MDR. Sophos automatically creates a Case for a High-Risk Detection unless it is already included in a suitable Case on the same day. Later Detections of the same type can be added.

A Sophos-managed Case based on MDR Detections is investigated by the MDR team. A Self-managed Case from XDR Detections remains the customer’s responsibility and is assigned to an administrator. Sophos creates it, but does not investigate it automatically.

Detection, Alert and Case

ElementPurpose
Detectionsuspicious activity or rule match
Alertprioritised notification requiring action
Casegrouped investigation with owner, status and evidence
Detection Rulerule that hides matching Detections and prevents them from creating Cases

Several Detections can belong to the same attack chain. Conversely, one notable Detection may already justify an investigation.

Work on a Case

Start at Threat Analysis Center > Cases. Open an automatically generated Self-managed Case using its Case ID. On Overview, use the menu beside the Case name to set the severity. Change the status from New to Investigating, then select the responsible administrator under Owner. If the administrator is missing, add them there with Add user. The Owner can also be assigned later.

There are two officially documented ways to create a Self-managed Case manually:

  • Under Threat Analysis Center > Cases > Create case > Self-managed case, enter a name and description, select Severity, status New, and optionally an Assignee, then save with Create. Under Threat Analysis Center > Detections, select the matches and use Actions > Add to Case.
  • Alternatively, first select the matches under Threat Analysis Center > Detections and choose Actions > Create Case. Add later Detections with Actions > Add to Case.

Manually created Cases can contain Sophos XDR Detections only, not MDR or Managed Risk Detections. Sophos recommends using only alphanumeric characters, spaces, and basic punctuation in the Case name because APIs can interpret special characters as syntax.

For the investigation itself:

  1. Read the summary, severity and timeline.
  2. Check affected devices, users, processes, IPs and files.
  3. Assess MITRE ATT&CK techniques and the Detection source.
  4. Use Threat Graph, Live Discover and available Enrichments.
  5. Document containment such as isolation or Live Response.
  6. Record the cause, scope and closure decision.

AI-generated summaries can accelerate triage, but must be checked against raw data and the timeline.

Detection Rules

Detection Rules can currently only suppress unwanted Detections and require a Super Admin. A rule prevents a matching Detection from appearing in the Detection list and from creating a Self-managed XDR Case. It cannot suppress MDR Cases.

Create a rule from an existing Detection: go to Threat Analysis Center > Detections, open the three-dot menu beside the Detection name, and select Add detection rule. Enter a name and description under Rule Details; the rule is enabled by default. Suppress is currently the only option under Actions. Under Conditions, select the characteristics of the existing match that should trigger the rule, then select Save. A tenant can have no more than 25 Detection Rules.

Before saving the default-enabled rule, document its name, purpose, data source, expected frequency, Owner, and review date. Conditions should identify only the confirmed legitimate trigger, not merely a severity or broadly scoped process characteristic.

A new rule can take up to 20 minutes and applies only to Detections created after the rule. Conditions are case-sensitive: Windows and windows can be treated differently.

Manage existing rules under Threat Analysis Center > Detection rules. A rule can be enabled, disabled, duplicated, or deleted, but not edited directly. To change it, duplicate and adjust it from the three-dot menu, then disable or remove the original after controlled replacement.

Control Suppression

Suppression reduces known, expected matches. It is not cleanup and must not hide genuine activity. Every Suppression requires:

  • a precise condition rather than a broad pattern,
  • a documented legitimate trigger,
  • an owner and review date,
  • review of Detections already suppressed.

A quiet console is not a sign of quality if rules are suppressed too broadly.

To verify the result, go to Threat Analysis Center > Detections > Show filters. Under Detection Visibility, clear Hide Suppressed Detections and select Apply. This shows what a rule actually matches. Because rules don’t apply retroactively, this view is also a better basis for the next review than simply counting fewer visible matches.

Closure and lessons learned

Close a Case when the scope, cause, containment, cleanup and recovery are documented. Then adjust Detection Rules, policies, exclusions and Runbooks if the investigation revealed a gap.

Close a Self-managed Case by setting its status to Resolved. It remains in the list for 30 days and Sophos then deletes it. Partner Super Admins and Enterprise Super Admins can’t close or remove Cases, so account for this role boundary before assigning the owner.

The underlying telemetry and query work are explained in Sophos XDR Data Collection and Live Discover.

Sources

Frequently asked questions

Is every Detection an incident?

No. A Detection is a signal that requires context. Several weak signals can still combine into a relevant incident.

Can a frequent Detection simply be suppressed?

Only after confirming a legitimate cause. Keep the Suppression narrow, document it and review it regularly.