EDR / XDR integration
Automate Sophos Intercept X EDR / XDR with plain language
Read Sophos Central endpoints and alerts, and isolate a device that VernacSecure SuperBot™ flags for review.
What you can do
Sophos Central — Endpoint API
- List Sophos Central endpoints and health
- Read alerts and their severity
- Isolate an endpoint
Connection: bearer authentication against https://api-us01.central.sophos.com. Credentials are encrypted at rest, or prompted per action if you prefer never to store them.
Example
Ask in plain English
Prompt: “Isolate the laptop with the latest critical detection in Sophos Intercept X”
Result: VernacSecure SuperBot™ reads recent detections, confirms the device and isolates it, with a full audit entry.
Read actions
- Fetch endpoints — Lists Sophos Central endpoints.
- Fetch alerts — Lists open alerts.
Write actions
- Isolate endpoint — Turns on isolation for the named endpoint ID.