Sophos · Capability
Sophos Security Operations
Unified capability for security operations using the Sophos Central SIEM API. Combines alert retrieval and event monitoring to support SOC analysts performing threat detection, incident triage, and security event analysis workflows.
What You Can Do
GET
List alerts
— List security alerts from Sophos Central within the last 24 hours
/v1/alerts
GET
List events
— List security events from Sophos Central within the last 24 hours
/v1/events
MCP Tools
list-security-alerts
Retrieve security alerts from Sophos Central. Use for threat detection, incident triage, and monitoring active security events. Supports cursor pagination and date filtering.
read-only
list-security-events
Retrieve security events from Sophos Central. Use for SIEM integration, log analysis, and security monitoring. Supports filtering by event type exclusions and date ranges.
read-only
APIs Used
sophos-siem