Skip to content

lof1sec/sophos-xdr

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

9 Commits
 
 
 
 

Repository files navigation

Sophos-XDR SIEM integration

This is a script for querying the Sophos XDR datalake. You only need valid API credentials. The SQL query is hardcoded and based on the "sophos_events_windows" template. The script creates a JSON log that is ready to be shipped to any SIEM solution.

Releases

No releases published

Packages

No packages published

Languages