Skip to main content

Overview

Authorization/setup steps

Connection Method: API
Setup Time: 15-20 minutes
Access Required: Administrator account

Data collected

This integration provides:
  • Security event data
  • Threat intelligence
  • Asset visibility
  • Compliance information

Setup instructions

1

Log in to your account

Access your Sophos dashboard with administrator credentials.
2

Create API credentials

Generate API credentials or tokens for ThreatAware integration. Navigate to API or integrations settings, create a new API key/token, and copy the credentials securely.
3

Configure in ThreatAware

Complete the integration setup in ThreatAware. Open ThreatAware and navigate to Settings > Integrations, search for and select Sophos, enter the required credentials, and click Connect to establish the integration.
4

Verify Connection

After connecting, ThreatAware will begin syncing data.
  • Check that the Integration Status shows as Active
  • Verify data is appearing in ThreatAware within 30 minutes

Required credentials

Field Name: Sophos API Key
Type: String (encrypted)
Description: The API key or token generated in Sophos
Store this credential securely in your organisation’s password manager for future reference.
Field Name: Sophos Endpoint
Type: String
Description: The API endpoint or URL for your Sophos instance
Format: Typically your instance URL or API endpoint
Example: https://api.sophos.com or your instance URL

Verification and testing

After setup, verify the integration is working correctly:
  1. Check Integration Status
    • Navigate to Settings > Integrations in ThreatAware
    • Confirm the Sophos integration shows Active status
    • Check the last sync timestamp
  2. Verify Data Collection
    • Wait 30-60 minutes for the initial data sync
    • Search for known devices or assets in ThreatAware
    • Verify the Sophos data is present
  3. Test Queries
    • Create a test query to filter devices with Sophos data
    • Verify the data matches your expectations

Troubleshooting

Symptoms: Integration status shows authentication failureSolutions:
  • Verify the API key/token is correct and not expired
  • Check if the API credentials have sufficient permissions
  • Ensure the credentials were not modified or rotated
  • Regenerate credentials if needed and update ThreatAware
Symptoms: Integration fails to connect or times outSolutions:
  • Verify the endpoint URL is correct and accessible
  • Check firewall rules allow outbound HTTPS (443) to the endpoint
  • Confirm the Sophos service is operational
  • Test the URL in a browser to ensure it’s reachable
Symptoms: Integration shows active but no data appearsSolutions:
  • Verify there is data available in Sophos to collect
  • Check API permissions allow access to the required data
  • Contact support for integration logs and debugging
  • Confirm devices/assets exist in your Sophos account

Additional resources

Sophos API Documentation

Official Sophos API documentation

ThreatAware Support

Contact support for integration assistance

Best practices

Credential Management
  • Create a dedicated API user/token specifically for ThreatAware
  • Document credentials in your organisation’s password manager
  • Rotate credentials annually or per your security policy
  • Monitor for authentication failures regularly
Security Considerations
  • Only grant minimum necessary permissions to API credentials
  • Review audit logs in Sophos periodically to monitor API usage
  • Follow your organisation’s least privilege principles
  • Disable credentials immediately if they are compromised