Detections API
We have published a new Detections API to allow our XDR customers to query for detections from endpoints, servers, and third-party integrations.
Detections identify activity that's unusual or suspicious and might need investigation. They're based on data that devices upload to the Sophos Data Lake. You can use these detections to examine devices, processes, users, and events for signs of potential threats that other Sophos features haven't blocked.
See more details in the Detections API Guide.