/sophos-central-alerts | Type: Application | PCID required: Yes
Tools
| Tool | Description |
|---|---|
sophos-central-alerts_acknowledge_alert | Take action on an alert |
sophos-central-alerts_create_case | Create investigation case |
sophos-central-alerts_delete_case | Delete case |
sophos-central-alerts_get_alert | Get alert details |
sophos-central-alerts_get_case | Get case details |
sophos-central-alerts_get_case_mitre_attack_summary | Get MITRE ATT&CK summary |
sophos-central-alerts_get_who_am_i | Get caller identity and tenant information |
sophos-central-alerts_list_alerts | List alerts |
sophos-central-alerts_list_case_detections | List case detections |
sophos-central-alerts_list_case_impacted_entities | List impacted entities |
sophos-central-alerts_list_cases | List investigation cases |
sophos-central-alerts_search_alerts | Search alerts |
sophos-central-alerts_update_case | Update case |
sophos-central-alerts_acknowledge_alert
Take action on an alert Parameters:| Parameter | Type | Required | Default | Description |
|---|---|---|---|---|
alertId | string | Yes | — | Alert ID |
action | string | Yes | — | Action to perform (e.g., acknowledge) |
message | string | No | — | Optional message for the action |
sophos-central-alerts_create_case
Create investigation case Parameters:| Parameter | Type | Required | Default | Description |
|---|---|---|---|---|
assignee | string | No | — | Assignee ID |
initialDetectionId | string | No | — | Initial detection ID to link |
name | string | Yes | — | Case name |
overview | string | No | — | Case overview |
severity | string | Yes | — | Case severity |
status | string | Yes | — | Case status |
type | string | Yes | — | Case type |
sophos-central-alerts_delete_case
Delete case Parameters:| Parameter | Type | Required | Default | Description |
|---|---|---|---|---|
caseId | string | Yes | — | Case ID |
sophos-central-alerts_get_alert
Get alert details Parameters:| Parameter | Type | Required | Default | Description |
|---|---|---|---|---|
alertId | string | Yes | — | Alert ID |
sophos-central-alerts_get_case
Get case details Parameters:| Parameter | Type | Required | Default | Description |
|---|---|---|---|---|
caseId | string | Yes | — | Case ID |
sophos-central-alerts_get_case_mitre_attack_summary
Get MITRE ATT&CK summary Parameters:| Parameter | Type | Required | Default | Description |
|---|---|---|---|---|
caseId | string | Yes | — | Case ID |
sophos-central-alerts_get_who_am_i
Get caller identity and tenant informationsophos-central-alerts_list_alerts
List alerts Parameters:| Parameter | Type | Required | Default | Description |
|---|---|---|---|---|
pageSize | integer | No | — | Number of items per page |
page | integer | No | — | Page number |
severity | string | No | — | Filter by severity |
category | string | No | — | Filter by category |
product | string | No | — | Filter by product |
from | string | No | — | Filter alerts from this timestamp |
sophos-central-alerts_list_case_detections
List case detections Parameters:| Parameter | Type | Required | Default | Description |
|---|---|---|---|---|
caseId | string | Yes | — | Case ID |
pageSize | integer | No | — | Items per page |
page | integer | No | — | Page number |
sophos-central-alerts_list_case_impacted_entities
List impacted entities Parameters:| Parameter | Type | Required | Default | Description |
|---|---|---|---|---|
caseId | string | Yes | — | Case ID |
pageSize | integer | No | — | Items per page |
page | integer | No | — | Page number |
sophos-central-alerts_list_cases
List investigation cases Parameters:| Parameter | Type | Required | Default | Description |
|---|---|---|---|---|
pageSize | integer | No | — | Number of items per page (1-50) |
page | integer | No | — | Page number |
sophos-central-alerts_search_alerts
Search alerts Parameters:| Parameter | Type | Required | Default | Description |
|---|---|---|---|---|
filter | object | No | — | Filter criteria as key-value pairs |
pageSize | integer | No | — | Number of items per page |
pageTotal | boolean | No | — | Include total count |
sort | string[] | No | — | Sort fields (e.g., [‘-raisedAt’] for descending) |
sophos-central-alerts_update_case
Update case Parameters:| Parameter | Type | Required | Default | Description |
|---|---|---|---|---|
caseId | string | Yes | — | Case ID |
assignee | string | No | — | Updated assignee |
name | string | No | — | Updated name |
overview | string | No | — | Updated overview |
severity | string | No | — | Updated severity |
status | string | No | — | Updated status |

