Schedule scans for IoC's in Threat Searches.
It would be nice to create a scheduled scan for all devices (servers included) for whatever IoC's you add to it.
Integrating Yara rules into Sophos Central EDR seems to be a quite good idea. The new upcoming feature where it is possible to create invidual searches seems to going into that direction, but unfortunately it does not "understand" Yara and OpenIOC yet.
As security authorities tend to provide information about threats including Yara rules, it would be a huge benefit to have this integrated instead of being required to use other products to fulfill the required search for indicators of compromise (IOS).
To name a few other Software Solutions as an example of what we are looking for: Thor and Loki from nextron, Trend Micro Apex Central 2019 offers an API "CreateScan (OpenIOC and YARA Files)", Tenable Nessus offers threat Hunting using Yara rules, Kaspersky Anti Targeted Attack Platform allows uploading Yara rules, ….
So please Sophos take up this idea and improve your offering (I believe best integrated into Sophos Central with EDR).