Active Threat Response is a Sophos Firewall feature that uses Sophos X-Ops threat feeds to help detect and block threat activity, including C2-related indicators.
Go to:
Protect > Active Threat Response > Sophos X-Ops threat feeds
Set the action to:
Log and drop
To review detections, go to:
Control center > Sophos X-Ops
There you can review detected endpoints and IPs.
If a device is affected, perform a full/deep scan using Sophos Endpoint Security before marking the incident as resolved.
If you want, I can reformat this into a fuller KB article with purpose, procedure, and troubleshooting sections.