Hello,
does anyone know, if Sophost blocks, deletes or put into quarantine penetration testing tools, like fuzzers, exploitation tools or remote access tools?
Thanks.
This thread was automatically locked due to age.
Hello,
does anyone know, if Sophost blocks, deletes or put into quarantine penetration testing tools, like fuzzers, exploitation tools or remote access tools?
Thanks.
Hi Jaroslav,
Thank you for reaching out to us. I would like to confirm that we have strong Behavior Detection signatures for Meterpreter loaded in the memory. As a test you may feel free to attack a box using TheFatRat. As soon as Sophos AV detects the shell's presence in memory, we'll kill the offending process and flag it to the user.
Talking about Pupy, I would say Sophos AV/Intercept X's Deep Learning would easily catch the generated payload. If it doesn't - I'm all ears! It's the undying efforts of wonderful people like who who help us get better at what we do.
And this is me only talking about Sophos Antivirus. If you have Intercept X, it adds several layers of security.
In any case, if you find that the tests are succeeding, feel free to DM me and we can take a look together!
Thanks,
Vikas
Global Escalations - Malware
Hi Jaroslav,
Thank you for reaching out to us. I would like to confirm that we have strong Behavior Detection signatures for Meterpreter loaded in the memory. As a test you may feel free to attack a box using TheFatRat. As soon as Sophos AV detects the shell's presence in memory, we'll kill the offending process and flag it to the user.
Talking about Pupy, I would say Sophos AV/Intercept X's Deep Learning would easily catch the generated payload. If it doesn't - I'm all ears! It's the undying efforts of wonderful people like who who help us get better at what we do.
And this is me only talking about Sophos Antivirus. If you have Intercept X, it adds several layers of security.
In any case, if you find that the tests are succeeding, feel free to DM me and we can take a look together!
Thanks,
Vikas
Global Escalations - Malware