As previously communicated, from the beginning of June, no new customers are able to enroll into the XDR & EDR Data Lake Endpoint and Server early access programs (EAPs). For customers who were already enrolled, they are no longer able to a...
Click to view the Japanese version: Intercept X Advanced with EDR のアップデート
With the launch of EDR 4.0 in May, Sophos has introduced significant enhancements to the Endpoint Detection and Response (EDR) offering. A key new EDR component is the S...
Hi guys,
We are running a new UX Research Project to understand better what types of Orientation Information is most important to our users regarding Indicators of Compromise (IOCs).
If you are interested and would like to help with this project, we ...
As previously communicated, from the beginning of June, no new customers are able to enroll into the XDR & EDR Data Lake Endpoint and Server early access programs (EAPs). For customers who were already enrolled, they are no longer able to a...
Hi all,
We have some exciting changes coming to the Endpoint/Server Protection and EDR Features Early Access Program over the next few weeks. One of the biggest changes is the decrypt and re-encrypt of HTTPS traffic between the browser and the w...
Hello All,
With EDRv4 and our new XDR offering having become generally available in mid-May, Sophos will now begin the wind down of the XDR & EDR Data Lake Early Access Programs. At this point we will not be introducing any new functionalit...
We are pleased to announce that today, May 19, we have released some exciting updates for all customers using Sophos EDR (Endpoint Detection and Response) with Intercept X Advanced with EDR and Intercept X Advanced for Server with EDR.
What’s n...
Following on from my announcement back in December about changes to AWS and Azure Connectors in Intercept X for Server; i'm pleased to inform you about Cloud Optix Standard.
Sophos Intercept X Advanced for Server customers now benefit from C...
Sophos appreciates your assistance. Please make sure to read all the items in this post. Also, please report any issues on the Discussions forum - we need your feedback to help improve the product.
Overview
This Early Access Program allows...
Hi Community,
On behalf of the team, we would like to thank everyone who participated in our Big Sur Early Access Program and especially those who took the time to share their feedback.
The team would also like to extend a special thank you...
With the release of the product we will be adding scheduled query reports.
This feature is NOT YET available in the EAP but is coming with the general release in mid May. For those eager to see it before it is complete I have recor...
BRIEF Video on EMAIL and the Data Lake.
In this video we show the EMAIL Attachment and URL table that is available in the data lake, we also pivot from a URL seen an an email to ask if any endpoint have ever communicated to that URL and if so what pr...
A 30 min tour of some of the capabilities of Sophos Intercept X with EDR XDR. In this 30 min video I touch on some of the core concepts in the product and explain a bit about how queries work and show some of the features. It by no means covers...
Often administrators would prefer to see the graphical view of the attack instead of the tables.
With a graphical view it is often MUCH easier to understand what was happening and come to a decision is something is malicious or not.
To he...
We continue to make excellent progress to the intended May release of the Data Lake version of the product.
This week I wanted to demonstrate some of the capabilities we have just added around Pivots and the Depth of information available for admins ...
Welcome to the EDR Data Lake EAP (Early Access Program).
How do I learn more
In this forum you will find a number of documents, videos, queries and posts explaining the program and if you have any questions you can post them to the discussions area ...
After the launch of Intercept X Advanced with EDR in late 2018, we introduced the EDRv1 Data Feed (aka Trickle Feed) functionality to enable Administrators to easily view Threat Indicators and perform Threat Searches. Now there is a better way! The L...
For query assistance, please see the following Best Practices guide
Watch the video from the technical demo where we cover how to use Live Discover datalake queries.
https://vimeo.com/519661823
Queries used during SophSkills Demo
DATA LAKE...
Hi Community,
A new version of Intercept X has been released to our Sophos Central customers.
The release updates:
Sophos Central Intercept X version to 2.0.20
HitmanPro.Alert component version to 3.8.1.504
Resolved issues
Resolved issues fo...
For those enrolled in the XDR & EDR Data Lake early access program (EAP), this week we will be launching new pivoting capabilities which allow administrators to rapidly navigate from the result of one query to an available Action, Query, or Enric...
Hi Community,
The following is being released to Sophos Central Window Servers:
Server Core Agent 2.15.4
Endpoint Advanced 10.8.10
The following are changes of note introduced in this release:
Enablement of Tamper Protection in safe boot
Upd...
The latest of our Live Response enhancements is now available to customers with the release of our new Live Response per session audit logs.
Typically a few minutes after running a Live Response session, if you navigate to the Logs and R...
For query assistance, please see the following Best Practices guide
With the data lake we can do some interesting IOC hunts that perform counts across all devices for similar IOC's and with some use of variables we allow for the administra...