Hi Community,
A new version of Intercept X has been released to our Sophos Central customers.
The release updates:
Sophos Central Intercept X version to 2.0.20
HitmanPro.Alert component version to 3.8.1.504
Resolved issues
Resolved issues fo...
For those enrolled in the XDR & EDR Data Lake early access program (EAP), this week we will be launching new pivoting capabilities which allow administrators to rapidly navigate from the result of one query to an available Action, Query, or Enric...
Hi Community,
The following is being released to Sophos Central Window Servers:
Server Core Agent 2.15.4
Endpoint Advanced 10.8.10
The following are changes of note introduced in this release:
Enablement of Tamper Protection in safe boot
Upd...
The latest of our Live Response enhancements is now available to customers with the release of our new Live Response per session audit logs.
Typically a few minutes after running a Live Response session, if you navigate to the Logs and R...
For query assistance, please see the following Best Practices guide
With the data lake we can do some interesting IOC hunts that perform counts across all devices for similar IOC's and with some use of variables we allow for the administra...
Hello Community.
A new version of Sophos Central Endpoint for macOS and Sophos Anti-virus for macOS (OPM) has been released now.
The release versions are:
Central 10.0.4
OPM 9.10.2
Release information
This release contains th...
We're pleased to announce that the XDR & EDR Data Lake Early Access Program is now publicly available to our Intercept X Endpoint and Server customers.
For customers who join and enroll devices into these endpoint and/or server early access progr...
For anyone who's joined the XDR & EDR Data Lake Early Access Program, we've been providing instructions on the different steps to join and enroll devices but I thought it would be useful to have one full blog post covering those steps and also de...
For query assistance, please see the following Best Practices guide
(NEW) Video on Schemas for EDR and Data Lake (15 Min)
https://vimeo.com/515493008
With the addition of the data lake a significant amount of new information is available....
In this 7min video we show the features that were enabled on Feb 22nd for the Early Access Program for the XDR Data lake.
Welcome to the EAP and stay tuned more features are coming in March and April as we add
Context aware pivoting to another query...
For query assistance, please see the following Best Practices guide
One of the most frequently used queries by our threat hunting team is a flexible generic search query against the data lake.
Often you know exactly what you are looking fo...
For query assistance, please see the following Best Practices guide
Below is a query that will list all installed applications, the publisher, application name, and version number. It performs some nice counting so you don't have to deal w...
For query assistance, please see the following Best Practices guide
Below is a query that will list all installed applications, the publisher, application name, and version number. It performs some nice counting so you don't have to deal with a long...
For query assistance, please see the following Best Practices guide
One of the most frequently used queries by our threat hunting team is a flexible generic search query against the data lake.
Often you know exactly what you are looking fo...
In this brief demo video we cover the core features being add during the early access program and as part of the expected product availability in May/June 2021
Content
Data Lake and direct endpoint queries from one console (Available in EAP)
Schedul...
For query assistance, please see the following Best Practices guide
With the addition of the data lake a significant amount of new information is available. In this document we will discuss each of the core database schemas.
For thos...
Hi Community,
The following is being released to Sophos Central Windows Endpoints :
Core Agent v2.15.4
Endpoint Advanced v10.8.10
The following are changes of note introduced in this release:
Enablement of Tamper Protection in safe boot mode...
New feature – Tamper Protection Password Export (due for release on w/c 25th January)
Sophos Central allows you to recover the tamper protection passwords of devices that you’ve recently deleted.You might need to do this so that you...
This blog post contains a listing and details on features that have previously been released to the New Endpoint/Server Protection Features early access program and are now generally available to all customers.
19/08/2020 - IPS for Windows Ser...
Hi Community,
The latest Sophos Linux Protection has been released with the following module version changes:
Sophos Linux Base has been updated to 1.1.4.
Sophos Live Discover plugin has been updated to 1.1.0.
Sophos Linux Live Response has be...
Hi Community,
The following is being released to Sophos Central Windows Endpoints and Servers:
Core Agent v2.10.8
Update components are:
Sophos AutoUpdate updated to version 6.6.386.
Sophos Endpoint Defense updated to versi...
IaaS connector functionality for Amazon AWS and Microsoft Azure is being removed from the Intercept X Advanced for Server (SVRCIXA) and Central Server Protection (SVRC) licenses. It is being replaced by the more comprehensive capabilities of Sophos C...
Sophos appreciates your assistance. Please make sure to read all the items in this post. Also, please report any issues on the Discussions forum - we need your feedback to help improve the product.
Overview
Support is now GA (Generally Available) fo...
Check out this webinar where the Sophos Engineering and PM team give an introduction on coding against the EDR Data Lake API and walk through using and modifying the Sophos Data Lake Test tool.
vimeo.com/.../ad569fd23d