• Announcements: Queries for endpoint (Firewall coming soon)

    Hi all I have started populating the queries section of the forum.  I Expect to put about 50 queries into the forum to perform the basic navigation and exploration of the data.  Once I get those loaded in we will start adding more interesti...
  • Release Notes & News: Intercept X Protection Enhancements

    We're starting to turn on IPS and Behavior detection features for endpoint and server customers. You'll see a new "Detect malicious behavior" option in threat protection policies. You can test both of these features now in the Early Access Program; ...
  • Release Notes & News: Intercept X with EDR September enhancements

    Throughout September we will continue to enhance EDR capabilities and with our latest update we are pleased to announce that the powerful EDR querying and response capabilities of Live Discover and Live Response are now generally available on Ma...
  • Announcements: Notice for next EAP update

    Hello all, We are due to update our EAP agent during the week of 21st September; this update has some small fixes in it and will allow us to start enabling IPS and our new behavioral engine.  Note: After this update you need to reboot devices to...
  • Release Notes & News: Enhancing EDR in The Cloud

    We are excited to announce that Intercept X for Server Advanced with EDR has been enhanced with powerful cloud visibility features from Cloud Optix.

    In addition to even more detail on AWS, Azure and GCP cloud workloads, this integration gives Sophos partners and customers critical insight into their wider cloud environment including security groups, hosts, shared storage, databases, serverless, containers and more.

     

  • Release Notes & News: Sophos Intercept X Advanced with EDR just keeps getting better

    Sophos continues to enhance our new EDRv3 capabilities and over the past week numerous improvements have been introduced:

    Role Based Access Controls for the Live Response Beta:

    One of the top requests received during the Live Response Beta during the Early Access Program was to provide Administrators better control around defining Central admins who can use Live Response and who can manage the Live Response settings. 

  • Announcements: Exploring Windows Events and Security groups with Live Discover

    For query assistance, please see the following Best Practices guide

    The Sophos UK Sales engineering team has been getting familiar with live discover. In the work they explored group policy and provided the following queries:

    Deleted security groups -

    Variable to specify the number of days to check
    Windows

    /* Deleted Security Groups */
    SELECT
       source,
       eventid, 
       CAST(datetime(time, 'unixepoch') AS TEXT) AS 'Change Made',…

  • Announcements: Detecting Glupteba malware with Sophos EDR

    Last week SophosLabs published a report about the Glupteba malware. According to Sophos Labs this malware family has been growing in numbers. "This malware, with its hard-to-pronounce name, has been getting regular updates and feature enhancements that seem to be focused on its ability to conceal itself from detection on infected computers....The core malware is, in essence, a dropper with extensive backdoor functionality, but…

  • Release Notes & News: Intercept X Advanced with EDR: Start using the powerful new EDR features

    We are thrilled to announce that the latest version of Sophos EDR (endpoint detection and response) is now available to all Intercept X Advanced with EDR and Intercept X Advanced for Server with EDR customers.  This release brings powerful new capabilities that enable both IT admins and security analysts to ask detailed IT operations and threat hunting questions across their entire estate. It also provides new functionality …

  • Release Notes & News: Linux EDR - Live Discover

    There have been posts about our exciting new Linux EDR release elsewhere on the forum, but in case you missed them; here they are!

    We have had our Live Discover feature available for Linux Servers in our Early Access Program for a couple of months; this will be launching next week. Live Discover allows admins to search their data to answer almost any question they can think of by searching across their servers using SQL…

  • Announcements: Live Discover for LINUX.... Video

    In the next two weeks we will be fully launching the EDR Live Discover for LINUX.

    The capabilities on Linux are simply astounding, we have been busy creating the prebuilt queries and finishing the last bit of work before this is fully available.

    In the video, Ethan Vince-Urwin, one of the core linux developers who has been building the features we all love takes the product for a test drive and shows off some of the power…

  • Announcements: KingMiner non-deterministic indicators of compromise

    For query assistance, please see the following Best Practices guide

    See the story from SophosLabs Uncut on KingMiner: https://news.sophos.com/en-us/2020/06/09/kingminer-report/

    The article is both educational and enlightening.  One of the aspects of KingMiner that is common with other attacks is that many of the indicators of compromise are non-deterministic.  The domain names and URLs they use are all auto generated.   I read…

  • Release Notes & News: Intercept X with EDR: Powerful new IT operations and threat hunting features now available

    We are thrilled to announce that the latest version of Sophos EDR (endpoint detection and response) is now available in Intercept X Advanced with EDR and Intercept X Advanced for Server with EDR.  This release brings powerful new capabilities that enable both IT admins and security analysts to ask detailed IT operations and threat hunting questions across their entire estate. It also provides new functionality to remotely respond…

  • Announcements: New Sophos Table - Sophos_process_activity

    For query assistance, please see the following Best Practices guide

    We have added a new table to the sophos forensics journals. The sophos_process_activity table.

    Often as part of an investigation you need to to get a quick view of what a process did in the past and this table provides a quick lookup location for that information.

    This table contains a subject for each of the other Sophos 'journals' and collects some of…

  • Announcements: Live Discover Queries - Review Process

    Posting a query to the Live Discover Queries board will now include a review process.  This will allow us to review any question and proposed answer prior to it being visible by others.  We are adding this to ensure that the content of the queries do not contain anything inappropriate and that the query has been reviewed and tested and is not believed to cause harm. as for how well it does what it says.  we advise administrators…

  • Announcements: How to find and use the Schema for Live Discovery Queries

    For query assistance, please see the following Best Practices guide

    While we have the schema posted on the EAP community pages, I have had a number of request for how to find it and how to use it.

    First how to find the schema(s):

    From the Sophos Community: We provide a link to definition of the sophos windows schema on the community form in the documents section. You can downlaod the file with this link: https://community…

  • Release Notes & News: Updated Endpoint User Interface

    We're pleased to announce that a new version of the Sophos Endpoint user interface is being rolled out to customers. Windows clients will begin updating this week, with Windows servers following in June.

    The key goal of the update is to better represent our different endpoint components (Intercept X, Central Device Encryption, and the upcoming Unified Endpoint Management agent), and to bring a consistent look across…

  • Announcements: Intercept X with EDR EAP - Variable support for queries

    Starting on the week of may 18 we will be adding variable support to queries.

    You can create queries that now include support for up to 6 variables. A variable will be given a $$ prefix and postfix and can be either a TEXT or DATE value.  You will write your query and specify the variable information in the query.  Then when you run it you will be able to simply drop in the information for the variable and we will automatically…

  • Announcements: Intercept X with EDR EAP Update - Adding Create/Save/Edit Queries

    The week of May 18 we will be turning on two powerful new capabilities in the EAP, Edit Query and Query Variables.

    CREATE, SAVE queries - With this new capability you can now create and save your own queries, This will allow you to start from scratch or modify an existing query.  You will need to give your query a name, description, identify one or more categories it will be a part of and specify what operating systems…

  • Announcements: Live Response now in Early Access and other EDR updates

    Note: Use of all features and functionalities provided under the Early Access Program is subject to the Sophos End User License Agreement.

     

    We are excited to announce that Live Response is now available in early access.

     

    Live Response allows admins to remotely connect to devices and get access to a command line interface so that detailed investigations can be performed, or to take prompt action to contain or remediate a…

  • Announcements: Help design the future of security; Live Discover User Experience Research

    Can you help to shape our future products?

     

    We're looking for customers and partners to join our Sophos Design Partner group. Sign up and you'll be able to give us your product feedback and ideas through surveys, interviews, or usability testing.

    You'll be helping to make the world a safer place -- and you might win Amazon vouchers while you're doing it.

    We’re particularly keen to talk to customers who…

  • Announcements: New Windows endpoint UI

    I'm pleased to say that a new version of our endpoint user interface is being released to EAP customers this week. Windows devices (client and server) enrolled in the EAP will receive the update automatically.

    The key goal of the update is to better represent Sophos' different endpoint components - Intercept X, Central Device Encryption and our upcoming UEM agent. It will also to bring a consistent look across platforms…

  • Announcements: New Linux EDR Agent now available in Early Access


    We are excited to announce that we have added our new Linux EDR agent to the New Server Protection and EDR Features early access program.

    Joining the EAP:

    To get access to the new agent you must first join the New Server Protection and EDR Features early access program. See this presentation on how to join the EAP.

    Getting access to the agent and installing:

    Once you have successfully joined, from the Protect Devices…

  • Release Notes & News: Sophos Anti-Virus version 9.9.8 for MAC OS released

    Hi Community,

    Sophos Anti-Virus v9.9.8 for Mac OS has been released. This release has the fix for blank captive portal.

    For more information, please refer to the below release notes: