• Announcements: XG Firewall data

    For query assistance, please see the following Best Practices guide I am adding a set of queries to explore information in the data lake from the XG Firewall. For the data lake to have information from the XG Firewall you will need to have...
  • Announcements: API Guide - Getting Started

    You can find the getting started guide for the EDR Data Lake APIs available here on the apigee.io site we use. Overview This guide takes you through a few simple steps to start using the new EDR Data Lake APIs in Sophos Central. All our APIs are off...
  • Release Notes & News: Track Network Connections - New policy setting

    Hi all, We are releasing a new policy setting to all customer on the w/c 2nd November, 'Track Network Connections'. This will be in the Advanced Settings section of the Threat Protection policy We plan to enable this new feature gradually ov...
  • Announcements: License changes to New Endpoint and Server Protection and EDR Features early access programs

    With having completed the early access testing on our new EDRv3 capabilities and with the upcoming features that will be entering the New Endpoint and Server Protection and EDR Features early access program being more protection rather than EDR relat...
  • Release Notes & News: Sophos Central- Sophos Core Agent v2.10.7 and Endpoint Advanced v10.8.9 has been released

    Hi everyone,  The following versions have been released to Sophos Central Windows Endpoints.  Sophos Core Agent 2.10.7 Endpoint Advanced 10.8.9 This release will require a reboot. Please see the following release notes for more informatio...
  • Announcements: Queries for endpoint (Firewall coming soon)

    Hi all I have started populating the queries section of the forum.  I Expect to put about 50 queries into the forum to perform the basic navigation and exploration of the data.  Once I get those loaded in we will start adding more interesti...
  • Release Notes & News: Intercept X Protection Enhancements

    We're starting to turn on IPS and Behavior detection features for endpoint and server customers. You'll see a new "Detect malicious behavior" option in threat protection policies. You can test both of these features now in the Early Access Program; ...
  • Release Notes & News: Intercept X with EDR September enhancements

    Throughout September we will continue to enhance EDR capabilities and with our latest update we are pleased to announce that the powerful EDR querying and response capabilities of Live Discover and Live Response are now generally available on Ma...
  • Announcements: Notice for next EAP update

    Hello all, We are due to update our EAP agent during the week of 21st September; this update has some small fixes in it and will allow us to start enabling IPS and our new behavioral engine.  Note: After this update you need to reboot devices to...
  • Release Notes & News: Enhancing EDR in The Cloud

    We are excited to announce that Intercept X for Server Advanced with EDR has been enhanced with powerful cloud visibility features from Cloud Optix.

    In addition to even more detail on AWS, Azure and GCP cloud workloads, this integration gives Sophos partners and customers critical insight into their wider cloud environment including security groups, hosts, shared storage, databases, serverless, containers and more.

     

  • Release Notes & News: Sophos Intercept X Advanced with EDR just keeps getting better

    Sophos continues to enhance our new EDRv3 capabilities and over the past week numerous improvements have been introduced:

    Role Based Access Controls for the Live Response Beta:

    One of the top requests received during the Live Response Beta during the Early Access Program was to provide Administrators better control around defining Central admins who can use Live Response and who can manage the Live Response settings. 

  • Announcements: Exploring Windows Events and Security groups with Live Discover

    For query assistance, please see the following Best Practices guide

    The Sophos UK Sales engineering team has been getting familiar with live discover. In the work they explored group policy and provided the following queries:

    Deleted security groups -

    Variable to specify the number of days to check
    Windows

    /* Deleted Security Groups */
    SELECT
       source,
       eventid, 
       CAST(datetime(time, 'unixepoch') AS TEXT) AS 'Change Made',…

  • Announcements: Detecting Glupteba malware with Sophos EDR

    Last week SophosLabs published a report about the Glupteba malware. According to Sophos Labs this malware family has been growing in numbers. "This malware, with its hard-to-pronounce name, has been getting regular updates and feature enhancements that seem to be focused on its ability to conceal itself from detection on infected computers....The core malware is, in essence, a dropper with extensive backdoor functionality, but…

  • Release Notes & News: Intercept X Advanced with EDR: Start using the powerful new EDR features

    We are thrilled to announce that the latest version of Sophos EDR (endpoint detection and response) is now available to all Intercept X Advanced with EDR and Intercept X Advanced for Server with EDR customers.  This release brings powerful new capabilities that enable both IT admins and security analysts to ask detailed IT operations and threat hunting questions across their entire estate. It also provides new functionality …

  • Release Notes & News: Linux EDR - Live Discover

    There have been posts about our exciting new Linux EDR release elsewhere on the forum, but in case you missed them; here they are!

    We have had our Live Discover feature available for Linux Servers in our Early Access Program for a couple of months; this will be launching next week. Live Discover allows admins to search their data to answer almost any question they can think of by searching across their servers using SQL…

  • Announcements: Live Discover for LINUX.... Video

    In the next two weeks we will be fully launching the EDR Live Discover for LINUX.

    The capabilities on Linux are simply astounding, we have been busy creating the prebuilt queries and finishing the last bit of work before this is fully available.

    In the video, Ethan Vince-Urwin, one of the core linux developers who has been building the features we all love takes the product for a test drive and shows off some of the power…

  • Announcements: KingMiner non-deterministic indicators of compromise

    For query assistance, please see the following Best Practices guide

    See the story from SophosLabs Uncut on KingMiner: https://news.sophos.com/en-us/2020/06/09/kingminer-report/

    The article is both educational and enlightening.  One of the aspects of KingMiner that is common with other attacks is that many of the indicators of compromise are non-deterministic.  The domain names and URLs they use are all auto generated.   I read…

  • Release Notes & News: Intercept X with EDR: Powerful new IT operations and threat hunting features now available

    We are thrilled to announce that the latest version of Sophos EDR (endpoint detection and response) is now available in Intercept X Advanced with EDR and Intercept X Advanced for Server with EDR.  This release brings powerful new capabilities that enable both IT admins and security analysts to ask detailed IT operations and threat hunting questions across their entire estate. It also provides new functionality to remotely respond…

  • Announcements: New Sophos Table - Sophos_process_activity

    For query assistance, please see the following Best Practices guide

    We have added a new table to the sophos forensics journals. The sophos_process_activity table.

    Often as part of an investigation you need to to get a quick view of what a process did in the past and this table provides a quick lookup location for that information.

    This table contains a subject for each of the other Sophos 'journals' and collects some of…

  • Announcements: Live Discover Queries - Review Process

    Posting a query to the Live Discover Queries board will now include a review process.  This will allow us to review any question and proposed answer prior to it being visible by others.  We are adding this to ensure that the content of the queries do not contain anything inappropriate and that the query has been reviewed and tested and is not believed to cause harm. as for how well it does what it says.  we advise administrators…

  • Announcements: How to find and use the Schema for Live Discovery Queries

    For query assistance, please see the following Best Practices guide

    While we have the schema posted on the EAP community pages, I have had a number of request for how to find it and how to use it.

    First how to find the schema(s):

    From the Sophos Community: We provide a link to definition of the sophos windows schema on the community form in the documents section. You can downlaod the file with this link: https://community…

  • Release Notes & News: Updated Endpoint User Interface

    We're pleased to announce that a new version of the Sophos Endpoint user interface is being rolled out to customers. Windows clients will begin updating this week, with Windows servers following in June.

    The key goal of the update is to better represent our different endpoint components (Intercept X, Central Device Encryption, and the upcoming Unified Endpoint Management agent), and to bring a consistent look across…

  • Announcements: Intercept X with EDR EAP - Variable support for queries

    Starting on the week of may 18 we will be adding variable support to queries.

    You can create queries that now include support for up to 6 variables. A variable will be given a $$ prefix and postfix and can be either a TEXT or DATE value.  You will write your query and specify the variable information in the query.  Then when you run it you will be able to simply drop in the information for the variable and we will automatically…

  • Announcements: Intercept X with EDR EAP Update - Adding Create/Save/Edit Queries

    The week of May 18 we will be turning on two powerful new capabilities in the EAP, Edit Query and Query Variables.

    CREATE, SAVE queries - With this new capability you can now create and save your own queries, This will allow you to start from scratch or modify an existing query.  You will need to give your query a name, description, identify one or more categories it will be a part of and specify what operating systems…