This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

CredGuard exploit prevention in 0patch Service

I'm running 0patch for hot patching. After activating 'Active Adversary Mitigations' the 0patch Service is blocked mentioning "CredGuard" in the events on the PC itself.

Unfortunately in Sophos Central there is only reported that a malware is active or couldn't be cleaned.

Trying to create an exception I had to exclude the process as the exploit does not show up in the exploit list. But creating an exception for the process doesn't change the behaviour.

What can I do to create a working exception? Why does the exploit not show up in Sophos Central?


I should mention that I'm taking part in the EDR beta and have other versions installed. Maybe this is important.

This thread was automatically locked due to age.
Parents Reply Children
  • Hi Gowtham,


    Mitja Kolsek of 0patch here. Please don't hesitate to reach out to me for resolving this issue. We can do some tests and help you pinpoint the problem.




  • Hi Gowtham,


    unfortunately nothing about this event shows up in the Central dashboards. Only my computer is marked as critical.

    I'm going to send you a PM. Thanks.

    Regards, Jelle

    Sophos XG210-HA (SFOS 18.0.4) on SG210 appliances with Sandstorm and 1x AP55
    Sophos Central with Intercept X Advanced, Device Encryption, Phish Threat, Mobile Control Advanced

    If a post solves your question use the 'This helped me' link.