HI,
Intercept X has removed a file. I whant to send it to Sophos Labs for analyzing. Where can I find it ? I do not whant to release it to get hold of it ;-)
This thread was automatically locked due to age.
HI,
Intercept X has removed a file. I whant to send it to Sophos Labs for analyzing. Where can I find it ? I do not whant to release it to get hold of it ;-)
No, that's why I asked. I don't want to restore it to the default location. I was just thinking if there is maybe a quarantine folder where all those files are kept. The file that we are talking about is a inf file and I am wondering what is in that file. I need to examine it because the fle name indicates it is indeed malicious. The name is "fuckgothin.inf". Google search led me to believe it is pulling stuff from an IP address.
Quarantined items are moved from SophosClean to the SafeStore which houses the unwanted/suspect data in an encrypted format. Files only can be restored/decrypted to their default location.
There are two SafeStore quarantine folders:
If you have Intercept X with EDR, you can do analysis also directly via Central. Maybe you just start a trial version if possible.
Intrusus
Sophos Certified Engineer | Sophos Certified Technician
private lab:
XG firewall with SFOS 20.X running on Proxmox
If a post solves your question use the 'Verify Answer' link
Quarantined items are moved from SophosClean to the SafeStore which houses the unwanted/suspect data in an encrypted format. Files only can be restored/decrypted to their default location.
There are two SafeStore quarantine folders:
If you have Intercept X with EDR, you can do analysis also directly via Central. Maybe you just start a trial version if possible.
Intrusus
Sophos Certified Engineer | Sophos Certified Technician
private lab:
XG firewall with SFOS 20.X running on Proxmox
If a post solves your question use the 'Verify Answer' link