This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Will automatic interception be added to SOPHOS detection mode MITRE ATT&CK in the future?

Now this mode only has observation mode, I hope to add interception mode in the future, for example, if the high risk level exceeds a certain score, automatic interception will be triggered and threat chart will be automatically built



This thread was automatically locked due to age.
Parents
  • Hi Leung233,

    Thanks for reaching out to the Sophos Community Forum. 

    The detections you are seeing here typically require more analysis to determine all of what may be impacted on your environment. Creating an automated response based on the information Sophos ingests may be possible in the future, but I'm not aware of any immediate plans to develop something like this. The need to have a more intimate understanding of your network and environment is why incident response teams exist today.

    If the powershell command you've highlighted here is run by a user logged in normally into a workstation, a detection may not be raised. An adversary with elevated access to your systems running commands under the "normal user context" may not be detected by an antivirus due to the commands being seen as legitimate. 

    If there is another process on the system which tries to execute this PowerShell command, that will be detected as malicious. 

    Do let me know if this helps, and if I understood your question correctly.

    Kushal Lakhan
    Team Lead, Global Community Support
    Connect with Sophos Support, get alerted, and be informed.
    If a post solves your question, please use the "Verify Answer" button.
    The New Home of Sophos Support Videos!  Visit Sophos Techvids
Reply
  • Hi Leung233,

    Thanks for reaching out to the Sophos Community Forum. 

    The detections you are seeing here typically require more analysis to determine all of what may be impacted on your environment. Creating an automated response based on the information Sophos ingests may be possible in the future, but I'm not aware of any immediate plans to develop something like this. The need to have a more intimate understanding of your network and environment is why incident response teams exist today.

    If the powershell command you've highlighted here is run by a user logged in normally into a workstation, a detection may not be raised. An adversary with elevated access to your systems running commands under the "normal user context" may not be detected by an antivirus due to the commands being seen as legitimate. 

    If there is another process on the system which tries to execute this PowerShell command, that will be detected as malicious. 

    Do let me know if this helps, and if I understood your question correctly.

    Kushal Lakhan
    Team Lead, Global Community Support
    Connect with Sophos Support, get alerted, and be informed.
    If a post solves your question, please use the "Verify Answer" button.
    The New Home of Sophos Support Videos!  Visit Sophos Techvids
Children
No Data