This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos machine learning doesn't work?

I'm doing a POC with Crowdstrike and on the test computer we received a file that was detected as ( RegistryPersistEdit ) by Crowdstrike's machine learning. Sophos detected nothing and let the file make changes to the Windows registry. Sophos machine learning doesn't work? This is worrying. I have a ticket where I sent the sample file (07062400)

Thanks



This thread was automatically locked due to age.
Parents
  • Hi Maxim.

    Yes, it is an executable file. I submitted it to virustotal.com and some detect it as heuristic malware detection, so it's probably a malicious executable file that Sophos didn't detect.

    The license we use is Intercept-X Advanced with XDR. I'll wait for support's response, it could be a false positive from CrowdStrike.

Reply
  • Hi Maxim.

    Yes, it is an executable file. I submitted it to virustotal.com and some detect it as heuristic malware detection, so it's probably a malicious executable file that Sophos didn't detect.

    The license we use is Intercept-X Advanced with XDR. I'll wait for support's response, it could be a false positive from CrowdStrike.

Children
No Data