• Sophos Endpoint

    Guys, I have a doubt. there is no more sophos product for endpoint with EDR? XDR only?
  • Check Confluence Version to confirm Patch - Confluence Server Webwork OGNL injection (CVE-2021-26084)

    This query will check the installed version of Confluence and print the message IF the installed confluence version is PATCHED or NOT PATCHED. SELECT DISTINCT 'Check Confluence Version to confirm Patch' Test, CASE version WHEN '6.13.23' THEN…
  • alarm shows in Security Health page in Sophos central portal

    Hi everyone, My client had deployed End-point protection with an activatable license key entered in central portal. However, here is a warning alert shows some features are not able to run. See attach screen. May I know is there any idea refer the…
  • Is Sophos Intercept X Advanced with EDR support Consumption/PAYG Billing (Month-on-Month) and MSP Multi-Tenant Licensing & Activation ?

    I tried to find the details about the PAYG Billing (Month-on-Month)/consumption and MSP multi-Tenant licensing support but didn't find this information anywhere. Can anyone please help to get the answer of above query?
  • Intercept X advanced With EDR query for a keylogger

    Hi , I have a keylogger written in python listening and sending a file containing the keys pressed by the user to an email every time the user press esc. i want to detect it using Sophos edr by a query that look to a process sending a file periodically…
  • How do you investigate "Safe Browsing detected browser Google Chrome has been compromised"

    Good day everyone! I am sure we have all seen a few of these pop up in our environments: "Safe Browsing detected browser Google Chrome has been compromised". My question is, what steps do you take to investigate this alert? There is a rather small…
  • Cannot install EDR agent con cento7

    I cannot install EDR agent on centos7 server I downloaded EDR server from my dashboard and save it as a bash script I copied this nash script on the server to protect and execute it: this is the console message /root/sophos_edr.sh: line 1: #!…
  • Intercept X With EDR on Windows Server Core

    I can't find documentation on this so I'm hoping someone can answer this for me. Is it supported to install Intercept X with EDR on a Windows Server 2019 Core (Without Desktop Experience) Server? Specifically, one with the Hyper-V Role installed hosting…
  • how to check if a windows server applied EDR EAP?

    we enabled the EAP for Servers. How can I check if the servers have this enabled? Is this it?
  • Intercept X advanced with EDR trial licence problem

    Our orginization got the licence for the intercept x advanced, 3 days ago i started the trial for the intercept x advanced with EDR, and all the licences shifted to the trial, what happens once the trial expires, will i have to uninstall and install…
  • EDR can't use live response because need MFA

    Good morning, in our eviroment we can't use live response on uor EDR beacuase we need to activate the MFA for admin account, but at this moment we use azure federation for login with microsoft account(who already has mfa anabled), but we still have…
  • Live query pre-res / requirements

    Hi, I've looked for this information in the Admin guide and various other locations but I've drawn a blank. I'm trying to gather some information on the pre-reqs for a good Sophos Live query, specifically the logs. After all, a query is only as good…
  • Need Docs for Linux EDR

    Ive installed Central EDR linux but its file structure and cmd's are different to Central Linux, Is there a pdf around with the updated cmds for linux edr pls?? I cant run manual tasks with EDR installed as the file names and locations have all changed…
  • [Sophos Notification] Intercept X with EDR Early Access Program Now Open!

    Hi Community, The best just got better. Sophos is pleased to announce that the Intercept X Advanced with EDR Early Access Program is now open. The new Endpoint Detection and Response (EDR) capabilities allow you to take charge of security incidents…