• WipeGuard exploit prevented in Sophos Endpoint Defense Software

    There is one client that does nothing else than reporting WipeGuard preventions. Even for Sophos Processes. What's the use of that feature and log? Initial Detection: WIN-MITRE-Behavioral-TA0040-T1561.002
  • Real time scanning slowing developer systems

    Real Time sanning is (or seems to be) causing major performance issues for our developers when they are creating a project using yarn to assemble the repositories, even if they have cached the files or have them in a local repository. Can the scans be…
  • Global folder exclusions and PUA's

    We are rolling out Sophos on our servers. One server holds the software repository with company software installers and a lot of tooling for us sysadmins. As one can guess, Sophos detects several PUA's, like Nirsoft apps, TightVNC, a.s.o. We and…
  • safe browsing

    I have a couple of computers that when downloading, it will stay at 100%. will not allow you to open the file/ will not open "Show in folder".... I can go to my downloads page and I can access it and run the download from there. So after so much troubleshooting…
  • Confusing Exclusion in Threat Protection Policy

    Why would someone want to add the directory %programfiles(x86)%\Sophos\Sophos Anti-Virus\ as an exclusion from scanning for threats in the Threat Protection Policy?
  • Endpoint Protection and VPN Connection

    Hello, I use an IPSecVPN / SSL VPN connection in conjunction with Sophos Endpoint Protection on the end devices in a company with around 200 employees. Unfortunately, our laptops have an extremely poor / slow connection as soon as endpoint protection…
  • Issue with Creative Cloud apps unable to overwrite files on the server.

    Hi, We have an issue where users are unable to overwrite Creative Cloud files on network shares. For instance if the user opens a Photoshop psd, makes a change and saves the file they get the error "could not save XXXXX.psd because write access was…
  • J'ai installé InterceptX chez une entreprise cliente. Tous les utilisateurs ne peuvent plus se connecter à leur application-metier. Quand je desinstalle sophos, la connexion revient. Que faire, SVP? Merci d'avance.

    J’a
  • Sophos exclusions for Microsoft Endpoint Configuration Manager?

    Is there anything special that needs to be done for Configuration Manager to work with Intercept-X? Some (not all and it changes A LOT) computers aren't seeing deployments in Software Center. Some computers will see 5 one day then all the next. Some will…
  • pages un responsive

    we have a desktop users which is installed the intercept x endpoint. now for these user are facing an issue that when they open a specific link the chrome or edge is getting error pages un responsive. when try with another user from the desktop which…
  • CryptoGuard detected ransomware in C:\Windows\explorer.exe

    Hi, We have had 2 of these notifications over the past week on two computers days apart. Can somebody please help me to understand this. Many thanks in advance. Endpoint Type : Computer OS : Windows Device : …
  • does sophos protect mapped drives on end points

    Does sophos protect mapped drives on endpoints?
  • Información de detección 'Troj/DrodZp-CB'

    Good afternoon I use SyncBackFree, it creates a temporary file. It is detecting it as a virus I've been looking for documentation on Troj/DrodZp-CB and I can't find any documentation. Has something similar happened to you?
  • I would like to know about SoPhos process information.

    Hi I would like to know about SoPhos process information. Please tell us in detail what function the two processes below perform. 1. SoPhosFilesScanner.exe 2. SSPService.exe
  • Sophos Endpoint ODS threshold time

    Anyone aware of a Sophos central managed Endpoint setting where we can restrict an On Demand scan to a particular time. let's say after 24 hours, it should stop.
  • Difference between Sophosfilescanner.exe and SophosFS.exe process

    I wanted to understand the Difference between Sophosfilescanner.exe and SophosFS.exe process, are they same in functionality ? Is SophosFileScanner.exe have the role of SAVservice.exe which has been removed recently after Core agent update 2.20.11 …
  • What details are specific to a Detection ID?

    We recently had a false positive from CryptoGuard and were unsure whether to exclude it via Detection ID or filename+filepath. What details actually make up a Detection ID? We installed two versions of the software and although the exe file that caused…
  • Sophos Intercept X

    Could anyone let me know the main features which is available in Sophos intercept X, ( this is for presentation purpose, it would be great if anyone explains me briefly if you know) thanks in advance Have a great day ahead
  • machine learning for malware detection

    Hello experts, I have a question about machine learning for malware detection. How does "machine learning" work at Sophos? How can you imagine that? I see many analyzes in the reports from Sophos labs intelix that draw on an enormous database. How is…
  • Which exclusions for Siemens OPC Server

    Hi, the services of the Siemens OPC Server do not start in the appropriate time. After I change the OPC services to automatic delayed the services starts succesfully. Which exclusions do I have to set ? Best regards, Thomas
  • "CryptoGuard detected ransomware in C:\Program Files (x86)\Articulate\360\Storyline\Storyline.exe"

    Hi This High Alert appeared on Storyline.exe. This is a standard commercial app we've been using for years. Could this be a false positive? The information with the alert is for " Generic.Ransom.C" Thanks Robin
  • Performace essue when enable Real Time scanning file

    We have a problem issue when enabling Real Time scanning for files, almost the program consumed 10 times delayed if we enable this feature. Any advice ?????
  • Websites stop loading in all browsers

    We rolled out Sophos Advanced Endpoint with Intercept X recently (replacing Kaspersky) and we've encountered an issue where a few users suddenly lose access to any website (external and internal) in an web browser. All other network activity is fine,…
  • Cryptoguard bloqueando aplicação

    Cryptoguard bloqueando aplicação que o cliente já utilizava. Aplicação de confiança, mesmo marcando como confirmado e como resolvido o mesmo continua impedindo a aplicação.
  • what's about the Firefox SEC_ERROR_REUSED_ISSUER_AND_SERIAL issue with HTTPS decryption

    My feeling is, Sophos does not know about the Intercept-X EAP forums. So I put this to focus here. Maybe one of the Sophos members can bring some light into this issue, it this is on Sophos' screen and will be fixed? https://community.sophos.com/intercept…