Overview
Live Discover allows you to check the devices that Sophos Central is managing, look for signs of a threat, or assess compliance.

New to Live Discover & Response queries? See Getting Started In Live Discover - From Beginner to Advanced Query Creation
Make sure to also check out Best Practices On Using Live Discover & Response Query Forum and Sophos EDR Threat Hunting Framework.

Note: For more information on Live Discover, please check out our Product Documentation.

Navigate to a category below to browse and submit a query

Browse Ideas in Category
  • Live Response - Suspicious Process - Create a dump for offline analysis

    • Approved on
    • 1 Comment
    REVIEWED by Sophos Imagine the scenario - you see what looks to be a suspicious process on an endpoint, maybe you've used Live Query to list modules but you need to dig a little deeper. Well, how about the following workflow: Initiate a Live Response...
  • Live Response: Temperature of a machine

    • Under Review on
    • 2 Comments
    REVIEWED by Sophos In Celsius -------------------------------------- function Get-Temperature { $t = Get-WmiObject MSAcpi_ThermalZoneTemperature -Namespace "root/wmi" $returntemp = @() foreach ($temp in $t.CurrentTemperature) { $currentTempKelvin...
  • Live Response - Investigating other devices

    • Under Review on
    • 0 Comments
    Given the scenario where you have a number of computers at a site and in the same subnet, it may be possible to perform some remote diagnostics. Some example PowerShell commands are included below that could be used as-is or modified as needed. Finding...
  • Using Live Response to investigate Sophos Services & their CPU utilization

    • Approved on
    • 0 Comments
    Initial Steps: The given Powershell script will run from Live Response as well as from powershell prompt. There's no obligation to have elevated privilege to run this script. After opening command prompt enter "powershell" Copy paste the complete...
  • Live Response: Controlling Windows Firewall Using Netsh

    • Under Review on
    • 0 Comments
    Imagine a scenario where you discover vulnerable ports or need to temporarily block an application, port, or other. Many environments will leverage GPOs to set their profiles and exceptions. On the fly, we can make changes in real-time to protect the...
  • Live Response - Force an update from the command line and checking status

    • Under Review on
    • 2 Comments
    Given that Live Response is now live! This might be a useful command to initiate an "update now" from the command line: powershell -command $(New-Object -comObject "ActiveLinkClient.ClientUpdate.1").UpdateNow(1,1) You can monitor the progress by watching...
  • Live Response: Return WindowsOS assets set NIC Gateway IP

    • Under Review on
    • 1 Comment
    G'Day Community, Does anyone know how I could run a live response query that can return the machine's Gateway IP on its configured NICs? I've run all the related network queries: Network Interface details, Network Interfaces, and Network Interface...
  • Live Response read text files; change configuration files etc.

    • Under Review on
    • 2 Comments
    Hello 99% of my time I use the GUI; so when it comes to use the CMD prompt I feel a little uncomfortable I am trying to use live response; in the kb and other documentation it is stated that with Live Response on windows you can: Reboot a device that...
  • Live Response - Using command line tools to check files

    • Under Review on
    • 0 Comments
    There are a number of tools installed on the endpoint for evaluating files. For example: SAV32CLI.exe Sav32cli which is part of the Sophos Anti-Virus component. If you wished to scan a folder or file, from the command line you could run: sav32cli...
  • Live Response - Don't forget Tamper Protection

    • Under Review on
    • 1 Comment
    When performing a Live Response session, with a view to troubleshoot Sophos components, it may be worthwhile confirming if Tamper Protection (Endpoint Defense) is disabled. To do so you can run: "C:\Program Files\Sophos\Endpoint Defense\SEDcli.exe"...
  • Live Response - Performance Check

    • Under Review on
    • 1 Comment
    One of the most common problems users report is performance. These might be, the vague: "It just seems generally slow", or "when I do X it takes forever". Well from the command line and through the magic that is Live Response, you can now answer these...
  • Live Response - Capturing network traffic

    • Under Review on
    • 1 Comment
    REVIEWED by Sophos Given the ability to utilize Live Query, specifically the tables 'sophos_http_journal', 'sophos_ip_journal', 'sophos_url_journal', etc. I can see how it might be interesting to conduct a packet trace via Live Response. When people...
  • Live Response - Command audit

    • Under Review on
    • 0 Comments
    At the current time you can specify a reason for the connection but once connected it maybe helpful to document a list of commands run. From the default command prompt to print a list of previous commands for the session you can run: doskey /history...
  • Live Response - Making use of Sysinternals tools

    • Under Review on
    • 0 Comments
    Given how useful the Sysinternals suite of tools is, it's probably worth a quick post to show how these can be obtained and used via Live Response to save disrupting an end user. Thankfully Sysinternals exposes the tools at the following location: ...
  • Live Response - Viewing the raw JSON Sophos Health trail files

    • Under Review on
    • 0 Comments
    I can imagine a case where it might be helpful to process the raw trail files of Sophos Health found under: %ProgramData%\Sophos\Health\Event Store\Trail\ Note : It is possible to also get this information from Live Discover using the "sophos_events_summary...