Browse Ideas in Category
  • Check Live Discover to see if a specific KB of Microsoft Office is installed

    • Under Review
    • Live Discover
    • 3 Comments
    Hello Sophos Team, I wanted to know if there is any query capable of validating the installation of a specific KB of Microsoft Office on Windows computers, whether it is a monthly update or security update. The purpose of this query is to verify...
    • 16 Jun 2021 4:29 PM
  • New "Logs & Reports" page ?!?

    • Under Review
    • Live Discover
    • 2 Comments
    Hi folks, apparently the "Logs & Reports" in our sophos central dashboard has been updated. Unfortunately at the top we lost our scheduled reports which we could customize with the little pin icon. Surprised that Sophos went live with such update...
    • 16 Jun 2021 8:04 AM
  • Live Discover Query to see the versions of any software installed on macOS

    • Under Review
    • Live Discover
    • 5 Comments
    Hello Sophos Team, I wanted a live discovery query that would retrieve the version of any software installed on macOS machines in my environment, as well as the hostname / IP of the machines. The purpose of this query is to verify and patch all programs...
    • 15 Jun 2021 10:25 PM
  • Data Lake: Threat Indicators

    • Under Review
    • Live Discover
    • 0 Comments
    Similar to the Threat Indicators report in Central today, this query evaluates the machine learning and reputation scores to provide a list of the most suspect executables observed in the environment with the added benefit that customers can fine tune...
    • 10 Jun 2021 10:11 AM
  • Data Lake: Show network activity for defined Sophos Process ID

    • Under Review
    • Live Discover
    • 0 Comments
    This query will detail network activity for a defined Sophos Process ID -- Data Lake show network activity for defined Sophos Process ID -- VARIABLE $$sophos_pid$$, SophosPID WITH split_pids AS ( SELECT x2.new_pid, x1.* FROM xdr_data...
    • 10 Jun 2021 12:24 PM
Browse All Ideas
  • Show computer where exist specific file

    • Files
    • Under Review
    • Not categorized
    • 1 Comment
    hi all, I wanted to ask you if it is possible to make a query to show all computers where there is (or where there is not) a specific file. Thank you
    • 17 Jun 2021 2:42 PM
  • Check Live Discover to see if a specific KB of Microsoft Office is installed

    • (All) Live Discover & Response Query Forum
    • Under Review
    • Live Discover
    • 3 Comments
    Hello Sophos Team, I wanted to know if there is any query capable of validating the installation of a specific KB of Microsoft Office on Windows computers, whether it is a monthly update or security update. The purpose of this query is to verify...
    • 16 Jun 2021 4:29 PM
  • New "Logs & Reports" page ?!?

    • (All) Live Discover & Response Query Forum
    • Under Review
    • Live Discover
    • 2 Comments
    Hi folks, apparently the "Logs & Reports" in our sophos central dashboard has been updated. Unfortunately at the top we lost our scheduled reports which we could customize with the little pin icon. Surprised that Sophos went live with such update...
    • 16 Jun 2021 8:04 AM
  • Live Discover Query to see the versions of any software installed on macOS

    • (All) Live Discover & Response Query Forum
    • Under Review
    • Live Discover
    • 5 Comments
    Hello Sophos Team, I wanted a live discovery query that would retrieve the version of any software installed on macOS machines in my environment, as well as the hostname / IP of the machines. The purpose of this query is to verify and patch all programs...
    • 15 Jun 2021 10:25 PM
  • Data Lake: Threat Indicators

    • (All) Live Discover & Response Query Forum
    • Under Review
    • Live Discover
    • 0 Comments
    Similar to the Threat Indicators report in Central today, this query evaluates the machine learning and reputation scores to provide a list of the most suspect executables observed in the environment with the added benefit that customers can fine tune...
    • 10 Jun 2021 10:11 AM