Community & Product Forums
Intercept X Endpoint
Sophos (XG) Firewall
Community Blogs & Events
Sophos Community Blog
Community Security Blog
Product Documentation Blog
Sophos Partners Group
Intercept X Endpoint
Release Notes & News
Threat Hunting Academy
Early Access Programs
Live Discover & Response Query Forum
Live Discover allows you to check the devices that Sophos Central is managing, look for signs of a threat, or assess compliance.
New to Live Discover & Response queries? See
Getting Started In Live Discover - From Beginner to Advanced Query Creation
Make sure to also check out
Best Practices On Using Live Discover & Response Query Forum
Sophos EDR Threat Hunting Framework
For more information on Live Discover, please check out our
Navigate to a category below to browse and submit a query
Browse Live Response and Discover Queries by Category
Browse Ideas in Category
By highest score
By recent status change
Ideas you submitted
Ideas you voted on
With any status
With any open status
With any closed status
With held votes
Currently 'Completed (Brand-new content)'
Currently 'Completed (Content Update)'
Currently 'Completed (Minor Issue)'
Currently 'Under Review'
Currently 'Coming Soon'
Currently 'Not Planned'
Load a local CSV file or Remote CSV File as a virtual table
You can supply a file path or URL location where a CSV File is located and it will load it into a virtual table for use with the query. Watch the Video then play with the query. https://vimeo.com/545619419 -- LOAD CSV from GIT LOCATION -- VARIABLE...
22 Jun 2021 3:51 AM
Why this query doesn't work?
What's wrong with this query? Why it doesn't work? I know for a fact that there are files named "VIRUS.exe", and yet live discovery doesn't return any results. SELECT path, directory, filename, device, size FROM file WHERE path LIKE '%VIRUS.exe%' ...
22 Jun 2021 3:14 AM
Live Discovery Query: How to bulk process a CSV List of SHA256 data
REVIEWED by Sophos When hunting for indicators of compromise it is not uncommon to find a list of things you should be checking. In the example below I will show how to use variables to select some csv data that is under 5KB in size and then convert...
22 Jun 2021 3:01 AM
Live Discover tip - how to select time limits in a human readable format - use STRFTIME
REVIEWED by Sophos I've been dumping some tables recently to see what kind of data is in them, and noticed that many of the default queries limit the results to the last 15 minutes of data if a time constraint is not specified (and fair enough, given...
22 Jun 2021 2:45 AM