Sophos Community
Sophos Community
  • User
  • Site
  • Search
  • User
  • Community & Product Forums
  • Community Blogs
  • Partners
  • Support Portal
  • Get started
  • Blogs
    • Sophos Community Blog
    • Sophos Endpoint
    • Sophos Firewall
    • Zero Trust Network Access
    • Sophos Switch
    • UTM Firewall
    • Sophos Wireless
    • Sophos Central
    • Sophos Cloud Optix
    • Sophos Central API
    • Sophos Factory
    • Sophos Email
  •  
    • Phish Threat
    • Sophos XDR
    • Sophos Mobile
    • On-Premise Endpoint
    • Encryption
    • Sophos Partners
    • Support Portal Feedback
    • Product Documentation Blog
    • SophosLabs
    • Free Tools
    • Sophos Integrations
  • Products
    • Endpoint Security
      • Endpoint protection - next-gen antivirus
      • Endpoint detection and response (XDR)
      • Mobile security
    • Email Security
      • Sophos Email
      • Phish Threat
    • Network Security
      • Sophos Firewall
      • UTM firewall
      • Zero trust network access (ZTNA)
      • Network detection and response (NDR)
      • Sophos Switch
      • Sophos Wireless
    • Cloud Security
      • Sophos Central
      • Sophos Cloud Optix
    • Sophos Home Premium
      • Sophos Home portal
    • Support Tools
      • Sophos integrations
      • Free tools
  • Services
    • Management platform
      • Sophos Central - sign in
      • Support portal - sign in
      • Community - sign in
  • Sophos Partners
    • Partners Corner
    • Partner blogs
    • Websinars and Events
  • Member Recognition
    • Community Leaderboards
    • Sophos Central login
    • Partner care
  • Become a partner
    • Join our program
  • Sophos Community: Getting started
    • How to get started
    • Frequently Asked Questions (FAQs)
    • SophosID Registration
    • How to contribute and participate
    • How to set up your profile
  •  
    • How to manage friends
    • How to manage private messages
    • How to manage digests, subscriptions, and notifications
    • Terms and Conditions of Use
  • Products and Services
    • Products
      • Endpoint Security
        • Endpoint protection - next-gen antivirus
        • Endpoint detection and response (XDR)
        • Mobile security
      • Email Security
        • Sophos Email
        • Phish Threat
      • Network Security
        • Sophos Firewall
        • UTM firewall
        • Zero trust network access (ZTNA)
        • Network detection and response (NDR)
        • Sophos Switch
        • Sophos Wireless
      • Cloud Security
        • Sophos Central
        • Sophos Cloud Optix
      • Sophos Home Premium
        • Sophos Home portal
      • Support Tools
        • Sophos integrations
        • Free tools
    • Services
      • Management platform
        • Sophos Central - sign in
        • Support portal - sign in
        • Community - sign in
  • Community Blogs
    • Blogs List 1
      • Sophos Community Blog
      • Sophos Endpoint
      • Sophos Firewall
      • Zero Trust Network Access
      • Sophos Switch
      • UTM Firewall
      • Sophos Wireless
      • Sophos Central
      • Sophos Cloud Optix
      • Sophos Central API
      • Sophos Factory
      • Sophos Email
    • Blogs List 2
      • Phish Threat
      • Sophos XDR
      • Sophos Mobile
      • On-Premise Endpoint
      • Encryption
      • Sophos Partners
      • Support Portal Feedback
      • Product Documentation Blog
      • SophosLabs
      • Free Tools
      • Sophos Integrations
  • Partners
    • Sophos Partners
      • Partners Corner
      • Partner blogs
      • Websinars and Events
    • Member Recognition
      • Community Leaderboards
      • Sophos Central login
      • Partner care
    • Become a partner
      • Join our program
  • Support Portal
  • Get started
    • Sophos Community: Getting started
      • How to get started
      • Frequently Asked Questions (FAQs)
      • SophosID Registration
      • How to contribute and participate
      • How to set up your profile
      • How to manage friends
      • How to manage private messages
      • How to manage digests, subscriptions, and notifications
      • Terms and Conditions of Use
Sophos Endpoint
Sophos Endpoint
Live Discover Query Forum Live Discover & Response Query Forum
  • Release Notes & News
  • Discussions
  • Recommended Reads
  • Early Access Programs
  • Threat Hunting Academy
  • Live Discover Query Forum
  • More
  • Cancel
  • New
Sophos Endpoint requires membership for participation - click to join
Overview
Live Discover allows you to check the devices that Sophos Central is managing, look for signs of a threat, or assess compliance.

New to Live Discover & Response queries?

See Getting Started In Live Discover - From Beginner to Advanced Query Creation

Make sure to also check out
⁃ Best Practices On Using Live Discover & Response Query Forum and Sophos EDR Threat Hunting Framework.
⁃ Query Corner Announcement and Master Index.

Notes:
If Sophos pre-defined queries aren't working, Sophos Support can help to ensure that data is uploaded from your devices to the Sophos Data Lake. Visit the support portal
For custom query assistance, please see Getting LD&R Community Support or contact Sophos Professional Services.
For more information on Live Discover, please check out our Product Documentation

Sophos Community XDR Queries on GitHub


Navigate to a category below to browse and submit a query

Browse Live Response and Discover Queries by Category
  • Uncategorized

  • Anomalies

  • ATT&CK

  • Cloud Optix

  • Compliance

  • Data Lake

  • Device

  • Email

  • Events

  • Files

  • Live Response

  • Network

  • Other queries

  • Processes

  • Query Tips

  • Registry

  • Threat Hunting

  • User

  • NDR Queries

Latest Live Discover and Response Queries (All)
  • Last reboot time (Uptime)

    MichaelCurtis
    MichaelCurtis
    • Data Lake
    • Approved on 8 Dec 2021
    • 0 Comments
    SELECT meta_hostname, MAX(meta_boot_time) AS EPOC, DATE_FORMAT(FROM_UNIXTIME(MAX(meta_boot_time)), '%Y-%m-%dT%H:%i:%SZ') AS Last_Reboot_Time FROM XDR_DATA GROUP BY meta_hostname ORDER BY Last_Reboot_Time ASC This query will report the last reboot date...
    • 14 Oct 2021 12:26 PM
  • Software install count by version

    MichaelCurtis
    MichaelCurtis
    • Data Lake
    • Approved on 8 Dec 2021
    • 1 Comment
    -- Software list temp table WITH software_temp AS ( SELECT DISTINCT name, MAX(version) AS version, meta_hostname FROM xdr_data WHERE query_name = 'windows_programs' Group BY name, meta_hostname ) select name AS Software_Title, version ,COUNT(version)...
    • 14 Oct 2021 12:23 PM
  • Find out of date software

    MichaelCurtis
    MichaelCurtis
    • Data Lake
    • Approved on 4 Dec 2021
    • 0 Comments
    -- Variables -- $$Software_Name$$ - String - Name of out of date software you are looking for -- $$Software_Version$$ - Latest version number. The query will return the software NOT running this version -- Software list temp table WITH software_temp AS...
    • 14 Oct 2021 12:20 PM
  • List of installed software

    MichaelCurtis
    MichaelCurtis
    • Data Lake
    • Approved on 3 Dec 2021
    • 0 Comments
    SELECT meta_hostname AS Hostname, name AS Software_Title, MAX(version) AS Version FROM xdr_data WHERE query_name = 'windows_programs' GROUP BY name, meta_hostname ORDER BY meta_hostname, name This query will list all the software installed on all...
    • 14 Oct 2021 12:14 PM
  • Check the Flaw in AMD Platform Security Processor, CVE-2021-26333

    RaviSoni
    RaviSoni
    • Device
    • Approved on 25 Feb 2022
    • 0 Comments
    The below query checks for the Flaw in the AMD PSP, CVE-2021-26333 if the system is vulnerable or not and print the appropriate message. -- Check the Flaw in AMD Platform Security Processor, CVE-2021-26333 SELECT CASE WHEN (SELECT 1 FROM cpu_info...
    • 2 Oct 2021 8:27 PM
  • Show the % free disk space - DATA LAKE

    Victor Domingo
    Victor Domingo
    • Queries
    • Under Review on 17 Sep 2021
    • 1 Comment
    Please i need the query for Show the % free disk space on DATA LAKE. Its possible???? Thanks
    • 17 Sep 2021 12:24 PM
  • OMIGOD Vulnerability | OMI version check

    Jainidhya Rajpal
    Jainidhya Rajpal
    • Device
    • Approved on 17 Sep 2021
    • 0 Comments
    SELECT CASE WHEN version = '1.6.8.1' THEN 'OMI is Updated' ELSE 'Update OMI to 1.6.8.1' END AS OMIGODVersionCheck, name, version, release, source, sha1, arch FROM rpm_packages WHERE name = 'omi' UNION ALL SELECT CASE ...
    • 17 Sep 2021 12:00 PM
  • Retrieve Folder Size

    Connor Rosenthal
    Connor Rosenthal
    • Files
    • Approved on 18 May 2022
    • 1 Comment
    I know you can get data back from files but is there a way to modify the OSQuery to get folder or directory information. Wanter to get Desktop and Document size. and convert if possible to MB.
    • 16 Sep 2021 9:54 PM
  • FORCEDENTRY Big Sur 11.6 Version Check

    Jainidhya Rajpal
    Jainidhya Rajpal
    • Threat Hunting
    • Under Review on 14 Sep 2021
    • 0 Comments
    SELECT CASE WHEN version = '11.6' THEN 'Not Vulnerable to FORCEDENTRY' ELSE 'Vulnerable | Upgrade to 11.6' END AS BigSurCheck FROM os_version WHERE major = '11'
    • 14 Sep 2021 8:11 PM
  • FORCEDENTRY Safari Check (CATALINA & MOJAVE)

    Jainidhya Rajpal
    Jainidhya Rajpal
    • Threat Hunting
    • Under Review on 14 Sep 2021
    • 0 Comments
    SELECT CASE WHEN bundle_short_version = '14.1.2' THEN 'PATCHED' ELSE 'Vulnerable to FORCEDENTRY' END AS VulnCheck FROM apps WHERE name = 'Safari.app'
    • 14 Sep 2021 7:31 PM
<>
Unfiltered HTML
  • Getting started
  • Legal
  • Privacy
  • Cookies

© 1997 - 2024 Sophos Ltd. All rights reserved.