This article provides information on the Download Reputation feature. Download Reputation is a feature of the Windows Endpoint product that checks files downloaded from some internet browsers against a database of files held in SophosLabs. The database uses feedback from Sophos’ latest Windows Endpoint products to generate reputation scores for files seen on customer endpoints. The reputation scores are currently based on the prevalence, age and URL source of files.
Using this score, files are grouped into a number of reputation categories ranging from ‘Unknown’, where SophosLabs have not previously seen any feedback about the file, to ‘High’ where feedback on the file has been frequent over an extended period of time and/or the file has some known and trusted provenance. A team of researchers in SophosLabs is assigned to monitoring and ensuring the continual efficacy of the scoring algorithm and the data that affects it.
Applies to the following Sophos products and versions Sophos Cloud Managed Server 1.3.0Sophos Endpoint Security and Control 10.6.3Sophos Cloud Managed EndpointEnterprise Console 5.4.0
Files can be assessed as low, medium or unknown reputation. The behavior of the product will depend on the settings selected from within the configuration options, over time SophosLabs may adjust the reputation data based on customer feedback and experience.
The default settings for Download reputation are:
With these settings, if an unknown or low reputation file is selected for download the user will be prompted to 'block' or 'trust and allow' the download. The pop-up message will contain the URL and file name in question, it is up to the user to decide if they trust the file and want to proceed.
If the strict option is selected medium reputation files will also be prompted. If the log only option is selected the details of downloaded files will be added to the local log but no user prompt will be shown.
The following browsers are supported by download reputation:
Sign up to the Sophos Support SMS Notification Service to get the latest product release information and critical issues.
Every comment submitted here is read (by a human) but we do not reply to specific technical questions. For technical support post a question to the community. Or click here for new feature/product improvements. Alternatively for paid/licensed products open a support ticket.