Hi,
We have SCE 5.5.1. We are interested in having the file hash when Sophos detects that it is a threat. We want to be able to use this hash to integrate it with our SIEM and be able to analyze it with Virustotal automatically.
Other antivirus stores this value without problems.
I have seen that in the database there is a field for the hash value but it is only filled in when the threat is from a file already registered in SCE, therefore 99% of rows in the database with files detected as threats do not have value.
Add this value to the database, it costs nothing and I do not understand how it is implementing how the rest of the antivirus in the market. Every day I am more disenchanted with the product and we value change.
We have called for support and they indicate that they have no idea and can not help me and that they can do this consultation in the community. If they do not know it or they do not want to ask the question to another level or department of Sophos ... it leaves much to be desired.
Thanks
Regards
This thread was automatically locked due to age.