This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Disable Automatically clean up malware not working

Hello everyone,

I'm trying to configure Sophos Intercept X to not to Automatically clean up malware or PUAs when detected on some servers and computers. So I go to the current Threat Protection Policy of the computer where I'm testing and disable the Automatically clean up malware option and save changes.

I test this configuration by unzipping PsTools wich includes PsExec and PsExec64 (usually detected and blocked for being a PUA) and instead of only detect them, a few minutes later Sophos deletes the files.

I'm using a Windows 10 Pro (it is no a  WM) but I have also tested this in a Win Server 2016 without success.

Any suggestions? 

Thanks in advanced.

Best regards,



This thread was automatically locked due to age.
Parents Reply
  • Thanks for your response.

    So, once I make the exclusion the file is accesisble again? even if It said it was cleaned up?

    If so, one thing with making the exclusion from the event is that it makes the exception for all devices (global), if I take that file hash and put it in an specific exclusion inside one policy, would it "return" the file too?

    Best regards,

Children