<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>I&amp;#39;m looking for about information the next path C:\ProgramData\Sophos\Endpoint Defense\Data</title><link>https://community.sophos.com/on-premise-endpoint/f/sophos-endpoint-software/128125/i-m-looking-for-about-information-the-next-path-c-programdata-sophos-endpoint-defense-data</link><description>Hi Friends How are you? 
 I need your help. I need information about ,the path C:\ProgramData\Sophos\Endpoint Defense\Data, because my customer needs to know what is this directory? and what is the function?</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: I'm looking for about information the next path C:\ProgramData\Sophos\Endpoint Defense\Data</title><link>https://community.sophos.com/thread/469822?ContentTypeID=1</link><pubDate>Tue, 01 Jun 2021 21:27:46 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:a1d7eeb9-67ae-472d-a7fa-3e916eb2333a</guid><dc:creator>Sophos User930</dc:creator><description>&lt;p&gt;It stores a lot of data, I assume the size is the reason for the interest?&amp;nbsp;&amp;nbsp;&lt;span class="emoticon" data-url="https://community.sophos.com/cfs-file/__key/system/emoji/1f642.svg" title="Slight smile"&gt;&amp;#x1f642;&lt;/span&gt; The main ones are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;\logs\ - the logs of the service, driver, processes&lt;/li&gt;
&lt;li&gt;\Event journals\ - When you have EDR/RCA/FIM (servers) enabled, SophosED.sys is recording all the operations taking place.&amp;nbsp; This is the data for that. *.bin are the current file, the xz are compressed files.&amp;nbsp; These are compressed every 5 mins by SEDService.exe.&lt;/li&gt;
&lt;li&gt;\Edr Saved Data\ - The 5 min processing of the journals by sspedr.exe for data of interest being sent is stored here.&amp;nbsp; &amp;quot;backup&amp;quot; folder for example has the last 10 uploads of the JSON data once extracted.&lt;/li&gt;
&lt;li&gt;\Forensic Snapshots\ - Any initiated forensic snapshots from Central are stored here.&lt;/li&gt;
&lt;li&gt;\data content records\&amp;nbsp; - Cache of data about files, persisted over reboots and loaded by SophosED.sys&lt;/li&gt;
&lt;li&gt;\appfeed\ data to detect applications for autoexclusions, etc.&lt;/li&gt;
&lt;li&gt;\decisionrulesv2\ - behavioural data files&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;They are the main ones, the others seem to be IPC data.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>