This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Live Protection and Suspicious Behaviour

Hello Sophos

Why the Sophos Live Protection don't send automatically the samples for suspicious files and suspicious behaviour because the 90% these files are malware.

I know this because all these files are send to SophosLabs manually and the 90% are catalogue as virus por SophosLabs.

Thanks you

Linck Tello Flores

:5480


This thread was automatically locked due to age.
  • Hello Linck,

    the Overview of the Sophos Live Protection architecture says: In some (emphasis mine) IDEs, SophosLabs include special instructions to trigger a live lookup, so don't expect that all detections cause a lookup and subsequent submission). Of course I don't know the technical details why it's available for some and not for others but I think it will need some specific instructions so amending all the IDEs for suspicious files will take some time.

    Christian

    :5490