Quick question... We've recently switched from using another AV vendor to Sophos and I had email rules in place if we received a ransomware alert. The alert email contained a trigger that would immediately send txt messages to certain people to get the machine off the network.
I've finished setting up Sophos and I'm looking to make sure these triggers still work. Can anyone tell me what the alert email looks like if Sophos detects a ransomware virus?
A recent alert example from Sophos looks like:
File "C:\Program Files (x86)\Settings Manager\systemk\del_DM_LL_nsxC8E2.dll" belongs to adware or PUA 'SearchSuite' (of type Adware).
Does a cryptolock type virus state "belongs to ransomware" or (of type ransomware)?
Thanks
R
This thread was automatically locked due to age.