Hi All,
I been asked does Sophos protect against Locky, or what can we do to prevent
Thanks
J
This thread was automatically locked due to age.
Hello Joetobai,
now, Locky (or whatever prevalent "bleeding edge" threat) is not a static executable (i.e. one program with a few specific checksums), it takes some time (and samples) to reliably detect all the mutations. This is complicated by the fact that aggressive strategies are not feasible in a corporate environment as the could be too aggressive and might impair important applications. Thus "complete protection" would be, at least in the early days, boastful.
In addition there's the delivery mechanism - the initial stage seems pretty archaic, email and macros in office documents. Then evidently a (state-of-the-art) staggered download. So while the concept isn't new the campaign doesn't reuse well-known components which is another challenge.
what can we do
Please see Ransomware Protection on Terminal Servers for some advice by Sophos.
Christian
In the video below we show you what happens when Locky Ransomware attacks a computer. You will see what a typical user would see if they were the victim of such an attack. We will then show you several scenarios demonstrating how Sophos protects the computers and networks of our customers using multiple techniques.
All products featured in this video are using their default settings and no new protection was created to block the malware shown.
Products featured: Sophos Endpoint managed by Sophos Central Console, with Sophos Intercept X.
Sophos XG Firewall including Heartbeat and Sophos Sandstorm.
- - - - - - - - - - - -
Communities Moderator, SOPHOS
Knowledge Base | @SophosSupport | Video tutorials
Remember to like a post. If a post (on a question thread) solves your question use the 'This helped me' link.