This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Application Control Logs

Hi all,

 

We are using Sophos Enterprise Console v5.5.0 to centrally manage\configure our Sophos Endpoint Security and Control solution.

I came across a Sophos article (dated Jan. 2019 - link below) which advised, among other things, blocking Powershell by default using Application Control within Enterprise Console.

https://nakedsecurity.sophos.com/2019/01/25/fighting-emotet-lessons-from-the-front-line/

I implemented the recommendation on most of our users and to my mild surprise found that Application Control had blocked Powershell on a few PCs.

I'm trying to discern if this activity was legitimate, but cannot locate a relevant log file (on the client-side or server-side) which may assist in this task.

Could someone please point me in the direction of any log file which may help?

 

Many thanks for your assistance in this matter.

 

John P



This thread was automatically locked due to age.
Parents Reply Children
No Data