Hi all,
We are using Sophos Enterprise Console v5.5.0 to centrally manage\configure our Sophos Endpoint Security and Control solution.
I came across a Sophos article (dated Jan. 2019 - link below) which advised, among other things, blocking Powershell by default using Application Control within Enterprise Console.
https://nakedsecurity.sophos.com/2019/01/25/fighting-emotet-lessons-from-the-front-line/
I implemented the recommendation on most of our users and to my mild surprise found that Application Control had blocked Powershell on a few PCs.
I'm trying to discern if this activity was legitimate, but cannot locate a relevant log file (on the client-side or server-side) which may assist in this task.
Could someone please point me in the direction of any log file which may help?
Many thanks for your assistance in this matter.
John P
This thread was automatically locked due to age.