As far as I know the hash of the files that have been detected by Sophos agent on clients are not logged (neither on Console DB or at client side) Am I wrong?
Is there a way to retrieve the MD5, SHA1 or whathever hash for the files detected as malicious from the Sophos agent running on the client?
There is also a feature request about this here:
we tested this on Sophos Enterprise Console 5.2.2: does v. 5.3 includes this basic feature?
I think this feature should have high priority to support the Incident Response phases.
This thread was automatically locked due to age.