This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Endpoint Intercept X 2.0 impacting Performance - slow?

On a new software build of windows 10 on a T450 Lenovo, we found that at the end we installed Sophos Endpoint Intercept X 2.0 and it significantly slowed down the computer.  All aspects of the computer became slow.  On first bootup, connecting the Wifi - slow.  On login, the CPU would pin at 100% for long periods of time with high memory usage.  All applications would be slow to open, printing would be very slow. This is a new laptop i5, 8 GB RAM, 256 SSD.

We would remove the Intercept X and the computer would return to normal operation.  Fast bootup, fast login, apps, etc...

Now for this customer, then use Trend Micro as their primary AV.  We have Sophos Intercept X added on for the extra protection. We did not have issues previously until the Intercept X Version went up to 2.0.  Has anyone else noticed a large performance hit with Intercept X 2.0?




[locked by: SupportFlo at 11:42 PM (GMT -7) on 12 Mar 2019]
Parents
  • This issue seems affecting Surface devices more than others, we had to disable intercept X for several of them (Endpoint protection > Computers > Manage endpoint software) and move affected devices from Assigned to Eligible column to get back decent performances. 

  • Using Core Agent 2.0.2, Endpoint Advanced 10.8.1.1 and Intercept X 2.0.2 on 25 computers and seeing no real issues. Maybe performance is a little bit slower but nobody including me noticed a real downgrade. Deep Learning is currently not activated.

    Regards, Jelle

    Sophos XG210-HA (SFOS 18.0.4) on SG210 appliances with Sandstorm and 1x AP55
    Sophos Central with Intercept X Advanced, Device Encryption, Phish Threat, Mobile Control Advanced

    If a post solves your question use the 'This helped me' link.

  • Update, March 23 - Sophos has escalated my ticket to global escalation specialists (GES). They said I will hear from them in 1-2 weeks. Have any one has any update from your ticket?

  • We have also been working very closely with GES in the UK.  We have narrowed it down to the Hitman Pro Service. Disabling that component will return the machine back to normal.  Instructions below;

    FYI, disabling HitmanPro service will disable a subset of features to stop working:

    Ransomware
    Exploit mitigations

    You will still have:

    PE file detections
    Deep Learning scanning (if enabled in policy)

     

    We have provided all logs as instructed and waiting to hear back also.

     

    1) Access the Services and stop then disable the following service:


    HitmanPro.Alert service

    2) Access the following folder:

    C:\Windows\System32\

    3) Rename hmpalert.dll to hmpalert.orig

    4) Access the following folder:

    C:\Windows\SysWOW64\

    5) Rename hmpalert.dll to hmpalert.orig

    6) Access the following folder:

    C:\Windows\System32\drivers\

    7) Rename hmpalert.sys to hmpalert.orig

    8) Reboot the computer.

Reply
  • We have also been working very closely with GES in the UK.  We have narrowed it down to the Hitman Pro Service. Disabling that component will return the machine back to normal.  Instructions below;

    FYI, disabling HitmanPro service will disable a subset of features to stop working:

    Ransomware
    Exploit mitigations

    You will still have:

    PE file detections
    Deep Learning scanning (if enabled in policy)

     

    We have provided all logs as instructed and waiting to hear back also.

     

    1) Access the Services and stop then disable the following service:


    HitmanPro.Alert service

    2) Access the following folder:

    C:\Windows\System32\

    3) Rename hmpalert.dll to hmpalert.orig

    4) Access the following folder:

    C:\Windows\SysWOW64\

    5) Rename hmpalert.dll to hmpalert.orig

    6) Access the following folder:

    C:\Windows\System32\drivers\

    7) Rename hmpalert.sys to hmpalert.orig

    8) Reboot the computer.

Children
No Data