Sophos Central License managing and Vulnerability management?

Hello,

Had some questions about Sophos central's capabilities. Can Sophos central manage vulnerabilities and out of date software? How would the licensing model work for shared systems like Terminal servers that have many users logging in? 



Edited TAGs
[edited by: Qoosh at 11:28 PM (GMT -8) on 2 Feb 2023]
Parents
  • Hi Moris,

    Thanks for reaching out to the Sophos Community Forum. 

    Could you elaborate on what you mean by this?

    manage vulnerabilities and out of date software?

    A vulnerability would be like an open hole in software that can be exploited. To get to the point where you have enough access to send commands or use the exploit, you will need access to a device or remote access in most cases. 

    With that being said, if the vulnerability is in another application which allows you to run a script for example, the script may be triggered but will be detected right away since Sophos is watching for any malicious actions taking place. Closing up the open hole in the application will be up to the vendor to sort out, but Sophos will continue to protect the device.

    In terms of having awareness of any vulnerable applications on your environment, you can use Live Discover to find this out. One great example is linked below. If you are looking to inquire about a new vulnerability or one that's only recently been found, it is also possible to construct a custom query of your own to check through the protected devices on your environment and provide a report.
    - Vulnerability Scanner in a query

    The following can be found in our document for Virtual Desktop Licensing, which explains how Terminal Servers are licensed.

    Kushal Lakhan
    Team Lead, Global Community Support
    Connect with Sophos Support, get alerted, and be informed.
    If a post solves your question, please use the "Verify Answer" button.
    The New Home of Sophos Support Videos!  Visit Sophos Techvids
Reply
  • Hi Moris,

    Thanks for reaching out to the Sophos Community Forum. 

    Could you elaborate on what you mean by this?

    manage vulnerabilities and out of date software?

    A vulnerability would be like an open hole in software that can be exploited. To get to the point where you have enough access to send commands or use the exploit, you will need access to a device or remote access in most cases. 

    With that being said, if the vulnerability is in another application which allows you to run a script for example, the script may be triggered but will be detected right away since Sophos is watching for any malicious actions taking place. Closing up the open hole in the application will be up to the vendor to sort out, but Sophos will continue to protect the device.

    In terms of having awareness of any vulnerable applications on your environment, you can use Live Discover to find this out. One great example is linked below. If you are looking to inquire about a new vulnerability or one that's only recently been found, it is also possible to construct a custom query of your own to check through the protected devices on your environment and provide a report.
    - Vulnerability Scanner in a query

    The following can be found in our document for Virtual Desktop Licensing, which explains how Terminal Servers are licensed.

    Kushal Lakhan
    Team Lead, Global Community Support
    Connect with Sophos Support, get alerted, and be informed.
    If a post solves your question, please use the "Verify Answer" button.
    The New Home of Sophos Support Videos!  Visit Sophos Techvids
Children