hello,
I got this intrusion attempt for the first time. just don't know what to do.
I looked for any recent downloads and browsing history, and asked the user if he plugged any device to the computer but nothing suspicious found.
this is a screenshot about the intrusion,
regards,
Hello,
You may refer here for details on the signature category that trigger the detection: https://docs.sophos.com/nsg/sophos-firewall/20.0/help/en-us/webhelp/onlinehelp/AdministratorHelp/IntrusionPrevention/IPSPolicies/IPSCategoryDescriptions/index.html which is file-image
You may check any events on the end machine AV solution for any potential detection and may also perform a full AV scan on the victim machine.
Regards,
Raphael Alganes
Community Support Engineer | Sophos Technical Support
Sophos Support Videos | Product Documentation | @SophosSupport | Sign up for SMS Alerts
If a post solves your question use the 'Verify Answer' link.