Browse By Tags

  • I would like to know about SoPhos process information.

    Hi I would like to know about SoPhos process information. Please tell us in detail what function the two processes below perform. 1. SoPhosFilesScanner.exe 2. SSPService.exe
  • Sophos Endpoint ODS threshold time

    Anyone aware of a Sophos central managed Endpoint setting where we can restrict an On Demand scan to a particular time. let's say after 24 hours, it should stop.
  • Difference between Sophosfilescanner.exe and SophosFS.exe process

    I wanted to understand the Difference between Sophosfilescanner.exe and SophosFS.exe process, are they same in functionality ? Is SophosFileScanner.exe have the role of SAVservice.exe which has been removed recently after Core agent update 2.20.11 …
  • Safe Browsing detected browser Firefox has been compromised

    Hi Sophos From this alert, please advice step and how to solve this case. RAW LOG Intruder Platform 6.1.7601/x86 v37 06_3c PID 111064 Enabled 005D2E3C1DBF9104 Silent 0000000000000100 Application C:\Program Files\Mozilla Firefox\firefox.exe Created…
  • What details are specific to a Detection ID?

    We recently had a false positive from CryptoGuard and were unsure whether to exclude it via Detection ID or filename+filepath. What details actually make up a Detection ID? We installed two versions of the software and although the exe file that caused…
  • Constant Block Notifications for Microsoft YourPhone

    How do I stop Sophos Endpoint from notifying users that Microsoft YourPhone is blocked 100 times a day? We want it blocked but our users don't need to know that it's blocked over and over throughout the day. I don't want to set "Focus Assist" to "Priorty…
  • Sophos Intercept X

    Could anyone let me know the main features which is available in Sophos intercept X, ( this is for presentation purpose, it would be great if anyone explains me briefly if you know) thanks in advance Have a great day ahead
  • machine learning for malware detection

    Hello experts, I have a question about machine learning for malware detection. How does "machine learning" work at Sophos? How can you imagine that? I see many analyzes in the reports from Sophos labs intelix that draw on an enormous database. How is…
  • Which exclusions for Siemens OPC Server

    Hi, the services of the Siemens OPC Server do not start in the appropriate time. After I change the OPC services to automatic delayed the services starts succesfully. Which exclusions do I have to set ? Best regards, Thomas
  • "CryptoGuard detected ransomware in C:\Program Files (x86)\Articulate\360\Storyline\Storyline.exe"

    Hi This High Alert appeared on Storyline.exe. This is a standard commercial app we've been using for years. Could this be a false positive? The information with the alert is for " Generic.Ransom.C" Thanks Robin
  • Performace essue when enable Real Time scanning file

    We have a problem issue when enabling Real Time scanning for files, almost the program consumed 10 times delayed if we enable this feature. Any advice ?????
  • Websites stop loading in all browsers

    We rolled out Sophos Advanced Endpoint with Intercept X recently (replacing Kaspersky) and we've encountered an issue where a few users suddenly lose access to any website (external and internal) in an web browser. All other network activity is fine,…
  • Sophos Central Endpoint is blocking Sharepoint folder downloads..

    We have a few users that download map template folders for their ESRI programs from a sharepoint site that they share. Recently, the download has stopped working when they select the two folders they need to download. They can go down into the folders…
  • Cryptoguard bloqueando aplicação

    Cryptoguard bloqueando aplicação que o cliente já utilizava. Aplicação de confiança, mesmo marcando como confirmado e como resolvido o mesmo continua impedindo a aplicação.
  • what's about the Firefox SEC_ERROR_REUSED_ISSUER_AND_SERIAL issue with HTTPS decryption

    My feeling is, Sophos does not know about the Intercept-X EAP forums. So I put this to focus here. Maybe one of the Sophos members can bring some light into this issue, it this is on Sophos' screen and will be fixed? https://community.sophos.com/intercept…
  • ¿How i get create exception for Java Archive (jar)?

    ¿How i get create exception for Java Archive (jar)? i need into in a web site and that site use Java to charge and Sohpos are blocking the site this user today have had eleven blocking for Java Archive (jar)
  • Online game now disconnecting

    Our company computers have the Sophos enterprise version and this is all managed through IT support web portal. Every time an online game is launched on CNC.net it now disconnects after 3 seconds. Worked perfectly for a long time. I have discussed with…
  • Intercept X - do process exceptions also exclude exploit mitigations?

    Hi Community, if I add an exe file to the process exceptions, will it still get checked for exploits? Thank you!
  • Bandwith Issues Chrome/Firefox/Edge

    We have been using Sophos intercept x advanced with MTR for about 6 weeks. Since then, our bandwidth has dropped 90%. We use a gigabit internet connection and have previously achieved the following values ​​in a speed test in the browser: Down: 900MB…
  • Sophos Intercept X Client CLI?

    Well hello there, is there any way to trigger a FileScan from commandline with Intercept X? I know with the old endpoint protection you could use the sav32cli.exe, but i can't find this in the new intercep X agent. Hope some one can help. Greeting …
  • Sysinternals and Nirsoft detected as PUA

    How can i exclude these apps from being detected as PUA? Do i have to exclude every single app one by one?
  • Application with "conf.json" blocked without events

    Hi, I have a Application with unc path "\\server-01\test$\xyz.exe". The shortcut of the application is in the same folder with "conf.json" in it. Sophos Central blocked this program without any events! Can anybody help ? best regards, Tho…
  • A lot of WMV files deleted since last weeks for unknow reason

    Hello, since last week, for unknown reason our Sophos Endpoint delete all WMV files on computers. This is the event : Malware detected: 'W32/GetCodec-A' at 'XXX\Intro discours.wmv' Any idea why it's happen now?? I already created a ticket to…
  • Malicious Behaviour (PrivGuard) detected

    Hello, i use gsudo.exe with Windows Terminal to start CMD or Powershell with administrative rights but since i use Sophos Endpoint it shuts down the Terminal app every time the gsudo process opens a new tab. The Error message is "Malicious Behaviour…
  • CXmal/WebAgnt-A continuously intercepted by Sophos on Exchange Server - Have I been hacked?

    Hi, I have an Exchange server 2019 wich have not been correctly patched since one month ago; it had Sophos Advanced Endopoint installed allready + Sophos Firewall Intercept X in front (protected by WAF - no DNAT) I started questioning my self as soon…