• Tags
  • Subscribe by email
  • More
  • Cancel
  • YARA Scanning rules with Sophos XDR

    Release Notes & News: YARA Scanning rules with Sophos XDR

    Karl_Ackerman
    Karl_Ackerman
    For query assistance, please see the following Best Practices guide With XDR we have access to the OSQuery supported tables and the ability to write our own SQL queries that can include variables.  One of the tables available is a YAR...
    • 14 Aug 2021
  • Thank you for participating in the Apple M1 (ARM) EAP!

    Announcements: Thank you for participating in the Apple M1 (ARM) EAP!

    Yashraj S
    Yashraj S
    Hi Community, On behalf of the team, we would like to thank everyone who participated in our Apple M1 (ARM) Early Access Program, especially those who took the time to share their feedback. With Apple M1 (ARM) now officially supported,...
    • 14 Aug 2021
  • Intercept X Advanced with XDR August updates

    Release Notes & News: Intercept X Advanced with XDR August updates

    Kevin Kingston
    Kevin Kingston
    Over the past few weeks and coming weeks we have/will release some new Intercept X Advanced with XDR features that I wanted to make everyone aware of. Live Discover Customer Defined Enrichments: Customers can now define their own Live Discover data e...
    • 11 Aug 2021
  • Sophos Protection for Linux - AV Plugin

    Release Notes & News: Sophos Protection for Linux - AV Plugin

    StephenMcKay
    StephenMcKay
    Hi all, On July 22nd we launch our Server Protection anti-virus plugin for all customers, so you can now run on-demand scans of your Linux servers. This update will provide the following features and functionality: Next generation threat detect...
    • 22 Jul 2021
  • Making it easier to use Live Discover

    Release Notes & News: Making it easier to use Live Discover

    Kevin Kingston
    Kevin Kingston
    For the typical Central administrator using Live Discover, often times you are just looking to run a pre-canned query to get results as quick and easy as possible so we've made some changes in Central to help simplify using Live Discover for those ad...
    • 22 Jul 2021
  • Sophos EDR and XDR are now a single offering

    Release Notes & News: Sophos EDR and XDR are now a single offering

    Kevin Kingston
    Kevin Kingston
    In May, we achieved a few significant strategic milestones in our product roadmap.  This included advancements in our EDR offering, the introduction of the Sophos Data Lake, and the launch of Extended Detection and Response (XDR) with integrati...
    • 11 Jul 2021
  • Winding down of the XDR & EDR Data Lake Early Access Program (Update June 30, 2021)

    Announcements: Winding down of the XDR & EDR Data Lake Early Access Program (Update June 30, 2021)

    Kevin Kingston
    Kevin Kingston
    As previously communicated, from the beginning of June, no new customers are able to enroll into the XDR & EDR Data Lake Endpoint and Server early access programs (EAPs).  For customers who were already enrolled, they are no longer able to a...
    • 30 Jun 2021
  • Intercept X Advanced with EDR updates

    Release Notes & News: Intercept X Advanced with EDR updates

    Kevin Kingston
    Kevin Kingston
    Click to view the Japanese version: Intercept X Advanced with EDR のアップデート With the launch of EDR 4.0 in May, Sophos has introduced significant enhancements to the Endpoint Detection and Response (EDR) offering.  A key new EDR component is the S...
    • 29 Jun 2021
  • Survey on Indicators of Compromise and Orientation information

    Release Notes & News: Survey on Indicators of Compromise and Orientation information

    Marcin Hutnik
    Marcin Hutnik
    Hi guys, We are running a new UX Research Project to understand better what types of Orientation Information is most important to our users regarding Indicators of Compromise (IOCs). If you are interested and would like to help with this project, we ...
    • 16 Jun 2021
  • Winding down of the XDR & EDR Data Lake Early Access Program (Update June 16, 2021)

    Announcements: Winding down of the XDR & EDR Data Lake Early Access Program (Update June 16, 2021)

    Kevin Kingston
    Kevin Kingston
    As previously communicated, from the beginning of June, no new customers are able to enroll into the XDR & EDR Data Lake Endpoint and Server early access programs (EAPs).  For customers who were already enrolled, they are no longer able to a...
    • 15 Jun 2021
  • Important Changes to the Endpoint/Server Protection and EDR Features Early Access Program

    Announcements: Important Changes to the Endpoint/Server Protection and EDR Features Early Access Program

    StephenMcKay
    StephenMcKay
    Hi all, We have some exciting changes coming to the Endpoint/Server Protection and EDR Features Early Access Program over the next few weeks. One of the biggest changes is the decrypt and re-encrypt of HTTPS traffic between the browser and the w...
    • 11 Jun 2021
  • Winding down of the XDR & EDR Data Lake Early Access Program

    Announcements: Winding down of the XDR & EDR Data Lake Early Access Program

    Kevin Kingston
    Kevin Kingston
    Hello All, With EDRv4 and our new XDR offering having become generally available in mid-May, Sophos will now begin the wind down of the XDR & EDR Data Lake Early Access Programs.  At this point we will not be introducing any new functionalit...
    • 4 Jun 2021
  • Sophos XDR and EDR 4.0 Now Available

    Release Notes & News: Sophos XDR and EDR 4.0 Now Available

    Kevin Kingston
    Kevin Kingston
    We are pleased to announce that today, May 19, we have released some exciting updates for all customers using Sophos EDR (Endpoint Detection and Response) with Intercept X Advanced with EDR and Intercept X Advanced for Server with EDR. What’s n...
    • 19 May 2021
  • Expansion of Sophos Cloud Workload Protection

    Release Notes & News: Expansion of Sophos Cloud Workload Protection

    StephenMcKay
    StephenMcKay
    Following on from my announcement back in December about changes to AWS and Azure Connectors in Intercept X for Server; i'm pleased to inform you about Cloud Optix Standard. Sophos Intercept X Advanced for Server customers now benefit from C...
    • 7 May 2021
  • Welcome to the Endpoint Protection Apple M1 (ARM) EAP

    Announcements: Welcome to the Endpoint Protection Apple M1 (ARM) EAP

    FormerMember
    FormerMember
    Sophos appreciates your assistance. Please make sure to read all the items in this post. Also, please report any issues on the Discussions forum - we need your feedback to help improve the product. Overview This Early Access Program allows...
    • 29 Apr 2021
  • Thank you for participating in the Big Sur EAP!

    Announcements: Thank you for participating in the Big Sur EAP!

    FloSupport
    FloSupport
    Hi Community, On behalf of the team, we would like to thank everyone who participated in our Big Sur Early Access Program and especially those who took the time to share their feedback. The team would also like to extend a special thank you...
    • 22 Apr 2021
  • Scheduled Query for automatic report generation (PREVIEW)

    Announcements: Scheduled Query for automatic report generation (PREVIEW)

    Karl_Ackerman
    Karl_Ackerman
    With the release of the product we will be adding scheduled query reports.    This feature is NOT YET available in the EAP but is coming with the general release in mid May.  For those eager to see it before it is complete I have recor...
    • 21 Apr 2021
  • EMAIL information now in the data lake

    Announcements: EMAIL information now in the data lake

    Karl_Ackerman
    Karl_Ackerman
    BRIEF Video on EMAIL and the Data Lake. In this video we show the EMAIL Attachment and URL table that is available in the data lake, we also pivot from a URL seen an an email to ask if any endpoint have ever communicated to that URL and if so what pr...
    • 21 Apr 2021
  • Intercept X EDR XDR Overview

    Announcements: Intercept X EDR XDR Overview

    Karl_Ackerman
    Karl_Ackerman
    A 30 min tour of some of the capabilities of Sophos Intercept X with EDR XDR.  In this 30 min video I touch on some of the core concepts in the product and explain a bit about how queries work and show some of the features. It by no means covers...
    • 20 Apr 2021
  • Generate Threat Case from Live Discovery file path

    Announcements: Generate Threat Case from Live Discovery file path

    Karl_Ackerman
    Karl_Ackerman
    Often administrators would prefer to see the graphical view of the attack instead of the tables.   With a graphical view it is often MUCH easier to understand what was happening and come to a decision is something is malicious or not. To he...
    • 19 Apr 2021
  • Update XDR (EMAIL data, Scheduled Reports, Enrichment Pivots)

    Announcements: Update XDR (EMAIL data, Scheduled Reports, Enrichment Pivots)

    Karl_Ackerman
    Karl_Ackerman
    Lots of new features are going to be enabled on Wed April 21.  We are still on track for GA in mid May. Video:
    • 19 Apr 2021
  • Pivots and the Depth of information available

    Announcements: Pivots and the Depth of information available

    Karl_Ackerman
    Karl_Ackerman
    We continue to make excellent progress to the intended May release of the Data Lake version of the product. This week I wanted to demonstrate some of the capabilities we have just added around Pivots and the Depth of information available for admins ...
    • 8 Apr 2021
  • Frequently asked questions

    Announcements: Frequently asked questions

    Karl_Ackerman
    Karl_Ackerman
    Welcome to the EDR Data Lake EAP (Early Access Program). How do I learn more In this forum you will find a number of documents, videos, queries and posts explaining the program and if you have any questions you can post them to the discussions area ...
    • 24 Mar 2021
  • Using Live Discover to get more flexible Threat Indicator results and perform powerful Threat Searches

    Release Notes & News: Using Live Discover to get more flexible Threat Indicator results and perform powerful Threat Searches

    Kevin Kingston
    Kevin Kingston
    After the launch of Intercept X Advanced with EDR in late 2018, we introduced the EDRv1 Data Feed (aka Trickle Feed) functionality to enable Administrators to easily view Threat Indicators and perform Threat Searches. Now there is a better way! The L...
    • 15 Mar 2021
<>