• Tags
  • Subscribe by email
  • More
  • Cancel
  • Linux host and container threat detection

    Release Notes & News: Linux host and container threat detection

    StephenMcKay
    StephenMcKay
    I am pleased to announce significant enhancements to the detection and response capabilities for Linux server workloads and containers in the cloud, on-premises and virtual deployments. The new functionality, made available through the integrati...
    • 1 Apr 2022
  • New Central Endpoint/Server Intelix Service Region setting

    Release Notes & News: New Central Endpoint/Server Intelix Service Region setting

    Kevin Kingston
    Kevin Kingston
    For Endpoint/Server customers looking to control the region being used when requesting the latest SophosLabs intelligence on files, we have introduced the new ‘Intelix Service Region’ setting.  SophosLabs Intelix provides threat...
    • 16 Mar 2022
  • Updated Features for XDR Detections and Investigations

    Release Notes & News: Updated Features for XDR Detections and Investigations

    Karl_Ackerman
    Karl_Ackerman
    We are continuing to make improvements to the XDR Detections and Investigation console.   Sophos is continuously developing new features and refining how existing ones work and for those who use the product regularly you will notice th...
    • 28 Feb 2022
  • XDR - Detection and Investigation EAP Closing February 28th

    Release Notes & News: XDR - Detection and Investigation EAP Closing February 28th

    Kevin Kingston
    Kevin Kingston
    With the Microsoft 365 Data Lake connector along with the Detection and Investigation functionality having reached general availability to all XDR customers we are now in a position where we are ready to close the ‘XDR – Detection and In...
    • 25 Feb 2022
  • XDR - Changes to look back in time when querying Sophos Data Lake

    Release Notes & News: XDR - Changes to look back in time when querying Sophos Data Lake

    Kevin Kingston
    Kevin Kingston
    We have introduced a new Time Period selector that is applied to XDR Data Lake queries. On creating a brand new Data Lake query, a new Data Lake query based off a canned query or a new scheduled Data Lake query you will see the new Time Period select...
    • 5 Feb 2022
  • Ransomware Protection - CryptoGuard 5 Enablement

    Release Notes & News: Ransomware Protection - CryptoGuard 5 Enablement

    StephenMcKay
    StephenMcKay
    CryptoGuard 5: A new policy option now sets the default action on detection of ransomware to terminate the process. We have kept the option to only isolate a process should you wish to keep using the setting from CryptoGuard 4.  This new releas...
    • 28 Jan 2022
  • Microsoft 365 Data Integration (formerly Office 365) and Investigations now in GA

    Release Notes & News: Microsoft 365 Data Integration (formerly Office 365) and Investigations now in GA

    Jack L
    Jack L
    We have now rolled out the Microsoft 365 Data Integration (formerly Office 365) and Investigations into GA.  1. Getting started with Microsoft 365 Data Integration: All XDR customers who wish to have their MS 365 data ingested into their data la...
    • 27 Jan 2022
  • MacOS Endpoint EAP - January 2022 Update

    Announcements: MacOS Endpoint EAP - January 2022 Update

    FormerMember
    FormerMember
    As of January 27 2022, the EAP is moving to version 10.3.2.  All enrolled devices should automatically update. Improvements in 10.3.2 Scan Extension improvements Optimized file interception operations to boost overall system performance Additi...
    • 26 Jan 2022
  • STIX scanning with XDR

    Release Notes & News: STIX scanning with XDR

    Karl_Ackerman
    Karl_Ackerman
    For query assistance, please see the following Best Practices guide The world is full of tools and products to facilitate threat hunting in your environment.  In this post I explore how to take threat intelligence from a 3rd party rep...
    • 27 Dec 2021
  • Investigations EAP Now Open

    Release Notes & News: Investigations EAP Now Open

    Jack L
    Jack L
    Investigations is now available for customers who wish to opt-in. If you were previously enrolled in the XDR – Detection and Investigation EAP, you should see Investigations in the Threat Analysis Center and there is no action on your part...
    • 17 Dec 2021
  • Intercept X Protection Is Getting Even Better

    Release Notes & News: Intercept X Protection Is Getting Even Better

    StephenMcKay
    StephenMcKay
    A multi-year endeavor in the making, the rollout of the next-gen scanning architecture has begun. This is a ground-up rewrite of functionality that touches nearly every aspect of Intercept X and delivers multiple benefits to customers.  Re...
    • 16 Dec 2021
  • Sophos XDR Data Sources, Enrichment and Pivoting

    Release Notes & News: Sophos XDR Data Sources, Enrichment and Pivoting

    Anthony Merry
    Anthony Merry
    Note: With special thanks to AK, mward19, Maxim-Sophos, and JoeLevy This post provides information about Sophos XDR. It has three main sections: Data Sources Data Enrichment and Pivoting Integrations and API’s Table...
    • 13 Dec 2021
  • [Closed] Sophos XDR new feature study: January 2022

    Release Notes & News: [Closed] Sophos XDR new feature study: January 2022

    Aman Sandher
    Aman Sandher
    Thank you to everyone who applied. Due to an overwhelming response, we have reached our capacity. The survey is now closed.  Try out a new XDR product feature as part of our Customer Research initiative in mid-January. Help us evaluate a new pro...
    • 13 Dec 2021
  • HTTPS policy changes

    Announcements: HTTPS policy changes

    StephenMcKay
    StephenMcKay
    Hi all, This weekend we are making some policy changes relating to the SSL/TLS decryption of HTTPS websites. We will be adding a toggle for SSL/TLS decryption into the Threat Protection policy for all customers. This new setting will determine if En...
    • 3 Dec 2021
  • Now available - MS 365 Azure Audit logs and XDR Data lake

    Announcements: Now available - MS 365 Azure Audit logs and XDR Data lake

    Karl_Ackerman
    Karl_Ackerman
    For query assistance, please see the following Best Practices guide We have enabled the ability to add the Office 365 Audit log information into the Sophos XDR Data Lake. This capability is available for ALL XDR customers at NO ADDITI...
    • 1 Dec 2021
  • New Techvids Release: Migrating from Enterprise Console to Sophos Central

    Release Notes & News: New Techvids Release: Migrating from Enterprise Console to Sophos Central

    Aman Sandher
    Aman Sandher
    Follow Kushal from the Sophos Community Team as he walks you through the Sophos Central Migration Tool. With Enterprise console nearing the end of support, now is the time to migrate to Sophos Central. Watch the full video: https://techvids.sophos.co...
    • 24 Nov 2021
  • Intercept X updates in the Early Access Program

    Announcements: Intercept X updates in the Early Access Program

    StephenMcKay
    StephenMcKay
    Hi all, As you will have read in the Recommended Read from last week; we released an update to Intercept X, 2.0.23. This week we will start enabling new features that are part of the update for devices that are running in the New Endpoint/Server...
    • 4 Nov 2021
  • XDR - Detections

    Release Notes & News: XDR - Detections

    Kevin Kingston
    Kevin Kingston
    Sophos are excited to announce that from today we have started the rollout of the new Detections functionality to all Sophos XDR customers. The rollout is being done in stages with additional functionality being added over time. In this first release...
    • 3 Nov 2021
  • XDR Live Discover Public_IP extension table will be removed

    Release Notes & News: XDR Live Discover Public_IP extension table will be removed

    Karl_Ackerman
    Karl_Ackerman
    For query assistance, please see the following Best Practices guide As part of the regular maintenance of the XDR Live Discover extension from Sophos we review the use of extension tables provided. In that review we see that only 5 custome...
    • 21 Oct 2021
  • Intercept X Advanced with XDR Mac devices to start uploading to Sophos Data Lake

    Release Notes & News: Intercept X Advanced with XDR Mac devices to start uploading to Sophos Data Lake

    Kevin Kingston
    Kevin Kingston
    Today we will start uploading data from Intercept X Advanced XDR Mac devices to the Sophos Data Lake where Endpoint Data Lake uploads have been enabled.  The plan is to slowly enable across our customer base doing 30% of accounts today, assumin...
    • 20 Oct 2021
  • XDR Detections EAP

    Announcements: XDR Detections EAP

    Karl_Ackerman
    Karl_Ackerman
    Now with the XDR Detections EAP open folks can see all activity that has been classified to MITRE ATT&CK. The new page is in the Threat Analysis Center and has lots of really great information on what has been observed in your environment. &...
    • 20 Oct 2021
  • Welcome to the New macOS Endpoint Protection Features EAP

    Announcements: Welcome to the New macOS Endpoint Protection Features EAP

    FormerMember
    FormerMember
    This EAP is a persistent program where you can subscribe to the latest and greatest new features and fixes. Participants are encouraged to try out these features and provide feedback to or development team to help improve the product.  Improveme...
    • 18 Oct 2021
  • SSL/TLS decryption of HTTPS websites

    Announcements: SSL/TLS decryption of HTTPS websites

    StephenMcKay
    StephenMcKay
    Hi all, HTTPS inspection is being enabled by default for devices in the EAP now that the roll out has finished, (both Endpoint and Server). When users visit websites via browsers the Sophos endpoint will decrypt HTTPS network traffic for the pur...
    • 15 Oct 2021
  • XDR - Detection and Investigation Early Access Program

    Announcements: XDR - Detection and Investigation Early Access Program

    Kevin Kingston
    Kevin Kingston
    We are excited to announce the opening of the Detections and Investigations Early Access Program (EAP).  The EAP begins with the introduction of the Detections dashboard which provides a prioritized list of suspicious activity for further invest...
    • 10 Oct 2021
<>