• Tags
  • Subscribe by email
  • More
  • Cancel
  • EDR Data Lake API Intro Webinar

    Announcements: EDR Data Lake API Intro Webinar

    Kevin Kingston
    Kevin Kingston
    Check out this webinar where the Sophos Engineering and PM team give an introduction on coding against the EDR Data Lake API and walk through using and modifying the Sophos Data Lake Test tool. vimeo.com/.../ad569fd23d
    • 18 Nov 2020
  • XG Firewall data

    Announcements: XG Firewall data

    Karl_Ackerman
    Karl_Ackerman
    For query assistance, please see the following Best Practices guide I am adding a set of queries to explore information in the data lake from the XG Firewall. For the data lake to have information from the XG Firewall you will need to have...
    • 16 Nov 2020
  • API Guide - Getting Started

    Announcements: API Guide - Getting Started

    Karl_Ackerman
    Karl_Ackerman
    You can find the getting started guide for the EDR Data Lake APIs available here on the apigee.io site we use. Overview This guide takes you through a few simple steps to start using the new EDR Data Lake APIs in Sophos Central. All our APIs are off...
    • 2 Nov 2020
  • Track Network Connections - New policy setting

    Release Notes & News: Track Network Connections - New policy setting

    StephenMcKay
    StephenMcKay
    Hi all, We are releasing a new policy setting to all customer on the w/c 2nd November, 'Track Network Connections'. This will be in the Advanced Settings section of the Threat Protection policy We plan to enable this new feature gradually ov...
    • 1 Nov 2020
  • License changes to New Endpoint and Server Protection and EDR Features early access programs

    Announcements: License changes to New Endpoint and Server Protection and EDR Features early access programs

    Kevin Kingston
    Kevin Kingston
    With having completed the early access testing on our new EDRv3 capabilities and with the upcoming features that will be entering the New Endpoint and Server Protection and EDR Features early access program being more protection rather than EDR relat...
    • 23 Oct 2020
  • Sophos Central- Sophos Core Agent v2.10.7 and Endpoint Advanced v10.8.9 has been released

    Release Notes & News: Sophos Central- Sophos Core Agent v2.10.7 and Endpoint Advanced v10.8.9 has been released

    Shweta
    Shweta
    Hi everyone,  The following versions have been released to Sophos Central Windows Endpoints.  Sophos Core Agent 2.10.7 Endpoint Advanced 10.8.9 This release will require a reboot. Please see the following release notes for more informatio...
    • 15 Oct 2020
  • Queries for endpoint (Firewall coming soon)

    Announcements: Queries for endpoint (Firewall coming soon)

    Karl_Ackerman
    Karl_Ackerman
    Hi all I have started populating the queries section of the forum.  I Expect to put about 50 queries into the forum to perform the basic navigation and exploration of the data.  Once I get those loaded in we will start adding more interesti...
    • 13 Oct 2020
  • Intercept X Protection Enhancements

    Release Notes & News: Intercept X Protection Enhancements

    StephenMcKay
    StephenMcKay
    We're starting to turn on IPS and Behavior detection features for endpoint and server customers. You'll see a new "Detect malicious behavior" option in threat protection policies. You can test both of these features now in the Early Access Program; ...
    • 1 Oct 2020
  • Intercept X with EDR September enhancements

    Release Notes & News: Intercept X with EDR September enhancements

    Kevin Kingston
    Kevin Kingston
    Throughout September we will continue to enhance EDR capabilities and with our latest update we are pleased to announce that the powerful EDR querying and response capabilities of Live Discover and Live Response are now generally available on Ma...
    • 21 Sep 2020
  • Notice for next EAP update

    Announcements: Notice for next EAP update

    StephenMcKay
    StephenMcKay
    Hello all, We are due to update our EAP agent during the week of 21st September; this update has some small fixes in it and will allow us to start enabling IPS and our new behavioral engine.  Note: After this update you need to reboot devices to...
    • 15 Sep 2020
  • Enhancing EDR in The Cloud

    Release Notes & News: Enhancing EDR in The Cloud

    Rich Beckett
    Rich Beckett

    We are excited to announce that Intercept X for Server Advanced with EDR has been enhanced with powerful cloud visibility features from Cloud Optix.

    In addition to even more detail on AWS, Azure and GCP cloud workloads, this integration gives Sophos partners and customers critical insight into their wider cloud environment including security groups, hosts, shared storage, databases, serverless, containers and more.

     

    …
    • 29 Jul 2020
  • Sophos Intercept X Advanced with EDR just keeps getting better

    Release Notes & News: Sophos Intercept X Advanced with EDR just keeps getting better

    Kevin Kingston
    Kevin Kingston

    Sophos continues to enhance our new EDRv3 capabilities and over the past week numerous improvements have been introduced:

    Role Based Access Controls for the Live Response Beta:

    One of the top requests received during the Live Response Beta during the Early Access Program was to provide Administrators better control around defining Central admins who can use Live Response and who can manage the Live Response settings. 

    …
    • 14 Jul 2020
  • Exploring Windows Events and Security groups  with Live Discover

    Announcements: Exploring Windows Events and Security groups with Live Discover

    Karl_Ackerman
    Karl_Ackerman

    For query assistance, please see the following Best Practices guide

    The Sophos UK Sales engineering team has been getting familiar with live discover. In the work they explored group policy and provided the following queries:

    Deleted security groups -

    Variable to specify the number of days to check
    Windows

    /* Deleted Security Groups */
    SELECT
       source,
       eventid, 
       CAST(datetime(time, 'unixepoch') AS TEXT) AS 'Change Made',…

    • 6 Jul 2020
  • Detecting Glupteba malware with Sophos EDR

    Announcements: Detecting Glupteba malware with Sophos EDR

    Seth Geftic
    Seth Geftic

    Last week SophosLabs published a report about the Glupteba malware. According to Sophos Labs this malware family has been growing in numbers. "This malware, with its hard-to-pronounce name, has been getting regular updates and feature enhancements that seem to be focused on its ability to conceal itself from detection on infected computers....The core malware is, in essence, a dropper with extensive backdoor functionality, but…

    • 29 Jun 2020
  • Intercept X Advanced with EDR: Start using the powerful new EDR features

    Release Notes & News: Intercept X Advanced with EDR: Start using the powerful new EDR features

    Kevin Kingston
    Kevin Kingston

    We are thrilled to announce that the latest version of Sophos EDR (endpoint detection and response) is now available to all Intercept X Advanced with EDR and Intercept X Advanced for Server with EDR customers.  This release brings powerful new capabilities that enable both IT admins and security analysts to ask detailed IT operations and threat hunting questions across their entire estate. It also provides new functionality …

    • 19 Jun 2020
  • Linux EDR - Live Discover

    Release Notes & News: Linux EDR - Live Discover

    StephenMcKay
    StephenMcKay

    There have been posts about our exciting new Linux EDR release elsewhere on the forum, but in case you missed them; here they are!

    We have had our Live Discover feature available for Linux Servers in our Early Access Program for a couple of months; this will be launching next week. Live Discover allows admins to search their data to answer almost any question they can think of by searching across their servers using SQL…

    • 15 Jun 2020
  • Live Discover for LINUX.... Video

    Announcements: Live Discover for LINUX.... Video

    Karl_Ackerman
    Karl_Ackerman

    In the next two weeks we will be fully launching the EDR Live Discover for LINUX.

    The capabilities on Linux are simply astounding, we have been busy creating the prebuilt queries and finishing the last bit of work before this is fully available.

    In the video, Ethan Vince-Urwin, one of the core linux developers who has been building the features we all love takes the product for a test drive and shows off some of the power…

    • 11 Jun 2020
  • KingMiner non-deterministic indicators of compromise

    Announcements: KingMiner non-deterministic indicators of compromise

    Karl_Ackerman
    Karl_Ackerman

    For query assistance, please see the following Best Practices guide

    See the story from SophosLabs Uncut on KingMiner: https://news.sophos.com/en-us/2020/06/09/kingminer-report/

    The article is both educational and enlightening.  One of the aspects of KingMiner that is common with other attacks is that many of the indicators of compromise are non-deterministic.  The domain names and URLs they use are all auto generated.   I read…

    • 10 Jun 2020
  • Intercept X with EDR: Powerful new IT operations and threat hunting features now available

    Release Notes & News: Intercept X with EDR: Powerful new IT operations and threat hunting features now available

    Kevin Kingston
    Kevin Kingston

    We are thrilled to announce that the latest version of Sophos EDR (endpoint detection and response) is now available in Intercept X Advanced with EDR and Intercept X Advanced for Server with EDR.  This release brings powerful new capabilities that enable both IT admins and security analysts to ask detailed IT operations and threat hunting questions across their entire estate. It also provides new functionality to remotely respond…

    • 29 May 2020
  • New Sophos Table - Sophos_process_activity

    Announcements: New Sophos Table - Sophos_process_activity

    Karl_Ackerman
    Karl_Ackerman

    For query assistance, please see the following Best Practices guide

    We have added a new table to the sophos forensics journals. The sophos_process_activity table.

    Often as part of an investigation you need to to get a quick view of what a process did in the past and this table provides a quick lookup location for that information.

    This table contains a subject for each of the other Sophos 'journals' and collects some of…

    • 26 May 2020
  • Live Discover Queries - Review Process

    Announcements: Live Discover Queries - Review Process

    Karl_Ackerman
    Karl_Ackerman

    Posting a query to the Live Discover Queries board will now include a review process.  This will allow us to review any question and proposed answer prior to it being visible by others.  We are adding this to ensure that the content of the queries do not contain anything inappropriate and that the query has been reviewed and tested and is not believed to cause harm. as for how well it does what it says.  we advise administrators…

    • 23 May 2020
  • How to find and use the Schema for Live Discovery Queries

    Announcements: How to find and use the Schema for Live Discovery Queries

    Karl_Ackerman
    Karl_Ackerman

    For query assistance, please see the following Best Practices guide

    While we have the schema posted on the EAP community pages, I have had a number of request for how to find it and how to use it.

    First how to find the schema(s):

    From the Sophos Community: We provide a link to definition of the sophos windows schema on the community form in the documents section. You can downlaod the file with this link: https://community…

    • 19 May 2020
  • Updated Endpoint User Interface

    Release Notes & News: Updated Endpoint User Interface

    tom_w
    tom_w

    We're pleased to announce that a new version of the Sophos Endpoint user interface is being rolled out to customers. Windows clients will begin updating this week, with Windows servers following in June.

    The key goal of the update is to better represent our different endpoint components (Intercept X, Central Device Encryption, and the upcoming Unified Endpoint Management agent), and to bring a consistent look across…

    • 18 May 2020
  • Intercept X with EDR EAP - Variable support for queries

    Announcements: Intercept X with EDR EAP - Variable support for queries

    Karl_Ackerman
    Karl_Ackerman

    Starting on the week of may 18 we will be adding variable support to queries.

    You can create queries that now include support for up to 6 variables. A variable will be given a $$ prefix and postfix and can be either a TEXT or DATE value.  You will write your query and specify the variable information in the query.  Then when you run it you will be able to simply drop in the information for the variable and we will automatically…

    • 15 May 2020
<>