• Tags
  • Subscribe by email
  • More
  • Cancel
  • SSH Brute Force and Port Scan detections

    SSH Brute Force and Port Scan detections

    Karl_Ackerman
    Karl_Ackerman
    New DDE Detection Reports for Sophos NDR We are excited to announce the activation of two new DDE detection reports for Sophos Network Detection and Response (NDR): 1. NDR-DET-DDE-BASICPORTSCAN Overview: This report detects simple port scanning acti...
    • 22 Oct 2024
  • NDR Update - Version 1.8.0-2352

    NDR Update - Version 1.8.0-2352

    Karl_Ackerman
    Karl_Ackerman
    NDR Sensor v1.8.0-2352: New Features and Enhancements We are excited to announce the release of NDR Sensor v1.8.0-2352, which brings powerful new capabilities in asset identification and enhanced security detection. Availability: This update was rele...
    • 17 Oct 2024
  • NDR Certified Hardware Aug 2024

    NDR Certified Hardware Aug 2024

    Karl_Ackerman
    Karl_Ackerman
    Updated Certified Hardware. MOST POPULARDirector Order Link:  https://www.onlogic.com/store/MC510-55-SOPHOS/#configure-and-buy
    • 27 Aug 2024
  • NDR Overview and Roadmap through 2025 Q2

    NDR Overview and Roadmap through 2025 Q2

    Karl_Ackerman
    Karl_Ackerman
    Watch the 40 min Sophos NDR product overview and presentation on roadmap items through 2025.  Karl Ackerman the product manager for Sophos NDR covers details on how NDR works and how to access the features of NDR from Sophos Central. commun...
    • 13 Aug 2024
  • NDR V1.7 - Investigation Console, product pages and new certified hardware

    NDR V1.7 - Investigation Console, product pages and new certified hardware

    Karl_Ackerman
    Karl_Ackerman
    This week, we are starting the phased deployment of Sophos NDR V 1.7, which will be completed for all existing NDR customers by August 9th. This release includes several important updates, including the new NDR Investigation Console. This tool provid...
    • 4 Aug 2024
  • Coming Soon: NDR Investigation Console (July)

    Coming Soon: NDR Investigation Console (July)

    Karl_Ackerman
    Karl_Ackerman
    In July 2024, Sophos plans to release the NDR Investigation Console, a new component for the Network Detection and Response (NDR) solution. The NDR Investigation Console provides: A graphical user interface for accessing 30 days of historical networ...
    • 3 Jun 2024
  • Investigation Playbooks for NDR

    Investigation Playbooks for NDR

    Karl_Ackerman
    Karl_Ackerman
    With NDR you will automatically have detections and for those with a severity of 6 or higher an investigation record will be created and the administrator will be notified.To assist with how to perform an investigation we are developing investigation...
    • 28 May 2024
  • NDR - Certified Hardware support Now available

    NDR - Certified Hardware support Now available

    Karl_Ackerman
    Karl_Ackerman
    All NDR customers can now deploy the NDR Sensor on certified Hardware, no additional license is required. NDR and Log Collectors are supported on VMWARE, MS Hyper-V, AWS AMI, and Hardware. NDR is currently supported on the following Certified HW opti...
    • 17 May 2024
  • Coming in May/June 2024 - NDR ISO image

    Coming in May/June 2024 - NDR ISO image

    Karl_Ackerman
    Karl_Ackerman
    NDR ISO Image for Certified Hardware Coming Soon! We're thrilled to share a major update on our NDR (Network Detection and Response) capabilities. Our team is in the final stages of developing an ISO image for installing NDR on certified hardware. Th...
    • 14 Feb 2024
  • AWS AMI deployment options

    AWS AMI deployment options

    Karl_Ackerman
    Karl_Ackerman
    Support for deployment of the NDR Sensor in AWS AMI for all NDR and XDR/MDR Customers with a licensed integration pack that requires a log collector. licensed customers. When will this be available for my use? We are expecting to make the AMI image d...
    • 8 Feb 2024
  • NDR Dashboard BETA

    NDR Dashboard BETA

    Karl_Ackerman
    Karl_Ackerman
    This week we began enabling the Beta version of the NDR Dashboards.The dashboards are located in the Threat Analysis Center and available for all accounts with an NDR Product license. The initial versions of the dashboards enable the ability to view ...
    • 25 Jan 2024
  • New Techvids Release - Sophos NDR: Product Overview

    New Techvids Release - Sophos NDR: Product Overview

    Sophos
    Sophos
    Sophos Network Detection and Response (NDR) provides critical visibility into network activity that other products miss.This video provides an overview of this exciting product and highlights the powerful real-time threat detection engines that power...
    • 2 Jan 2024
  • NDR EAP  to close in January

    NDR EAP to close in January

    Karl_Ackerman
    Karl_Ackerman
    With the release of NDR for XDR customers to purchase as a product in November, we are in the process of finalizing the remaining work we we planned for this year.  NDR EAP to close in January We will be closing the availability of NDR as part o...
    • 7 Dec 2023
  • NDR Detection generation from network device

    NDR Detection generation from network device

    Karl_Ackerman
    Karl_Ackerman
    In addition to the option to generate test detections from the NDR management console we have a test executable that can be downloaded from Sophostest.com.  Below are the details: Overview The NDR team has created an 'EICAR' ...
    • 29 Nov 2023
  • Generate NDR Detections

    Generate NDR Detections

    Karl_Ackerman
    Karl_Ackerman
    With the November update to NDR we have added the ability to generate an NDR detection directly from the Appliance manager console. VIDEO: https://vimeo.com/884426639?share=copy The Generate Detections option on the left side navigation bar will...
    • 14 Nov 2023
  • Updated Detection Display

    Updated Detection Display

    Karl_Ackerman
    Karl_Ackerman
    As part of the XDR Features EAP we are in the process of improving the overall detection display layout  See the detailed article in the XDR community forum.  New Detections User Experience for the Threat Analysis Center  For NDR dete...
    • 31 Aug 2023
  • NDR Appliance Manager GUI

    NDR Appliance Manager GUI

    Karl_Ackerman
    Karl_Ackerman
    We are adding a new Appliance Manager console the week of Aug 28th. As part of the Early Access Program for NDR I am happy to say we have the initial version of the Appliance Manager now available. You can log into a GUI management interface for the ...
    • 24 Aug 2023
  • NDR Early Access Program for XDR and Trial accounts

    NDR Early Access Program for XDR and Trial accounts

    Karl_Ackerman
    Karl_Ackerman
    We are adding the Sophos NDR Sensor to the XDR Features EAPDuring the EAP customers can deploy Sophos NDR (Network Detection and Response) in their estate and gain the benefits of the already available Sophos NDR Sensor without requiring to be a Soph...
    • 17 Jul 2023
  • NDR Best Practices deployment guide

    NDR Best Practices deployment guide

    Karl_Ackerman
    Karl_Ackerman
    When deploying and setting up an NDR Sensor on a VMWare or Hyper-V virtual appliance there are a lot of things to consider. In this comprehensive guide we cover best practices for the setup and configuration of the NDR Sensor.  Sophos Appliance ...
    • 14 Jun 2023
  • Sophos NDR for XDR - Early Access Program (Coming in July)

    Sophos NDR for XDR - Early Access Program (Coming in July)

    Karl_Ackerman
    Karl_Ackerman
    We are excited to announce the upcoming launch of our Early Access Program (EAP) for Sophos Network Detection and Response (NDR). Starting this July, all XDR and MDR customers will have an exclusive opportunity to test the potent capabilities of Soph...
    • 9 Jun 2023
  • A Deep Dive Into Pikabot: An Emerging Cyber Threat in 2023

    A Deep Dive Into Pikabot: An Emerging Cyber Threat in 2023

    Karl_Ackerman
    Karl_Ackerman
    Introduction Pikabot is a recently discovered malware trojan that emerged in 2023.​ With the June update to Sophos NDR we have added an additional machine learning model to detect the encrypted traffic pattern of suspect Pikabot communicati...
    • 8 Jun 2023
  • NDR Live Discover Reports

    NDR Live Discover Reports

    Karl_Ackerman
    Karl_Ackerman
    NDR Live Discover Category and a set of 23 reports are now available for all NDR customers. This update allows you to explore the NDR data and flow based detections. Video: https://vimeo.com/manage/videos/831535844 From the Central Threat Analysis Ce...
    • 8 May 2023
  • How to enable Remote Assistance for Data Collectors

    How to enable Remote Assistance for Data Collectors

    Karl_Ackerman
    Karl_Ackerman
    If you run into issues with a log collector or NDR Sensor and call Sophos support for assistance you can now enable remote assist to allow them direct access to the Data Collector. Sophos Support: https://www.sophos.com/en-us/support Sophos supp...
    • 4 May 2023
  • Update on QakBot Servers: ML Model for NDR Continues to Detect New C2 Servers

    Update on QakBot Servers: ML Model for NDR Continues to Detect New C2 Servers

    Karl_Ackerman
    Karl_Ackerman
    Sophos Network Detection and Response (NDR) uses encrypted packet analysis to identify new command and control (C2) servers as they emerge. Unlike traditional IOC-based detection, which relies on known indicators of compromise, our model performs con...
    • 24 Apr 2023
  • New QakBot C2 Servers Detected with Sophos NDR

    New QakBot C2 Servers Detected with Sophos NDR

    Karl_Ackerman
    Karl_Ackerman
    As malware continues to evolve and adversaries become more adept at evading detection, dynamic AI and machine learning technologies are critical for detection of the latest threats and attacks.  Sophos NDR utilizes a series of machine learning m...
    • 19 Apr 2023
>