• Notice for next EAP update

    Announcements: Notice for next EAP update

    StephenMcKay
    StephenMcKay
    Hello all, We are due to update our EAP agent during the week of 21st September; this update has some small fixes in it and will allow us to start enabling IPS and our new behavioral engine.  Note: After…
    • 15 Sep 2020
  • Exploring Windows Events and Security groups  with Live Discover

    Announcements: Exploring Windows Events and Security groups with Live Discover

    Karl_Ackerman
    Karl_Ackerman

    For query assistance, please see the following Best Practices guide

    The Sophos UK Sales engineering team has been getting familiar with live discover. In the work they explored group policy and provided…

    • 6 Jul 2020
  • Detecting Glupteba malware with Sophos EDR

    Announcements: Detecting Glupteba malware with Sophos EDR

    Seth Geftic
    Seth Geftic

    Last week SophosLabs published a report about the Glupteba malware. According to Sophos Labs this malware family has been growing in numbers. "This malware, with its hard-to-pronounce name, has been getting regular…

    • 29 Jun 2020
  • Live Discover for LINUX.... Video

    Announcements: Live Discover for LINUX.... Video

    Karl_Ackerman
    Karl_Ackerman

    In the next two weeks we will be fully launching the EDR Live Discover for LINUX.

    The capabilities on Linux are simply astounding, we have been busy creating the prebuilt queries and finishing the last…

    • 11 Jun 2020
  • KingMiner non-deterministic indicators of compromise

    Announcements: KingMiner non-deterministic indicators of compromise

    Karl_Ackerman
    Karl_Ackerman

    For query assistance, please see the following Best Practices guide

    See the story from SophosLabs Uncut on KingMiner: https://news.sophos.com/en-us/2020/06/09/kingminer-report/

    The article is both educational…

    • 10 Jun 2020
  • New Sophos Table - Sophos_process_activity

    Announcements: New Sophos Table - Sophos_process_activity

    Karl_Ackerman
    Karl_Ackerman

    For query assistance, please see the following Best Practices guide

    We have added a new table to the sophos forensics journals. The sophos_process_activity table.

    Often as part of an investigation you need…

    • 26 May 2020
<>