• Data Lake Query similar to Endpoint File Access History

    Vern Severight
    Vern Severight
    • Data Lake
    • Under Review on 7 Dec 2023
    • 3 Comments
    Is there a query available for the data lake to query file information similar to the File Access History that endpoint queries use? We would like to be able to query our data lake and find copied / modified / moved / deletions / re-naming & what it...
    • 7 Dec 2023 10:45 PM
  • XDR Query - Get OS Buildnumber with Patchlevel

    Bernhard Weitlaner
    Bernhard Weitlaner
    • NDR Queries
    • Under Review on 6 Dec 2023
    • 3 Comments
    Hello Community, is it possible to get the full os build number inclusive patchlevel (windows) with a XDR Query or other way? There is a query named "Hardware and operating system details" but with this query i only get the os_version and build, for...
    • 6 Dec 2023 7:46 AM
  • NDR detection

    Shay Hanya
    Shay Hanya
    • NDR Queries
    • Under Review on 26 Nov 2023
    • 1 Comment
    Hi I installed NDR appliance in my network, and I'm getting this messages: NDR-DET-DDE-MACIPHOSTNAMECORRELATION "Source MAC address, IP address, and Hostname correlation based on MDNS and NetBIOS" The detection in low severity. Any idea...
    • 26 Nov 2023 2:55 PM
  • Custom curl query?

    Andrew Bishop
    Andrew Bishop
    • Other queries
    • Under Review on 16 Nov 2023
    • 8 Comments
    Does anyone know of or have a custom live discover query that can identify any processes, programs running cURL? I am seeing something to help identify the vulnerability located in CVE-2023-38545. Description The version of curl installed on the remote...
    • 16 Nov 2023 3:16 PM
  • Is there a way to check what applications are installed on MAC endpoints via Sophos Central?

    Subash Chandran
    Subash Chandran
    • Device
    • Approved on 19 Jan 2024
    • 1 Comment
    Is there a way to check what applications are installed on MAC endpoints via Sophos Central? I can see queries to pull-out installed application list from Windows endpoints. Is there any query for MAC endpoints
    • 15 Nov 2023 8:50 AM
  • Create Custom Query and Run on Endpoints

    Dilip Devadas
    Dilip Devadas
    • Data Lake
    • Under Review on 17 Oct 2023
    • 2 Comments
    Hello, I would like to run this command on all devices and extract as periodic report using Query from endpoint thru Sophos Cental. Command wmic bios get serialnumber, hostname
    • 17 Oct 2023 4:43 AM
  • Live Discover - Patches Applied (Windows)

    Selvinen VENCATAKISTNEN
    Selvinen VENCATAKISTNEN
    • Compliance
    • Complete on 19 Jan 2024
    • 1 Comment
    Hello, The current query for "Patches applied" lists all the patches applied, but does not include patches applied via MSI or downloaded from Windows Update. Query: SELECT hotfix_id, description, installed_by, installed_on FROM patches Is...
    • 13 Oct 2023 6:31 AM
  • Domains (FQDNs) to allow for Live Discover (for MDR team)

    BoreasJeff
    BoreasJeff
    • Network
    • Under Review on 5 Oct 2023
    • 5 Comments
    What are the domains or FQDNs to allow for access to Live Discover? The goal is to allow the Sophos MDR team to access an endpoint that is in red status and getting blocked by the firewall. When a device behind the Sophos firewall goes into a red...
    • 5 Oct 2023 11:00 PM
  • Using Live Response to investigate Sophos Services & their CPU utilization

    Bhaumik Gohel
    Bhaumik Gohel
    • Live Response
    • Approved on 10 Aug 2023
    • 0 Comments
    Initial Steps: The given Powershell script will run from Live Response as well as from powershell prompt. There's no obligation to have elevated privilege to run this script. After opening command prompt enter "powershell" Copy paste the complete...
    • 10 Aug 2023 2:47 PM
  • Find only new created files by extension

    LHerzog
    LHerzog
    • Files
    • Under Review on 7 Aug 2023
    • 1 Comment
    Hi, I did a copy of the default live query: File access history I'm only interested in new files that have been created in that timeframe. The demand is a bit like the default " New applications deployed " query. But not only for applications. ...
    • 7 Aug 2023 3:50 PM
<>