• [Sophos Firewall / Data Lake] Identify Attempts to Access Firewall by Country

    Matthew Ritchie
    Matthew Ritchie
    • Network
    • Under Review on 18 Oct 2022
    • 1 Comment
    SELECT device_model, --device_serial_id, --app_name AS ProtoPort, --in_interface,-- --src_mac,-- src_ip, dst_ip, src_country, log_type AS Source_Log, log_subtype AS Decision, src_port, dst_port --protocol-- FROM xgfw_data ...
    • 18 Oct 2022 7:47 PM
  • mismatched input

    ekrem19
    ekrem19
    • User
    • Complete on 14 Oct 2022
    • 4 Comments
    Hi, I run the following query and had an error. I got the query from GitHub. https://github.com/Sophos-Community/XDR_Queries/commit/80a062e25426c9879b4b238cf889e93088e2e41f What could be wrong? Invalid sql: SELECT source, eventid, CAST(datetime...
    • 13 Oct 2022 11:31 PM
  • Live Discover query to check installed Internet Explorer

    gb-hg
    gb-hg
    • Device
    • Complete on 7 Oct 2022
    • 1 Comment
    Hello all, I would be very interested if someone has a ready-made query to check an installed Internet Explorer on Windows clients/server? C:\Program Files\Internet Explorer\iexplore.exe Many thanks for your support!
    • 7 Oct 2022 1:22 PM
  • Integration Status

    Karl_Ackerman
    Karl_Ackerman
    • NDR Queries
    • Approved on 5 Oct 2022
    • 0 Comments
    Identify the Integration that have information in the data lake, how much data they have sent and when they last sent data. NOTE: If no data has been sent to the data lake then the integration is not listed -- Display Integration status -- NOTE if...
    • 5 Oct 2022 3:13 PM
  • NDR: NDR Report - idsSrcIps Blacklist, botnets, and more

    Karl_Ackerman
    Karl_Ackerman
    • NDR Queries
    • Under Review on 16 Sep 2022
    • 0 Comments
    This query evaluates the NDR detection and report data to identify interesting detections that can also be seen from the Detections list page. -- List of communications to ids messages *Exclude ids_msg's that are NULL SELECT DISTINCT COUNT(*) instances...
    • 16 Sep 2022 1:43 PM
  • NDR Data exploration

    Karl_Ackerman
    Karl_Ackerman
    • NDR Queries
    • Under Review on 16 Sep 2022
    • 0 Comments
    With the Sophos NDR Connector configured and working you will have detections and reports available. How to setup the NDR Connector https://community.sophos.com/mdr-community-channel/mdr-integrations-eap/w/ndr_wiki/127/deployment-and-configuration...
    • 16 Sep 2022 1:22 PM
  • AWS Queries - Exploring AWS Data with live discover

    Karl_Ackerman
    Karl_Ackerman
    • NDR Queries
    • Under Review on 8 Sep 2022
    • 0 Comments
    Once you have configured the AWS Security hub connector you can add some queries to explore the data. How to enable the AWS Security Hub Connector: https://community.sophos.com/mdr-community-channel/mdr-integrations-eap/b/announcements/posts/enabling...
    • 8 Sep 2022 3:06 PM
  • Using Live Discover to determine TPM enabled devices

    Tenchima
    Tenchima
    • Device
    • Complete on 7 Oct 2022
    • 3 Comments
    Does anyone know of a SQL Query format in the Designer Mode in Live Discover that will allow me to query all Windows devices to determine which online systems have a TPM module? Thanks. -Andy
    • 25 Aug 2022 10:31 PM
  • AWS Security Hub - Explore detections

    Karl_Ackerman
    Karl_Ackerman
    • NDR Queries
    • Approved on 25 Aug 2022
    • 0 Comments
    The query below requires you to have setup the AWS Security Hub Connector. See https://community.sophos.com/mdr-community-channel/mtr-connector-eap/b/announcements/posts/enabling-asw-security-hub-guard-duty-in-mdr for instructions. SQL -- VARIABLE...
    • 25 Aug 2022 3:19 PM
  • Query for Device Inventory

    Manny Singh
    Manny Singh
    • Device
    • Complete on 7 Oct 2022
    • 1 Comment
    Hi Team, Would it be possible to query the below details for device : 1. DNS Name /FQDN 2. Logged in (Domain ) 3. Last logged in user 4. IP address 5. Group 6. Status 7. Operating system and version 9. Last update 10. Status 11....
    • 13 Jul 2022 4:26 PM
<>