• Scanning for activity of IPv6 and NetBIOS

    Christopher Danby
    Christopher Danby
    • Network
    • Under Review on 9 May 2022
    • 1 Comment
    Hi, I am looking for a way to have a query to detect all activity of NetBIOS and IPv6. These two ports need to be disabled on all network devices so I am looking for a query I can run on a monthly basis to confirm these ports are disabled. From...
    • 9 May 2022 1:57 PM
  • Outbound SMB Traffic

    Albert Straniti
    Albert Straniti
    • Network
    • Approved on 18 May 2022
    • 1 Comment
    I am trying to determine what process is generating outbound SMB traffic on a system. I can see the traffic in the firewall logs, but when I use the query below, nothing comes up. It doesn't matter which system I check, or whether I use port 137 or 445...
    • 28 Apr 2022 5:08 PM
  • Yara rules not returning results

    Chris Smith4
    Chris Smith4
    • Threat Hunting
    • Under Review on 19 Apr 2022
    • 0 Comments
    Cannot get results back from online rules (based on this https://community.sophos.com/intercept-x-endpoint/b/blog/posts/yara-scanning-rules-with-sophos-xdr ) so tried the simplest osquery I could think of: SELECT * FROM yara WHERE path = 'c:\windows...
    • 19 Apr 2022 10:16 PM
  • Live Discover Query for all DNS requests in a time frame with process (ZTNA App discover)

    LuCar Toni
    LuCar Toni
    • Uncategorized
    • Approved on 4 Apr 2022
    • 0 Comments
    Hi Team, Here is a Live Discover Query for all DNS requests in a particular time frame from a device. You can use % for all processes or search for a particular process. -- DNS Lookups by Process -- $$Start Time$$ DATE -- $$End Time$$ DATE -- $$Process...
    • 4 Apr 2022 8:54 AM
  • show devices where exist a file with a specific hash

    Giulia Zambetti
    Giulia Zambetti
    • Files
    • Complete on 18 May 2022
    • 1 Comment
    Hello, I would like to know if it is possible to make a query to show devices where there is a specific file in the Data Lake. Thank you
    • 29 Mar 2022 12:41 PM
  • Query for MD5 hashes

    Abdullah Lababidi
    Abdullah Lababidi
    • Threat Hunting
    • Under Review on 23 Mar 2022
    • 3 Comments
    Hello, I would like suggestions regarding how to put together a query to find MD5 hashes. There is a built-in query called Processes matching SHA-256 hashes in the last 30 days (below), but I would like to search for MD5 hashes not SHA-256, since...
    • 23 Mar 2022 10:02 PM
  • Determine is device(s) are in EAP

    SpencerBrown
    SpencerBrown
    • Registry
    • Under Review on 11 Mar 2022
    • 1 Comment
    When a device is enrolled in Early Access, many of the Sophos service tags for registry keys go from RECOMMENDED to BETA. Upon reviewing the results of this query, if any devices return with "data" : "BETA" - those devices are in the early access program...
    • 11 Mar 2022 8:30 PM
  • Sophos EDR: Query that will show me all users and groups (including domain accounts) in the local Administrators group of a PC

    Matt Schmitt
    Matt Schmitt
    • User
    • Under Review on 17 Feb 2022
    • 3 Comments
    I want to see any users or groups that have been added to the Local Administrators group on a PC. Including domain users and groups. I've been looking at this post: https://community.sophos.com/intercept-x-endpoint/i/user/edr-query-to-find-all-local...
    • 17 Feb 2022 5:10 PM
  • Query to collect Serial Numbers of computers

    Christian Jake A Garduque
    Christian Jake A Garduque
    • Device
    • Approved on 20 Apr 2022
    • 2 Comments
    Can someone help me. I need collect serial numbers of computers with sophos agent installed.
    • 16 Feb 2022 12:28 AM
  • Querying Installed Version of Chrome?

    Lisa Busby
    Lisa Busby
    • Files
    • Complete on 18 May 2022
    • 1 Comment
    Hi All, Does anyone know of a way I can query to find the version of Chrome that is installed on an endpoint? Thanks.
    • 15 Feb 2022 8:56 PM
<>