• Windows11InstallationAssistant

    Sampre
    Sampre
    Hey I need to check here if the Windows11InstallationAssistant has been realsed as i can not see that in our central portal? Thank you
    • Answered
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • CryptoGuard Ransomware Detection

    kheir fernandez
    kheir fernandez
    Hey folks, Does anybody know how and what triggers ransomware attack detection? We have a process via batch script and it calls for GPG.exe encryption on the files. This process are executed via remote workstation, and the target files are from our…
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Delete remote windows

    Angel Diaz
    Angel Diaz
    With Sophos endpoint I can wipe a computer remotely
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Intentionally Block USB Mouse and Keyboard

    Administrator User579
    Administrator User579
    I want to intentionally block a USB Mouse and Keyboard from being plugged in but I don't have the ability to yet. This needs to be a feature that is included in the Peripheral settings of Endpoint Protection
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Feature Request

    Administrator User579
    Administrator User579
    I would like the ability to block USB Mouse and Keyboards using the Peripheral Settings in Endpoint Protection.
    • Answered
    • over 2 years ago
    • Community Chat
    • Discussions
  • Query to know if a user with Central device encryption has configured his password

    Migue
    Migue
    Query to know if a user with Central device encryption has configured his password. I need your help if someone knows how to obtain that information through XDR by a query, we need to know how many computers do not have the password configured in bitlocker…
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • BitLocker blocked : file FVE2.{e40ad34d-dae9-4bc7-95bd-b16218c10f72}.1 blocked

    Kader-Mtl
    Kader-Mtl
    Hi There, I'm trying to activate BitLocker on USB key, but Sophos Central block the transfert of the file : FVE2.{e40ad34d-dae9-4bc7-95bd-b16218c10f72}.1 As you can see in the screen shot I created a rule in DLP to allow transfert to USB …
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Exe files (*.exe, *.bat, *.com, ...) should not be executed on an external drive

    osrsem keram
    osrsem keram
    Hello, We're using Sophos Central Intercept X in our domain, and would like to add a policy that will prevent our users from running or copying files from external drives, e.g . USB drives. Our goal is to go one step further: we want to create such…
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Intercept X advanced for Server with Tamper Protection Disabled when installed

    Kayode_Odeyinka
    Kayode_Odeyinka
    Hi Team, Kindly assist. I uninstalled and reinstalled a Sophos Intercept X Advanced agent on a Domain Controller but then on the reinstall the Settings tab on the Agent dashboard on the DC is enabled though the features were grayed out (the disabled…
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Sophos Exclusion Questions

    Lance Boon
    Lance Boon
    According to Sophos KB-000035264 support.sophos.com/.../KB-000035264 it states the following "By default, Sophos Central automatically uses vendor-recommended exclusions for certain widely-used applications. You can also set up your own exclusions in…
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Firewall Necessary?

    Louis Toscano1
    Louis Toscano1
    One of your moderators recommended that I remove Sophos Endpoint Security and replace it with Sophos Home. Can someone recommend a firewall; or is that unnecessary? Besides the old Sophos, I replaced Spywareblaster with Spybot. Thank you. I just want…
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • DOWNGRADE INTERCEPT X

    Chika Obiefule
    Chika Obiefule
    Is it possible to downgrade the sophos intercept x version? Having issues with forcepoint endpoint classifier.
    • Answered
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Sophos Central - How i can recovery data when OS corrupted.

    VanCuongNguyen User
    VanCuongNguyen User
    Hi Every one, My company just moved to Sophos Central to encrypt data. I was try find answer to questtion : when OS corrupted how i can recovery data in hard drive. Sure i'm known method is take hard drive and put in hdd box and using Recovery Key…
    • over 2 years ago
    • Sophos Central
    • Discussions
  • Query for missing default shares

    JeramyKopacko
    JeramyKopacko
    This query for create a virtual table from a URL file with defined CSVs. For this, we're going to look for missing default shares in Windows. As Microsoft indicates here, it can lead to various problems in the environment and in recent reports, it is…
    • over 2 years ago
    • Sophos Endpoint
    • Threat Hunting
  • Discover Google Chrome Browsers with Latest Zero Day

    JeramyKopacko
    JeramyKopacko
    SELECT meta_hostname AS Endpoint, MAX(CASE WHEN name = 'Google Chrome' THEN version END) AS Chrome FROM xdr_data WHERE query_name = 'windows_programs' and version != '96.0.4664.110' GROUP BY meta_hostname Google's full release of the CVE…
    • over 2 years ago
    • Sophos Endpoint
    • Data Lake
  • Can we create a policy in intune to identify Sophos as an antivirus and not make my systems non compliant

    Rizwan Ali
    Rizwan Ali
    Hi All i have been pushing the installation of Sophos endpoint protection on endpoints using intune. however they appear as non compliant on antivirus policy. i am need help. Regards Rizwan
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Basic search to find Log4J running on hosts from the DataLake

    CraigJones
    CraigJones
    Basic search which lists processes that include log4j in the cmdline> on Windows, Mac and Linux. The query returns a lot of results but works for an insight into what's running on the estate. SELECT meta_hostname AS ep_name, name, cmdline, path…
    • over 2 years ago
    • Sophos Endpoint
    • Compliance
  • [LiveDiscoverHelp] "Retrieve the list of the installed non Microsoft software version"

    Mohamed Amine EL Jaouhari
    Mohamed Amine EL Jaouhari
    Hi Team, Community, Could you help to share a query allowing to retrieve the list of the installed non Microsoft software version ? thank you so much in advance
    • Answered
    • over 3 years ago
    • Sophos Endpoint
    • Discussions
  • Reinstall Sophos EP with installer from another central account

    UTMaddict
    UTMaddict
    Hello, what happens if I reinstall Sophos EP with an installer from another central account (the Central accounts are not connected in any way)? I "simply" want to use a Sophos EP from another Central account. Regards UTMaddict
    • Answered
    • over 3 years ago
    • Sophos Central
    • Discussions
  • Query for System Reboots/Shutdowns

    JeramyKopacko
    JeramyKopacko
    Posted this for easier access as I am sharing it with another community user who looked for this functionality: SELECT DISTINCT eventid, CASE eventid WHEN '41' THEN 'Rebooted without clean shutdown' WHEN '1074' THEN 'Shutdown properly by user…
    • over 3 years ago
    • Sophos Endpoint
    • Events
  • Sophos endpoint stopping multiple pdf creations

    PeteH
    PeteH
    hi, We have recently installed endpoint on a site but we have a user who does payroll and sophos is blocking when they export / create multiple pdfs in one go. A couple work then it comes up with an error saying the process cant complete as the xxxx…
    • over 3 years ago
    • Sophos Endpoint
    • Discussions
  • Sophos Web Intelligence service high CPU

    Jo Vanattenhoven
    Jo Vanattenhoven
    Dear, one of our users is complaining that the Sophos Web Intelligence service is having a high CPU (around 40%-45%). He'll launch a scan, to be sure, later. But does anybody has an idea why this can happen and what we can do to solve this? Jo
    • over 3 years ago
    • Sophos Endpoint
    • Discussions
  • Sophos Endpoint/InterceptX File Scanner Service frequent stop

    Marco Bartholomew
    Marco Bartholomew
    We use Endpoint/InterceptX and have had the occasional Sophos File Scanner Service stopped issue, but never to the extent we are now. It's been picking up in frequency and today between myself and other IT team member we've had to restart the service…
    • Answered
    • over 3 years ago
    • Sophos Endpoint
    • Discussions
  • Query for CVE-2021-40444 MSHTML Process Event

    JeramyKopacko
    JeramyKopacko
    This query will look for a process event that has been associated with this attack. WinWord.exe has launched a child process called "control.exe" and has been seen in the wild with this vulnerability. This does NOT guarantee you've been breached but…
    • over 3 years ago
    • Sophos Endpoint
    • Threat Hunting
  • Query if CVE-2021-40444 MSHTML Mitigations Are Applied

    JeramyKopacko
    JeramyKopacko
    The current vulnerability CVE-2021-40444 MSHTML is a zero-day and is awaiting a patch. You should consider the Microsoft guidance in their Security Update Guide: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444 This query will…
    • over 3 years ago
    • Sophos Endpoint
    • Threat Hunting
<>