• PaperCut Activity Hunt

    JeramyKopacko
    JeramyKopacko
    This is sourced directly from Sophos MDR: Increased exploitation of PaperCut drawing blood around the Internet – Sophos News PaperCut IoC List: IoCs/papercut-nday-indicators-of-compromise.csv at master · sophoslabs/IoCs · GitHub SELECT date_format…
    • over 1 year ago
    • Sophos Endpoint
    • Data Lake
  • Sophos ZTNA – v2.0.2 is now available

    Tejas Kashyap
    Tejas Kashyap
    [Update: 17th May] A new release, Version 2.0.2, is now available. It addresses the problem with gateway upgrades that was previously reported. Overview Today, the ZTNA team is pleased to announce the general availability of Sophos ZTNA v2.0.2.…
    • over 1 year ago
    • Zero Trust Network Access
    • Announcements
  • 3CX users under DLL-sideloading attack

    FrasianX0
    FrasianX0
    Trying to run the latest 3CX; however receiving this error: f inished - errors - no such table: xdr_data SELECT meta_hostname, sophos_pids, domain, clean_urls, source_ips, destination_ips, timestamps, ingestion_timestamp FROM xdr_data…
    • Answered
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • [QueryCorner][March2023] Deep Diving into OneNote Attacks

    JeramyKopacko
    JeramyKopacko
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Index Purpose Prerequisites Query #1 - Live Discover - Check…
    • over 1 year ago
    • Sophos Endpoint
    • Recommended Reads
  • [QueryCorner][February2023] Data Lake - Sophos Firewall: Threat Hunting Dropped Logs

    JeramyKopacko
    JeramyKopacko
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Purpose Sophos Firewall uses firewall rule ID "0" in your log viewer…
    • over 1 year ago
    • Sophos Endpoint
    • Recommended Reads
  • [QueryCorner][February2023] Data Lake - Sophos Firewall: Port Scanning Detections

    JeramyKopacko
    JeramyKopacko
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Purpose Sophos Community has amassed an incredible catalog of queries…
    • over 1 year ago
    • Sophos Endpoint
    • Recommended Reads
  • [QueryCorner][February2023] Data Lake - Device: Pending Windows/Mac Updates

    JeramyKopacko
    JeramyKopacko
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Purpose If you have not traversed the XDR journals, please review…
    • over 1 year ago
    • Sophos Endpoint
    • Recommended Reads
  • PowerShell script to migrate Sophos endpoint protection from current Sophos Central to new Sophos Central

    IsmailJaweed
    IsmailJaweed
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Overview This article describes how to create a PowerShell script…
    • over 1 year ago
    • Sophos Endpoint
    • Recommended Reads
  • [QueryCorner][January2023] Live Discover - Network: Processes with an open network connection

    JeramyKopacko
    JeramyKopacko
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Purpose If you have not traversed the XDR journals, please review…
    • over 1 year ago
    • Sophos Endpoint
    • Recommended Reads
  • Sophos Endpoint

    enemy1337
    enemy1337
    Guys, I have a doubt. there is no more sophos product for endpoint with EDR? XDR only?
    • Answered
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • [QueryCorner][October2022] Audit Application Control

    JeramyKopacko
    JeramyKopacko
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Purpose Sophos Endpoint and Server products all come equipped with…
    • over 2 years ago
    • Sophos Endpoint
    • Recommended Reads
  • [QueryCorner][October2022] Deep Diving into Windows Firewall

    JeramyKopacko
    JeramyKopacko
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Purpose The Windows Firewall is a security component to help protect…
    • over 2 years ago
    • Sophos Endpoint
    • Recommended Reads
  • [QueryCorner][September2022] Live Discover - Program Execution Evidence

    JeramyKopacko
    JeramyKopacko
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Purpose This query is taken directly from the Sophos Rapid Response…
    • over 2 years ago
    • Sophos Endpoint
    • Recommended Reads
  • [QueryCorner][September2022] Data Lake - IOC Hunting

    JeramyKopacko
    JeramyKopacko
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Purpose The Great Karl_Ackerman put this query together to provide…
    • over 2 years ago
    • Sophos Endpoint
    • Recommended Reads
  • [QueryCorner][August2022] Live Response - Five Basics for Windows

    JeramyKopacko
    JeramyKopacko
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Purpose This post is to highlight response actions that an operator…
    • over 2 years ago
    • Sophos Endpoint
    • Recommended Reads
  • SIEM integration API

    Luca Comellini
    Luca Comellini
    The script siem.py is very useful to retrieve alerts and actions on Sophos Central, but it is unable to collect data from XDR. Is it possible to "empower" it to read XDR data? SIEM would have a complete visibility on activities done on the infrastructure…
    • over 2 years ago
    • Sophos Central API
    • Discussions
  • Detections/Investigations API

    kevin robertson
    kevin robertson
    Hi there, Has anyone managed to construct API queries to pull out Detections/Investigations from Sophos XDR at all? We want these to be pushed into our ticketing platform as they are generated (or fetch them every 5 mins etc.) but I can't find any…
    • over 2 years ago
    • Sophos Central API
    • Discussions
  • [QueryCorner][August2022] Deep Diving Into RDP

    JeramyKopacko
    JeramyKopacko
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Purpose Often, Remote Desktop Protocol (RDP) sessions are used…
    • over 2 years ago
    • Sophos Endpoint
    • Recommended Reads
  • [QueryCorner][August2022] Live Discover - IOC Hunting

    JeramyKopacko
    JeramyKopacko
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Purpose Let's revisit a query written by Kyle Seike - post can…
    • over 2 years ago
    • Sophos Endpoint
    • Recommended Reads
  • [QueryCorner][July2022] Windows PCI Audit Report

    JeramyKopacko
    JeramyKopacko
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Purpose This query is designed to give you information required…
    • over 2 years ago
    • Sophos Endpoint
    • Recommended Reads
  • [QueryCorner][July2022] Live Discover Device Card - MacOS

    JeramyKopacko
    JeramyKopacko
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Purpose This query is designed to give you a "Total Report" of…
    • over 2 years ago
    • Sophos Endpoint
    • Recommended Reads
  • [QueryCorner][June2022] Data Lake Device Card - Windows

    JeramyKopacko
    JeramyKopacko
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Purpose This query is designed to give you a "Total Report" of…
    • over 2 years ago
    • Sophos Endpoint
    • Recommended Reads
  • New on the Secure Block

    DeanCTS
    DeanCTS
    Hey everyone, happy to be a part of this nice community. I decided to register an account as I've lurked around a fair share and actually am employed by Sophos Partner company. Looking for some recommendations on EDR / XDR with primary focus being the…
    • over 2 years ago
    • Community Chat
    • Discussions
  • Getting Started With Sophos Live Discover Design Mode

    JeramyKopacko
    JeramyKopacko
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Overview This post is going to cover setting up a user created…
    • over 2 years ago
    • Sophos Endpoint
    • Recommended Reads
  • Query Corner Announcement and Master Index

    JeramyKopacko
    JeramyKopacko
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Overview Here at Sophos, we launched EDR into the endpoint platform…
    • over 2 years ago
    • Sophos Endpoint
    • Recommended Reads
<>