• How can I search for a HASH list with live discover?

    Raul Manteca Fernandez
    Raul Manteca Fernandez
    Hello. I´m trying to create a query that allows me to check if a HASH from a list (with a comma separated) is located on some device. The problem I have when consulting the hash table is that it does not show me any value if I do not define a directory…
    • Answered
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • How to use ""File attributes and metadata" to find a file anywhere on a computer?

    Hyujfnr16
    Hyujfnr16
    Hello! How can I use the Live Discover query called "File attributes and metadata" to locate a file that might be stored at any place on a computer, or at different places on different computers? This article on Sophos.com got me to thinking. They suggest…
    • over 2 years ago
    • Sophos Endpoint
    • Files
  • [LiveDiscoverHelp] "Retrieve the list of the installed non Microsoft software version"

    Mohamed Amine EL Jaouhari
    Mohamed Amine EL Jaouhari
    Hi Team, Community, Could you help to share a query allowing to retrieve the list of the installed non Microsoft software version ? thank you so much in advance
    • Answered
    • over 3 years ago
    • Sophos Endpoint
    • Discussions
  • Query for System Reboots/Shutdowns

    JeramyKopacko
    JeramyKopacko
    Posted this for easier access as I am sharing it with another community user who looked for this functionality: SELECT DISTINCT eventid, CASE eventid WHEN '41' THEN 'Rebooted without clean shutdown' WHEN '1074' THEN 'Shutdown properly by user…
    • over 3 years ago
    • Sophos Endpoint
    • Events
  • Live Discover for Parent_Sophos_PID without result - how can that be?

    LHerzog
    LHerzog
    Im trying to get the root process for an event on a client currently offline. Using Data Lake query. However, the Parent PID Search gives no results.The Event is 14 days old. I thought the Sophos PID is THE idicator of something in the Data Lake - how…
    • Answered
    • over 3 years ago
    • Sophos Endpoint
    • Discussions
  • Live Discover Query to identify application trying to access specific remote port

    Tiago Bianchini1
    Tiago Bianchini1
    Hi I want to detect what program in a Windows PC with Sophos Endpoint is trying to access a service running at a specific port in other equipament in my network. Its possible to do that with at Sophos Central, with Live Discovery?
    • over 3 years ago
    • Sophos Endpoint
    • Discussions
  • Live Discover Sophos Product Updates - in particular NTP: Network Threat Protection

    LHerzog
    LHerzog
    Today Sophos is pushing new updates to NTP Engine, causing short outages on every computer. This produces some ammount of calls in our helpdesk and I'd like to run a query in Live Discover about computers that have received the update. This would…
    • Answered
    • over 3 years ago
    • Sophos Endpoint
    • Discussions
  • OMIGOD Vulnerability | OMI version check

    Jainidhya Rajpal
    Jainidhya Rajpal
    SELECT CASE WHEN version = '1.6.8.1' THEN 'OMI is Updated' ELSE 'Update OMI to 1.6.8.1' END AS OMIGODVersionCheck, name, version, release, source, sha1, arch FROM rpm_packages WHERE name = 'omi' UNION ALL SELECT CASE …
    • over 3 years ago
    • Sophos Endpoint
    • Device
  • Retrieve Folder Size

    Connor Rosenthal
    Connor Rosenthal
    I know you can get data back from files but is there a way to modify the OSQuery to get folder or directory information. Wanter to get Desktop and Document size. and convert if possible to MB.
    • over 3 years ago
    • Sophos Endpoint
    • Files
  • FORCEDENTRY Big Sur 11.6 Version Check

    Jainidhya Rajpal
    Jainidhya Rajpal
    SELECT CASE WHEN version = '11.6' THEN 'Not Vulnerable to FORCEDENTRY' ELSE 'Vulnerable | Upgrade to 11.6' END AS BigSurCheck FROM os_version WHERE major = '11'
    • over 3 years ago
    • Sophos Endpoint
    • Threat Hunting
  • FORCEDENTRY Safari Check (CATALINA & MOJAVE)

    Jainidhya Rajpal
    Jainidhya Rajpal
    SELECT CASE WHEN bundle_short_version = '14.1.2' THEN 'PATCHED' ELSE 'Vulnerable to FORCEDENTRY' END AS VulnCheck FROM apps WHERE name = 'Safari.app'
    • over 3 years ago
    • Sophos Endpoint
    • Threat Hunting
  • Check Confluence Version to confirm Patch - Confluence Server Webwork OGNL injection (CVE-2021-26084)

    RaviSoni
    RaviSoni
    This query will check the installed version of Confluence and print the message IF the installed confluence version is PATCHED or NOT PATCHED. SELECT DISTINCT 'Check Confluence Version to confirm Patch' Test, CASE version WHEN '6.13.23' THEN…
    • over 3 years ago
    • Sophos Endpoint
    • Discussions
  • Query - IOC´s From GitHub list

    Rafael Moura
    Rafael Moura
    /* Desc: Number of Hours of activity to search / TYPE: String / SQLVAR: $$Number of Hours of activity to search$$ Desc: RAW IOC List location from a URL / TYPE: String / SQLVAR: $$RAW IOC List location from a URL$$ / Value: ... Desc: Start Search From…
    • over 3 years ago
    • Sophos Endpoint
    • Threat Hunting
  • Using XDR for Discovering Unsupported Software

    JeramyKopacko
    JeramyKopacko
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Table of Contents Introduction Goals Prerequisites Check…
    • over 3 years ago
    • Sophos Endpoint
    • Recommended Reads
  • Compare Specific Program Version

    JeramyKopacko
    JeramyKopacko
    This query is leveraged in our recommended read to assist in auditing unsupported software. Credit to Jainidhya for assembling this little beauty. Set variable as $$Version$$ with type 'string' and another variable as $$Name$$ with type 'string' Once…
    • over 3 years ago
    • Sophos Endpoint
    • Device
  • T1078 - CVE-2020-1472 - Netlogon

    JeramyKopacko
    JeramyKopacko
    This is an older vulnerability but still nice to showcase the capabilities of how XDR can discover CVEs. This query will search and detect Windows vulnerability affecting the Netlogon feature. Sophos Security Bulletin: https://community.sophos.com…
    • over 3 years ago
    • Sophos Endpoint
    • Threat Hunting
  • Receiving ACL for SAM file not working

    Dennis Barnekow
    Dennis Barnekow
    Hi, I created this query to check which of our systems are effected by serious SAM vulnerability. When I fire the query I not receive any data back. Does someone know what I did wrong? SELECT * FROM ntfs_acl_permissions WHERE path like 'C:\Windows…
    • over 3 years ago
    • Sophos Endpoint
    • Threat Hunting
  • HiveNightmare aka SeriousSAM vulnerability query

    SecBug
    SecBug
    The Live Discover query below, from Sophos MTR, will identify processes that have accessed either the SAM, SECURITY, or SYSTEM Registry hive files in Shadow volumes. It is optimized to minimize the number of accesses to the Sophos File Journal to enable…
    • over 3 years ago
    • Sophos Endpoint
    • Threat Hunting
  • Query who has modified an Active Directory object

    Dennis Franz1
    Dennis Franz1
    Hello, I am not sure if I am in the right place here. We need a query who changed an Active Directory object. E.g. who disabled or enabled a computer in AD. There are queries for user objects but I haven't found any for computer objects. Can…
    • over 3 years ago
    • Sophos Endpoint
    • Compliance
  • Checking For Print Spooler Vulnerabilities

    JeramyKopacko
    JeramyKopacko
    This query will search your endpoints for the following CVEs and their currently released patches: 2021-1675, 2021-34527, and 2021-34481. As of writing this, CVE-2021-34481 is considered still vulnerable and the recommended fix is to disable the print…
    • over 3 years ago
    • Sophos Endpoint
    • Threat Hunting
  • SeriousSam/HiveNightmare Hunting Query (Live Endpoint)

    reg1nleifr
    reg1nleifr
    Hunting Query we've used for detecting suspicious processes exploiting the SeriousSAM Vulnerability. Depending on your environment you might see plenty false positives. A good idea might be to add valid processes to the query based on the sha256 value…
    • over 3 years ago
    • Sophos Endpoint
    • Threat Hunting
  • Ability to view URL's (warn, block) using EDR

    RaviSoni
    RaviSoni
    This query will parse the Web Intelligence log files and display the URL's that users have visited or have attempted to visit, Category of the URL, Action was taken etc. This gives a rough idea of what users have visited on a specific date. Declare…
    • over 3 years ago
    • Sophos Endpoint
    • Compliance
  • Check IP Journal against File Properties & Processes

    JeramyKopacko
    JeramyKopacko
    It may be useful to see what specific PID, program, syntax, etc and its threat scoring that has interacted with a specific IP. This is the final query from the Getting Started Recommended Read shared recently. ## DEFINE $$IPaddress$$ as IPaddress …
    • over 3 years ago
    • Sophos Endpoint
    • Threat Hunting
  • Getting Started In Live Discover - From Beginner to Advanced Query Creation

    JeramyKopacko
    JeramyKopacko
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Table of Contents Background Prerequisites Guide Intro…
    • over 3 years ago
    • Sophos Endpoint
    • Recommended Reads
  • Printnightmare Hunting Query (Live Discovery/Windows)

    reg1nleifr
    reg1nleifr
    Similar to the Data Lake Query (which seems to be having issues since it's not detecting all dll files in all folders) we've also created a Live-Discovery Query for Windows Systems on the Printnightmare Vulnerability. The Query could be scheduled via…
    • over 3 years ago
    • Sophos Endpoint
    • Threat Hunting
  • View related content from anywhere
  • More
  • Cancel
<>