• mass-release from quarantine

    FFin
    FFin
    Hi all, i've got a false-positive outbreak detected on one fileserver. There're around 100 Items in Quarantine - alerts spread over 6 pages in Events-Section in central. i went through that list multiple times but was able to release 95 elements from…
    • 2 months ago
    • Sophos Central
    • Discussions
  • Editing exclusions leads to deletion - is this a known bug?

    Björn Vermöhlen
    Björn Vermöhlen
    Hi! I just found a bug in the Sophos Central dashboard and could not find it in the known issues list. Here's how to replicate the issue: 1. Create an exclusion of the type "Exploit mitigation", choose an application and deactivate at least one of…
    • Answered
    • 3 months ago
    • Sophos Central
    • Discussions
  • Sudden Increase in False Positives from Sophos Central — Need Immediate Assistance

    Anas Rez
    Anas Rez
    Recently, I've noticed a troubling increase in false positives from Sophos Central that are impacting our workflow significantly. Legitimate files and applications are being flagged as threats, causing unnecessary disruptions and delays. This issue seems…
    • 3 months ago
    • Sophos Central
    • Discussions
  • Protect network traffic blocks EWS service URL from within a program

    Jonas Havemann TimberTec GmbH
    Jonas Havemann TimberTec GmbH
    Hello, we have a problem with the feature “Protect network traffic”. We are using a terminal server, on which employees work with a program that uses EWS to send mails. We now have the problem that Sophos blocks the automatic login process via the…
    • 5 months ago
    • Sophos Central
    • Discussions
  • Safe Browsing has detected that the Microsoft Edge browser has been manipulated

    msw_fisit
    msw_fisit
    We have a terminal server running Sophos Intercept X Essentials. This now also reported a detected manipulation of the browser and provided corresponding information. How do you deal with this? Do you always report these reports to the Sophos team or…
    • 9 months ago
    • Sophos Central
    • Discussions
  • Sophos Central Policy Deep Scan logs

    Ali A
    Ali A
    I created a Threat Protection Policy and enabled Deep scan and Scheduled it for only one file server. Today, I'm trying to find the log of the scan and see if it deleted or quarantined anything. Where can I find this?
    • 10 months ago
    • Sophos Central
    • Discussions
  • IPS FILE-IMAGE Adobe Reader malformed app13 marker memory corruption attempt

    Louis Havenga
    Louis Havenga
    Good day members. I Trust you are well. Our IPS report on Sophos Central shows the following IPS report. I have Traced the IP back to microsoft Data center. I would like to know is this a false positive as i have scanned the computers muliple times…
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Block or log if user run any vba macro in office

    Onur Akcay
    Onur Akcay
    Hello, Is it possible to log or block if user tries to run any vba macro in office applications? Regards.
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Can't adding application

    Adam Guan
    Adam Guan
    Hi I want to adding a appliction on device SJ32ACC but its told me error adding application , and I allow by SHA256 & key applicaion used by most organisations , could you help me to fix this issue ,thx?
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Can PSTools be excluded for a single machine (for Sophos admin)?

    PaulC-SA
    PaulC-SA
    Just as the subject asks: Can PSTools be excluded for a single machine (for Sophos admin)? if so, how can I create that exclusion so that it's not alerting every time I try to download and install it? I don't want to create a global exclusion because…
    • Answered
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Real-Time Scan Exclusion Variable\WildCard Confirmation

    Yogi_Bear_79
    Yogi_Bear_79
    I want to exclude the following (example) from real-time scanning: This directory ( 26e9f183-6e80-4436-8461-a67d55c5e4b1) is randomized within the user's profile temp directory c:\Users\testuser\Temp\26e9f183-6e80-4436-8461-a67d55c5e4b1 These files…
    • Answered
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Exploit mitigation or ransomware wildcards and variables and using the "$" variable

    Slappy
    Slappy
    Anybody else tried using the "$" variable to exclude a filename and not work?? Looking at the article: Exploit mitigation or ransomware wildcards and variables - Sophos Central Admin Is says this: VariableExample $ All available drives. For…
    • Answered
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Enterprise Application Issue - Linked to recent maintenance ??

    SimonGoode
    SimonGoode
    We use a SaaS based ticketing system, this is an enterprise application with SSO login and we use this process for many other SaaS based applications. We've an issue today whereby users are unable to login to this SaaS ticketing system resulting in a…
    • Answered
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Has anyone seen a false flag for "WIN-CAC-NET-CONNECTION-NO-CMDLINE-1.star"

    bkatw0rk
    bkatw0rk
    I'm running into an issue where sophos flags dllhost.exe as suspicious because it runs with no command line arguments. That IS suspicious, my issue is that when I dug into it, that particular process ID it flags on my end does have a command line argument…
    • over 1 year ago
    • Sophos Central
    • Discussions
  • why do you disallow a comment for exploit mitigation exclusions?

    LHerzog
    LHerzog
    Hi, in our VoIP Client there is a ROP Detection. After searching, this is by Exploit detection engine. No I can set exclusions for a lot of things and I in all I checked, it is possible to make a comment like here: but for exploit mitigation…
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Sophos Endpoint Agent XDR & Siemens WinCC V7.x

    Thomas_LSW
    Thomas_LSW
    Hi community, Sophos Central has not been approved by Siemens WinCC V7.x ! I am forced to install Sophos Endpoint Agent on such Servers anyway. What are the recommended global exclusions from Sophos for such Servers, and above all which exclusion…
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Onenote false positives in Google Drive File Stream files stored locally on machines being detected

    Marvin Mathieu
    Marvin Mathieu
    I have been having an issue with Onenote files being detected as false positives and to prevent half of the detections from happening, I excluded all onenote files with the file extensions *.onepkg and *.one.backupconsctruction globally regardless of…
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Does Sophos can block Rorschach ransomware?

    TimChen
    TimChen
    Does Sophos can block Rorschach ransomware? www.trendmicro.com/.../an-analysis-of-the-bablock-ransomware.html
    • over 1 year ago
    • Sophos Central
    • Discussions
  • How can I exclude a false positive for onepkg files if the Hash and Path is different for each user?

    Marvin Mathieu
    Marvin Mathieu
    Apr 17, 2023 8:19 PM Manual malware cleanup required: 'Mal/OneBad-A' at 'C:\Users\greg_peterson\Downloads\Augustin MaryAnne 302642.onepkg' How can I effectively exclude onepkg false positives across my organization when the path and hash…
    • over 1 year ago
    • Sophos Central
    • Discussions
  • How to detect Microsoft Office documents spawning processes?

    Bill Elkin
    Bill Elkin
    How to detect Microsoft Office documents spawning processes? Such as: PowerShell CMD WMI MSHTA Etc.
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Using LogMeIn Rescue Generates an Investigation

    Matt Schmitt
    Matt Schmitt
    I use LogMeIn Rescue to support remote PCs. Last week, Sophos EDR has started generating an Investigation after each use. Has anyone else seen this of have any insignt? Initial Detection: WIN-MITRE-Behavioral-TA0005-T1562.009 Risk 6 Category:…
    • Answered
    • over 2 years ago
    • Sophos Central
    • Discussions
  • Sophos Central - False positive - Connectwise Screenconnect - a Thoma Bravo Company - Same as Sophos

    Dennis Jones
    Dennis Jones
    Good morning (NZ Time) We are an IT support business We use connectwis's screenconnect product to remotely support all of our clients, and have done for 6 years. From Yesterday afternoon (NZ Time) our Sophos Central alerts are going off with the below…
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Adaptive Active Adversary Protection

    Laureen Hart
    Laureen Hart
    From this morning's New Innovations email: "Adaptive Active Adversary Protection temporarily puts the impacted device into a more aggressive security mode that disrupts and delays the attacker by automatically blocking a wide range of activities that…
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Allow access to uncategorised Wi-Fi network splash screen logons

    David Rowan
    David Rowan
    We have an issue where if our users want to use a Hotel, Conference Centre, or Airport Lounge’s Wi-Fi they can’t because the Wi-Fi network’s internal logon splash screen is blocked as ‘Uncategorised’ by SOPHOS Central Web Protection and we don’t allow…
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Allow Applications

    ab awal
    ab awal
    I want to allow an application which are detected with Sophos central, but in the event details tab is not showing allow applications option. even though when I allow the detected path from global settings allow applications then the application is not…
    • over 1 year ago
    • Sophos Central
    • Discussions
  • View related content throughout Sophos Central
  • More
  • Cancel
>