• Cleaning AD of old Sophos installations

    Fred_B
    Fred_B
    We have used Sophos for a long time and as a result our Windows AD is littered with old Sophos users and groups that are no longer used. In the past we used Sophos SAV, Enterprise Library, Puremessage and SQL DB. Currently we use Sophos Central, Endpoint…
    • 2 months ago
    • Sophos Endpoint
    • Discussions
  • Alarm Naming Proposal for HMPA

    ong! L
    ong! L
    I recently discovered that HMPA blocking certain malicious behaviors can already trigger a Cleanup, and I have a suggestion to change the HMPA blocking prompts to be more aptly named based on the MITRE ATT&CK architecture, as in the behavioral defense…
    • 3 months ago
    • Sophos Endpoint
    • Discussions
  • Blocking Controlled Items Prompts for Problems

    ong! L
    ong! L
    Currently, there is no pop-up alert for blocking controlled items. Will the next version add a switch for this alert, just like the alert for found viruses?
    • 3 months ago
    • Sophos Endpoint
    • Discussions
  • Is there a technical specification for Malicious behavior protection?

    ong! L
    ong! L
    So far I can only find the name of its behavior separation, but I can't find any description of this technology https://docs.sophos.com/central/customer/help/zh-tw/ManageYourProducts/LogsReports/Logs/Events/MaliciousBehaviorTypes/index.html
    • 3 months ago
    • Sophos Endpoint
    • Discussions
  • Sophos connector not working for API integration to Sentinel

    Marcelo Indacocha
    Marcelo Indacocha
    I am trying to integrate Sophos Endpoint using the Sophos Endpoint Sentinel connector. I have already completed all the configuration steps but the events are not displayed in the Sentinel.
    • 3 months ago
    • Sophos Endpoint
    • Discussions
  • Como configurar un servidor Syslog para Sophos Endpoint | Sophos Intercept X

    NTM
    NTM
    Buenos Día comunidad, Alguien sabe si desde Sophos Central para todos mis equipos Finales donde tengo Sophos Intercept X puedo configurar syslog a un servidor del cliente para recolectar toda la información. La configuración ya la realicé desde…
    • 4 months ago
    • Sophos Endpoint
    • Discussions
  • Sophos AV Product with API Integration

    Amol Sh
    Amol Sh
    We have Java based microservice hosted on AWS ECS that accepts files from Customers, now we have need to scan files before its stored into perment storage. For that looking for an antivirus product with the capability to programmatically (via API or Java…
    • 4 months ago
    • Sophos Endpoint
    • Discussions
  • Formulate URL web link to detection

    AnnMarie Norcross
    AnnMarie Norcross
    I am writing an integration with Sophos EDR and I'd like to have a clickable link from our SOAR platform to a detection in Sophos. Is there a was to formulate this link or is it accessible via REST API? I'm looking for something like "{sophos-console…
    • 4 months ago
    • Sophos Endpoint
    • Discussions
  • Authenticator app QR code

    Bordeianu Daniel
    Bordeianu Daniel
    Hello. Have read about good detection rates on your engine and thought to check with Endpoint a possible ransomware/ransomware situation. First time user, yet to install the trial version, after the email and password are accepted, and that email code…
    • 5 months ago
    • Sophos Endpoint
    • Discussions
  • Sophos Intercept X for Citrix VDI

    Anishkumar C
    Anishkumar C
    Hi Team, We have a query in Sophos license allocation in Citrix VDI environment. How the licensing will work here for the sessions. So, we have a master image with Windows 11 operating system. Each users have a different session in the environment.…
    • 6 months ago
    • Sophos Endpoint
    • Discussions
  • ADSyncWarningEvent

    Alessandro Rosa
    Alessandro Rosa
    Hello, Since yesterday, I've been receiving an alert on my Central platform. The description states "ADSyncWarningEvent," with the suggested action being "Email Alert - Change frequency for 'ADSyncWarningEvent' email alerts. This will be added to your…
    • Answered
    • 8 months ago
    • Sophos Endpoint
    • Discussions
  • Sophos Endpoint EDR

    Bruno H Silva
    Bruno H Silva
    Dear, I need to implement an endpoint solution that has EDR. Which Sophos endpoint solution already includes this feature?
    • 8 months ago
    • Sophos Endpoint
    • Discussions
  • Export XDR / EDR data from Sophos intercept X to SIEM platform

    Jeremy Hughes
    Jeremy Hughes
    Hi, I need to be able to pull the telemetry from Sophos Intercept X into my SIEM. I am currently using the GitHub project linked below to pull alerts into the SIEM, but I need the raw telemetry. Is this possible yet? This is an old thread that was…
    • 10 months ago
    • Sophos Endpoint
    • Discussions
  • Connectwise RMM/ Sophos install Script

    Ronnie Barreto
    Ronnie Barreto
    Does anyone have a Script for ConnectWise RMM to install Sophos Endpoint? We have used some of the other legacy scripts and attempted to convert it to Connectwise RMM but have been unsuccessful.
    • Answered
    • 10 months ago
    • Sophos Endpoint
    • Discussions
  • Sophos Central- Pulling Threat Analysis Center logs via API

    Dogan Sonmez
    Dogan Sonmez
    We need to pull "Threat Analysis Center" logs via API. When we look at guides on sophos there are just "alert", "event" queries to pull events. Could you help us, please?
    • Answered
    • 10 months ago
    • Sophos Endpoint
    • Discussions
  • What is the difference between CIXH1CSAA and CIXA0U12AANCAA?

    Aung Thaw Thaw
    Aung Thaw Thaw
    I request Sophos Central Intercept X Advanced quotation from the distributor. First, they gave quotation with model number CIXH1CSAA and when I request discount for that our distributor gave us new quotation with new model number CIXA0U12AANCAA. I found…
    • 10 months ago
    • Sophos Endpoint
    • Discussions
  • [CXIA]How to handle Sophos ID and CXIA License Key binding error?

    archilife archilife
    archilife archilife
    Our group has multiple companies, including company A and company B. Three years ago, the Sophos local reseller mistakenly entered the Sophos ID of company B with the License Key purchased for company A. This resulted in the LICENSE SCHEDULE for company…
    • Answered
    • 11 months ago
    • Sophos Endpoint
    • Discussions
  • Active Directory Sync Setup "The LDAP server is unavailable"

    Gavin Renn
    Gavin Renn
    Hey guys, I am trying to set up Sophos AD Sync on a new domain controller (Windows Server 2022 Datacenter) and I keep getting the error "The LDAP server is unavailable". This happens regardless of LDAP with SSL or insecure connection on port 389, different…
    • 11 months ago
    • Sophos Endpoint
    • Discussions
  • HOW TO ACTIVATE EXTENDED SUPPORT LICENSE IN WINDOWS SERVER 2012 R2 /standard

    Faizan Tanveer
    Faizan Tanveer
    Customer is having 15 machines running windows server 2012 standard/R2 with sophos protection Intercept X advanced for server , But now he is moving towards extended support for new server 2012 machines and already deployed machines . Kindly guide us…
    • 11 months ago
    • Sophos Endpoint
    • Discussions
  • Downgrade from Intercept X Advanced with XDR to Intercept X Advanced

    Than Khar Meng
    Than Khar Meng
    Hi Team, I would like to downgrade from Intercept X Advanced with XDR to Intercept X Advanced due to our full license is in Intercept X Advanced as per image. I have tried to go Devices > Manage Endpoint Software but there is no Intercept X Advanced…
    • Answered
    • 11 months ago
    • Sophos Endpoint
    • Discussions
  • Not receiving new investigation mail notification anymore.

    Bastien Thunissen
    Bastien Thunissen
    Hello everyone, We are not receiving anymore the new investigation notification since 25-10-23 and we did no changed anything. I see that there is changes with case and investigation which is legacy now. We also checked in Threat analysis center …
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • "License is not valid - you are not licensed to install any products provided by this installer on this computer. Check your license usage in Sophos Central"

    ECGC Bhavan
    ECGC Bhavan
    "License is not valid - you are not licensed to install any products provided by this installer on this computer. Check your license usage in Sophos Central"
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • Unable to login to Sophos Central when I am logged into chrome browser

    Garry Kiely
    Garry Kiely
    I CAN login with Chrome browser that doesn't have Chrome account attached. However, I am in the process of organising bookmarks etc, and what to be able to access while logged into chrome
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • how to export report threat analysis graph

    Ahmad
    Ahmad
    hi, i have installed CIXA for server on one of server. on that server in threat analysis it is showing that threat is detecred I need to export report of Threat Analysis Center : threat Graph , please advise. please advise.
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • Email alerts for XDR detections

    Jonas Stadler
    Jonas Stadler
    Hello everyone, Is it possible to set up an email alert for high risk XDR detections (no MDR-costumer) ? I am talking about the detections in the "Threat Analysis Center". For example, I want to be informed if a risk 6 or higher detection was found…
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • View related content throughout Sophos Endpoint
  • More
  • Cancel
>