• ChatGPT file uploading does not work due to Sophos EndPoint

    Rafael Telles
    Rafael Telles
    I have been using Sophos EndPoint for about 3 years and using ChatGPT for about a year. Everything has been working fine until about 4 to 6 weeks ago when all of the sudden staff in our office cannot upload files to ChatGPT. I wasn't sure what is was…
    • 1 month ago
    • Sophos Endpoint
    • Discussions
  • Endpoint performance recommendations?

    David Kucera
    David Kucera
    Hi, we are a new partner coming from an ESET ecosystem, looking to replace it with Sophos for our customers, since we are using XGS and it makes sense to integrate Endpoint as well. While testing Intercept X in our environment first, my developers…
    • 2 months ago
    • Sophos Endpoint
    • Discussions
  • Threat Protection - how to trust a file?

    Michael Wallis
    Michael Wallis
    Hi, We have a Sophos Intercept-X user that has problems running End of Month reports via Excel in a certain CRM application. He is the only user requiring this functionality. We have tracked the issue down to being a .XLL (I assume that is an Excel…
    • 2 months ago
    • Sophos Endpoint
    • Discussions
  • File control by extension

    Alves
    Alves
    Hi guys, Is it possible to block certain files when they are executed? For example, block all .EXE files when they are clicked
    • Answered
    • 3 months ago
    • Sophos Endpoint
    • Discussions
  • How to safely operate a developer-friendly loose policy?

    Yohei Ikata
    Yohei Ikata
    What is your company's policy regarding the operation of endpoint protection for software developers? I like Sophos Endpoint Protection, but the software developer environment is a headache. Our anti-threat policy has been so badly written that exceptions…
    • 5 months ago
    • Sophos Endpoint
    • Discussions
  • Malicious behavior ('Lockdown') prevented

    Andreas Sandner
    Andreas Sandner
    Hello, recently we've had multiple issues that Intercept X prevented installation or execution of software because it suposedly prevented "Lockdown". It likes to block our remote maintainance software because of this, and today I was unable to install…
    • 5 months ago
    • Sophos Endpoint
    • Discussions
  • Filescanner exceptions for network drives

    LHerzog
    LHerzog
    We need to exclude some files from Sophos File Scanner on network drives. Lets say we have mapped drive N:\ with \\server1\share1 I tested access and logged with procmon and SFS debug logs, what is scanned, when opening N:\file1 I can see \\server1…
    • 7 months ago
    • Sophos Endpoint
    • Discussions
  • Sophos InterceptX Advanced EP

    Nyein Chan Zaw
    Nyein Chan Zaw
    Hi all, I would like to know onething Sophos InterceptX Advanced EP can do skip scanning below these. > Some folders/files in server : if don’t want to scan.(File type is x.raw and other proprietary formats).
    • 6 months ago
    • Sophos Endpoint
    • Discussions
  • File/Folder-Exclusion-Rule for multiple filetypes in specific directory

    N_M
    N_M
    Hello, i would like to add a File-Exclusion rule for multiple filetypes and one specific path. Do i need to add multiple exclusions for each filetype or can i just create one rule for all? Here is an example: "C:\Test\Folder\*.txt,*.zip,*.abc…
    • Answered
    • 6 months ago
    • Sophos Endpoint
    • Discussions
  • how to exclude application from HMPA DLLHijackGuard

    LHerzog
    LHerzog
    We have an application that is found safe from Sophos Labs Team. How would I exclude it in Central? I have disabled all features on the endpoint as a test and it is still detected. Excluded the process path. No luck. Mitigation DLLHijack Policy…
    • Answered
    • 7 months ago
    • Sophos Endpoint
    • Discussions
  • Endpoint Detection Exclusion Query

    ptho
    ptho
    Hi Sophos, We are receiving what we believe to be false positives with a piece of software at use in our ogranisation. This software is triggering an event on the affected device for 'DynamicShellcode'. I understand that I can go to this device…
    • 7 months ago
    • Sophos Endpoint
    • Discussions
  • Sophos Intercept X Advanced - Bankingsoftware langsam

    Christian Niemann
    Christian Niemann
    Hallo Zusammen, hat jemand von euch Erfahrung mit dem Einsatz von Sophos Endpoint und Proficash? diese Bankingsoftware ist bei aktiven Endpoint schutz sehr langsam. Wenn die Policy's im Endpoint alle deaktiviert werden ist die Software wieder schnell…
    • 9 months ago
    • Sophos Endpoint
    • Discussions
  • Disable automatic cleanup of PUA

    Lukas_lzs
    Lukas_lzs
    Hey there. I know this question has been asked a few years back, but i hope there is an update to this. I deployed Sophos CIXA on my PC and it started automatically deleting some of my trusted software i use as a network technician. The files…
    • Answered
    • 10 months ago
    • Sophos Endpoint
    • Discussions
  • Is it possible to exclude a process from data lake detections?

    Travis_Dadmin
    Travis_Dadmin
    Good morning, We use Faronics Deep Freeze in our environment on shared-use PCs in classrooms and computer labs. We are experimenting with turning on data lake uploads to start using the threat analysis center, and the Deep Freeze detections are very…
    • Answered
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • Network threat Protection - Blocking PowerShell Login to MS Compliance search via the Localhost browser address

    jp_2006
    jp_2006
    Open Powershell 7 Connect-IPPSSession -UserPrincipalName User@domain.com MS login processes starts by trying to open a browser window with a local host address and a random port. The connection is refused and the login process to MS stops localhost…
    • Answered
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • Hollow Process and VMware ThinApp

    Michal Talman CZ
    Michal Talman CZ
    Hi, I have an application created using VMware ThinnApp. Something like a portable application. The last few days I have been getting the application blocked on HollowProcess. Unfortunately the application is quite important for me and I need to run…
    • Answered
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • Mal/HTMLGen-A

    Avijit Maity
    Avijit Maity
    One of our user has " Outbreak detected " report due to the following domain access. does this site really have any issue or this is an wrong detectection, as much as I can see it blocked image files only ? if no how sophos going to resolve it? https…
    • Answered
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • Endpoint Protection not applying global exclusions

    TheDrew2022
    TheDrew2022
    Evening, I recently came across an issue I can't figure out how to resolve. We have an add-in for Excel that causes Sophos Endpoint to kill the program with a "StackExec" (MemProt) exploit prevented in Excel. Up until now we've just added the detection…
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • How to reduce Stack Exec detections

    Daina McFarlane
    Daina McFarlane
    Recently we noticed that we are receiving over five detections on a given day for Stack Exec . The threat graph for all detections are identical with the root cause been Microsoft Office 2016. The reputation for Microsoft Office is good and the file is…
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • Question for in-house made Python script

    Jo Vanattenhoven
    Jo Vanattenhoven
    Hello everyone, I have a question. Some of your users needs to run a Python script (through VBA, command prompt or Python prompt). At the moment it gets blocked by Sophos. What's the best way to tackle this problem and allow this script to be run? …
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • How can we comment a exclusion in a Threat Protection Policie?

    Marcel Saggau
    Marcel Saggau
    We want to use a comment function in a "normal" Policie. If we click on "Add Exclusion" there is no field to comment something.
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • 'APCViolation' exploit prevented in crystal16

    Parag Shukla
    Parag Shukla
    Hi Team, We have some systems where Sophos clients are running and considering below path suspicious. PathC:\Program Files (x86)\Avantium Technologies\Crystal16.exe I have created global exclusion in two ways:- 1) Based on File or folder (Windows…
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • False malware with Volsoft?

    Joseph Black
    Joseph Black
    We've recently updated to Endpoint and have an unusual issue with one of our users recently migrated to Win10 and Endpoint. Whenever they attempt to launch Volunteer Reporter by Volsoft it is blocked by Sophos. I am awaiting a local screenshot from our…
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • False threat detection, ransomware, on dotnet.exe

    James Komenda
    James Komenda
    I have a large .net7 browser-wasm project that is published with AOT (Ahead-of-time) complication and Sophos keeps flagging "C:Program Files\dotnet\dotnet.exe" as a ransomware threat. The AOT process is linking and packaging a large number of files. Is…
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • Exploit Mitigation custom exclusion

    LHerzog
    LHerzog
    How can I add a new custom application to the exceptions? This does not seem to help or it is not clear what will happen with the path that I add manually: I was looking for something like this: Need to add ROP exclusion for this not so…
    • Answered
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • View related content throughout Sophos Endpoint
  • More
  • Cancel
>