• I would like to know about SoPhos process information.

    kwon hyuk-sang
    kwon hyuk-sang
    Hi I would like to know about SoPhos process information. Please tell us in detail what function the two processes below perform. 1. SoPhosFilesScanner.exe 2. SSPService.exe
    • Answered
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Sophos Intercept X

    assiag gehena
    assiag gehena
    Could anyone let me know the main features which is available in Sophos intercept X, ( this is for presentation purpose, it would be great if anyone explains me briefly if you know) thanks in advance Have a great day ahead
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • What details are specific to a Detection ID?

    JasP
    JasP
    We recently had a false positive from CryptoGuard and were unsure whether to exclude it via Detection ID or filename+filepath. What details actually make up a Detection ID? We installed two versions of the software and although the exe file that caused…
    • Answered
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Cryptoguard bloqueando aplicação

    Marcelo Gonzaga
    Marcelo Gonzaga
    Cryptoguard bloqueando aplicação que o cliente já utilizava. Aplicação de confiança, mesmo marcando como confirmado e como resolvido o mesmo continua impedindo a aplicação.
    • Answered
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • what's about the Firefox SEC_ERROR_REUSED_ISSUER_AND_SERIAL issue with HTTPS decryption

    LHerzog
    LHerzog
    My feeling is, Sophos does not know about the Intercept-X EAP forums. So I put this to focus here. Maybe one of the Sophos members can bring some light into this issue, it this is on Sophos' screen and will be fixed? https://community.sophos.com/intercept…
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Windows Server 2012 R2 MCSClient.log problem

    Tim Z
    Tim Z
    Good morning to all, we recently implemented Sophos Intercept X Advanced Server. One of our windows server 2012 r2 system has a problem where it can not communicate with Sophos Central. The installation went without a problem. After the reboot i get…
    • Answered
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Sophos Intercept for servers onprem proxy

    VonKrieghoff
    VonKrieghoff
    Hello I some instances we use Sophos intercept for servers. and it is quite compicated to manage access for Sophos agent to connect to sophos central. In Palo Alto Cortex XDR there is such thing as connetion Broker, that can be installed on prem and…
    • Answered
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • [Feedback] Current Windows 11 with Contrast Mode ON

    Valvaris Sigma
    Valvaris Sigma
    Hello Sophos-Team, as a feedback found that on Endpoint Protection the Settings, Events and Detections Text is all gone: Windows 11 with Current Patch (KB5014019) Best regards Val.
    • Answered
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • InterceptX and Citrix Virtual Apps and Desktop (Daas) 7.15 lTSR

    Matthew Sherman1
    Matthew Sherman1
    Since we've switched from SEP to Sophos. We've had many random issues with users connecting and receiving various connecting errors. I know that this is a Sophos issue because I removed Sophos from all of our Citrix VDAs and all problems go away. last…
    • Answered
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • macOS Big Sur 11.4 Compatibility Issue with Sophos Endpoint Installer

    Jason Roble
    Jason Roble
    Is the current Sophos Installer for mac OS on the Sophos Central backward compatible with macOS Big Sur 11.4? Our devices with macOS Monterey were installed without issues but when we tried using the same installer to our Macbook that's running on macOS…
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Endpoint Webfilter: The certificate associated with this URL has been revoked

    LHerzog
    LHerzog
    Hi, seeing this today on several websites. One example: https://www.scc.kit.edu/ Website blocked Location: https://www.scc.kit.edu/ We've blocked access to this URL due to your policy. The certificate associated with this URL…
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Sophos Endpoint (InterceptX) using almost all memory on server

    Sophos User6136
    Sophos User6136
    Hello, We have Sophos installed on a server and it's using a ton of memory. Almost using all of RAM. There is 24 GB of ram and it's using between 18-19. How do I stop it using so much memory? Also seems to be using a lot of CPU, but the memory is the…
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • 5 Services are missing since 1.may 2022

    THEVA_Thomas
    THEVA_Thomas
    Hi all, since last Update these services are missing in Sophos Central / Endpoint protection / Status / Services. Sophos Anti-Virus Sophos Clean Service Sophos Safestore Service Sophos Web Intelligence Filter Service Sophos Web Intelligence Service…
    • Answered
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Sophos Intercept X - OnDemand Scanner Jumps to different Drive

    Appa_Omega
    Appa_Omega
    Hello there again, I've just noticed a realy strange behaivior while using the OnDemand Scanner (right-click -> Scan with Sophos) I wanted to scan a mounted Image which was taken as a backup from a different client. When i try to scan the whole mounted…
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Sophos Intercept X Client CLI?

    Appa_Omega
    Appa_Omega
    Well hello there, is there any way to trigger a FileScan from commandline with Intercept X? I know with the old endpoint protection you could use the sav32cli.exe, but i can't find this in the new intercep X agent. Hope some one can help. Greeting …
    • Answered
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Controlled Updates: Test Computers in Global Setting vs. Server Setting

    LHerzog
    LHerzog
    Im a bit confused about Controlled Updates and Test Computers. 1. Our intension was that Client Endpoints get their updates when they are released but only on a specific day. 2. Server Endpoints have a test group we update to latest version on a patchday…
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • A lot of WMV files deleted since last weeks for unknow reason

    Sophos User3113
    Sophos User3113
    Hello, since last week, for unknown reason our Sophos Endpoint delete all WMV files on computers. This is the event : Malware detected: 'W32/GetCodec-A' at 'XXX\Intro discours.wmv' Any idea why it's happen now?? I already created a ticket to…
    • Answered
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Random RDP Dropouts

    acs
    acs
    Hello All Have a client that has a mix of full fat and thin clients, the full fat clients being W10 Pro are connecting into a RDS server. What am noticing is that one computer is randomly experiencing RDP dropouts. Initially thought it was the NIC and…
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Attack Surface Reduction mitigation re: LSASS Memory credential dump attack

    Matthew Smith3
    Matthew Smith3
    This article https://attack.mitre.org/techniques/T1003/001/ lists several mitigations against an LSASS memory credential dump attack, one of which is ASR (Attack Surface Reduction). The mitigation is described as Behavior Prevention on Endpoint and links…
    • Answered
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Windows Update Query

    Sophos User5832
    Sophos User5832
    Hello - Does anyone have a query they have used to see if Windows Update is running on an endpoint?
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Sophos MTR

    FormerMember
    FormerMember
    Hello All. So more and more cyber insurance questionnaires are asking for SIEM SOC and 24x7 monitoring. We have been using Sophos Advanced Intercept-X for years and have been relatively happy with it. We considered the XDR option but that means we need…
    • Answered
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Sophos Intercept X

    tam siryu
    tam siryu
    Could anyone let me know the main features which is available in Sophos intercept X, ( this is for presentation purpose, it would be great if anyone explains me briefly if you know) https://192168ll.link/ https://routerlogin.uno/ thanks in advance …
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Sophos ML Engine (64-bit) failed to install

    JC12X
    JC12X
    Hello, I am new to Sophos and System Administration in general. Over the weekend, I got several notifications that some of my servers had failed to update Sophos. Below are some error snippets I've identified from the installation log: %ProgramData…
    • Answered
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Sophos Central - SSPService.exe - hoher RAM Verbrauch

    Thomas Gothe
    Thomas Gothe
    Hallo zusammen, folgende Grundinformationen: HP 449G3 238 AiO System Windows 10 20H2 Intel Core i57500T 2,7GHz 8 GB RAM Sophos Core Agent 2.20.11 Sophos Endpoint Advanced 10.8.11.4 Sophos Intercept X 2.04.24 Wir haben unsere gesamten Rechner auf…
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Detections: MS Store App with Defense Evasion Asynchronous Procedure Call

    pfeffex
    pfeffex
    Hi, maybe somebody can help me to identify what's going on. I have one workstation with a official MS store app "Your Phone". Sophos detect a RISK 7 level on this command: "C:\Program Files\WindowsApps\Microsoft.YourPhone_1.22012.160.0_x64__8wekyb3d8bbwe…
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • View related content throughout Sophos Endpoint
  • More
  • Cancel
<>