Sophos Community
Sophos Community
  • User
  • Site
  • Search
  • User
  • Community & Product Forums
  • Blogs
  • Partners
  • Events & Webinars
  • Getting Started
  • Support Portal
  • Community Blogs
    • Application Control
    • Community
    • Product documentation
    • Security
  • Feedback
    • Support Portal
    • Product documentation
  • Products
    • Endpoint security
      • Sophos Endpoint
      • Sophos XDR
      • Device Encryption
      • Sophos Mobile
    • Network Security
      • Sophos Firewall
      • Sophos ZTNA
      • Sophos Switch
      • UTM Firewall
      • Sophos Wireless
      • Sophos NDR
    • Email Security
      • Sophos Email
      • Phish Threat
    • Cloud Security
      • Sophos Central
      • Sophos Cloud Optix
    • Support Tools
      • Sophos integrations
      • Free tools
    • AI Solutions
      • Sophos AI
  • Services
    • Management platform
      • Sophos Professional Services
      • Sophos Central
      • Support Portal
      • Sophos Community log in
  • Sophos Partners
    • Partners blog
    • Local Partner community
    • Partner news
  • Resources
    • MSP guides
    • Partner Care
    • Sophos Central
  • Webinars & Events
    • Webinars & Events
    • Calendar
  • Become a partner
    • Join our program
  • Events & Webinars
    • Events & Webinars
    • Calendar
    • Recordings
  • Getting started in the Community
    • How to get started
    • SophosID registration
    • How to set up your profile
    • How to contribute and participate
    • How to manage private messages
  • Member recognition
    • Recognition program
    • Leaderboard
  • Products and Services
    • Products
      • Endpoint security
        • Sophos Endpoint
        • Sophos XDR
        • Device Encryption
        • Sophos Mobile
      • Network Security
        • Sophos Firewall
        • ZTNA
        • Sophos Switch
        • UTM Firewall
        • Sophos Wireless
        • NDR
      • Email Security
        • Sophos Email
        • Phish Threat
      • Cloud Security
        • Sophos Central
        • Sophos Cloud Optix
      • Support Tools
        • Sophos integrations
        • Free tools
      • AI Solutions
        • Sophos AI
    • Services
      • Management platform
        • Sophos Professional Services
        • Sophos Central
        • Support Portal
        • Sophos Community log in
  • Blogs
    • Community Blogs
      • Application Control
      • Community
      • Product documentation
      • Security
    • Feedback
      • Support Portal
      • Product documentation
  • Partners
    • Sophos Partners
      • Partners blog
      • Local Partner community
      • Partner news
    • Resources
      • MSP guides
      • Partner Care
      • Sophos Central
    • Webinars & Events
      • Webinars & Events
      • Calendar
    • Become a partner
      • Join our program
  • Events & Webinars
    • Events & Webinars
      • Events & Webinars
      • Calendar
      • Recordings
  • Getting Started
    • Getting started in the Community
      • How to get started
      • SophosID registration
      • How to set up your profile
      • How to contribute and participate
      • How to manage private messages
    • Member recognition
      • Recognition program
      • Leaderboard
  • Support Portal
  • Community Blog
  • Member Recognition
  • More
  • Cancel
Sophos Endpoint
Sophos Endpoint
Release Notes & News
  • Release Notes & News
  • Discussions
  • Recommended Reads
  • Threat Hunting Academy
  • Early Access Programs
  • Live Discover & Response Query Forum
  • Calendars
  • More
  • Cancel
  • New
Sophos Endpoint requires membership for participation - click to join
Release Notes & News
Subscribe
  • Subscribe by email
  • Posts RSS
  • More
  • Cancel
  • Tags
  • Subscribe by email
  • More
  • Cancel
  • Using Live Discover to get more flexible Threat Indicator results and perform powerful Threat Searches

    Release Notes & News: Using Live Discover to get more flexible Threat Indicator results and perform powerful Threat Searches

    Kevin Kingston
    Kevin Kingston
    After the launch of Intercept X Advanced with EDR in late 2018, we introduced the EDRv1 Data Feed (aka Trickle Feed) functionality to enable Administrators to easily view Threat Indicators and perform Threat Searches. Now there is a better way! The L...
    • 15 Mar 2021
  • Getting ready for the live threat hunt!

    Threat Hunting Academy: Getting ready for the live threat hunt!

    Nick Fisher
    Nick Fisher
    Welcome to Monday everyone!  We're busily getting ready for our final session in the series tomorrow, where we'll be running through a live threat hunt with all of you. Can't wait to get started with it - should be fun Don't fo...
    • 15 Mar 2021
  • Session 5 Resources

    Threat Hunting Academy: Session 5 Resources

    Nick Fisher
    Nick Fisher
    Hope you all enjoyed today's session - I love seeing this end of the chain; as Ben said on the EMEA session, this is the 'fun' bit where everything we've learnt so far comes together! Here's links to a few resources that we mentio...
    • 10 Mar 2021
  • Technical training on XDR Data lake with Queries used

    Announcements: Technical training on XDR Data lake with Queries used

    Karl_Ackerman
    Karl_Ackerman
    For query assistance, please see the following Best Practices guide Watch the video from the technical demo where we cover how to use Live Discover datalake queries. https://vimeo.com/519661823 Queries used during SophSkills Demo DATA LAKE...
    • 10 Mar 2021
  • Sophos Central: Intercept X v2.0.20 released

    Release Notes & News: Sophos Central: Intercept X v2.0.20 released

    Shweta
    Shweta
    Hi Community,  A new version of Intercept X has been released to our Sophos Central customers. The release updates: Sophos Central Intercept X version to 2.0.20 HitmanPro.Alert component version to 3.8.1.504 Resolved issues Resolved issues fo...
    • 10 Mar 2021
  • Session 4 Resources

    Threat Hunting Academy: Session 4 Resources

    Nick Fisher
    Nick Fisher
    Great to see so many of you on the session today and interacting - thanks! I hope the new platform worked well for you. Here's a few query resources that I wanted to share following Andy's session: https://community.sophos.com/intercept-x-endpoin...
    • 9 Mar 2021
  • Live Discover Pivoting

    Announcements: Live Discover Pivoting

    Karl_Ackerman
    Karl_Ackerman
    For those enrolled in the XDR & EDR Data Lake early access program (EAP), this week we will be launching new pivoting capabilities which allow administrators to rapidly navigate from the result of one query to an available Action, Query, or Enric...
    • 8 Mar 2021
  • Session 3 Resources

    Threat Hunting Academy: Session 3 Resources

    Nick Fisher
    Nick Fisher
    Thanks Kris for a great session today!  Kris used quite a few queries which are listed below for you to test out and use on your network: RDP Status- https://community.sophos.com/intercept-x-endpoint/i/device/simple-query-to-audit-microsof...
    • 3 Mar 2021
  • On-Demand Content Available!

    Threat Hunting Academy: On-Demand Content Available!

    Nick Fisher
    Nick Fisher
    Just a quick note to say that session 1 is now available at the on-demand page, for you to review and please share with colleagues! https://events.sophos.com/threatacademyondemand  We'll get other sessions up as soon as possible after they&#...
    • 3 Mar 2021
  • Sophos Central - Release of Central Windows Server Core Agent 2.15.4 and Server Anti-Virus 10.8.10

    Release Notes & News: Sophos Central - Release of Central Windows Server Core Agent 2.15.4 and Server Anti-Virus 10.8.10

    Shweta
    Shweta
    Hi Community,  The following is being released to Sophos Central Window Servers: Server Core Agent 2.15.4 Endpoint Advanced 10.8.10 The following are changes of note introduced in this release: Enablement of Tamper Protection in safe boot Upd...
    • 3 Mar 2021
  • Session 2 Resources

    Threat Hunting Academy: Session 2 Resources

    Nick Fisher
    Nick Fisher
    Great interaction again on today's session - thanks for joining in! I loved having a proper look at how code can be executed on your network and devices, and what Sophos EDR can do to help you threat hunt. We'll see more of that power in the remainin...
    • 2 Mar 2021
  • Session 1 Resources

    Threat Hunting Academy: Session 1 Resources

    Nick Fisher
    Nick Fisher
    I hope you enjoyed the first session - that's just a taster of the amazing content we've got for you in the next couple of weeks! There were a couple of resources mentioned in the session which I've listed below for reference in case: VirusTotal -&n...
    • 2 Mar 2021
  • EDR Live Response session audit logs

    Release Notes & News: EDR Live Response session audit logs

    Kevin Kingston
    Kevin Kingston
    The latest of our Live Response enhancements is now available to customers with the release of our new Live Response per session audit logs.   Typically a few minutes after running a Live Response session, if you navigate to the Logs and R...
    • 2 Mar 2021
  • Threat Hunting Academy - Welcome!

    Threat Hunting Academy: Threat Hunting Academy - Welcome!

    Nick Fisher
    Nick Fisher
    Welcome! This page is where we'll post any follow-on resources from the Threat Hunting Academy series, so that you can continue to learn and explore after the sessions. Do let us know in the Comments below if you have any feedback or extra informati...
    • 1 Mar 2021
  • MITRE ATT&CK Hunting in the Data Lake

    Announcements: MITRE ATT&CK Hunting in the Data Lake

    Karl_Ackerman
    Karl_Ackerman
    For query assistance, please see the following Best Practices guide With the data lake we can do some interesting IOC hunts that perform counts across all devices for similar IOC's and with some use of variables we allow for the administra...
    • 26 Feb 2021
  • Sophos Central - Release of Central 10.0.4 / OPM 9.10.2 with Big Sur Support

    Release Notes & News: Sophos Central - Release of Central 10.0.4 / OPM 9.10.2 with Big Sur Support

    GlennSen
    GlennSen
    Hello Community. A new version of Sophos Central Endpoint for macOS and Sophos Anti-virus for macOS (OPM) has been released now.  The release versions are:  Central 10.0.4 OPM 9.10.2  Release information This release contains th...
    • 22 Feb 2021
  • XDR & EDR Data Lake Early Access Program

    Release Notes & News: XDR & EDR Data Lake Early Access Program

    Kevin Kingston
    Kevin Kingston
    We're pleased to announce that the XDR & EDR Data Lake Early Access Program is now publicly available to our Intercept X Endpoint and Server customers. For customers who join and enroll devices into these endpoint and/or server early access progr...
    • 22 Feb 2021
  • All you need to know about getting up and running

    Announcements: All you need to know about getting up and running

    Kevin Kingston
    Kevin Kingston
    For anyone who's joined the XDR & EDR Data Lake Early Access Program, we've been providing instructions on the different steps to join and enroll devices but I thought it would be useful to have one full blog post covering those steps and also de...
    • 22 Feb 2021
  • Database Schemas explained

    Announcements: Database Schemas explained

    Karl_Ackerman
    Karl_Ackerman
    For query assistance, please see the following Best Practices guide (NEW) Video on Schemas for EDR and Data Lake (15 Min) https://vimeo.com/515493008 With the addition of the data lake a significant amount of new information is available....
    • 21 Feb 2021
  • Video of XDR EAP Features

    Announcements: Video of XDR EAP Features

    Karl_Ackerman
    Karl_Ackerman
    In this 7min video we show the features that were enabled on Feb 22nd for the Early Access Program for the XDR Data lake. Welcome to the EAP and stay tuned more features are coming in March and April as we add Context aware pivoting to another query...
    • 21 Feb 2021
  • Powerful Generic Search Query explained

    Announcements: Powerful Generic Search Query explained

    Karl_Ackerman
    Karl_Ackerman
    For query assistance, please see the following Best Practices guide One of the most frequently used queries by our threat hunting team is a flexible generic search query against the data lake. Often you know exactly what you are looking fo...
    • 21 Feb 2021
  • Get an Inventory of all installed applications

    Announcements: Get an Inventory of all installed applications

    Karl_Ackerman
    Karl_Ackerman
    For query assistance, please see the following Best Practices guide Below is a query that will list all installed applications, the publisher, application name, and version number. It performs some nice counting so you don't have to deal w...
    • 21 Feb 2021
  • Get an Inventory of all installed applications

    Release Notes & News: Get an Inventory of all installed applications

    Karl_Ackerman
    Karl_Ackerman
    For query assistance, please see the following Best Practices guide Below is a query that will list all installed applications, the publisher, application name, and version number. It performs some nice counting so you don't have to deal with a long...
    • 20 Feb 2021
  • Powerful Generic Search Query explained

    Release Notes & News: Powerful Generic Search Query explained

    Karl_Ackerman
    Karl_Ackerman
    For query assistance, please see the following Best Practices guide One of the most frequently used queries by our threat hunting team is a flexible generic search query against the data lake. Often you know exactly what you are looking fo...
    • 20 Feb 2021
<>

Defeat Cyberattacks

Footer - Default

  • Column 1
    • Endpoint Security
      • Sophos Endpoint
      • Sophos XDR
      • Device Encryption
      • Sophos Mobile
    • Email Security
      • Sophos Email
      • Phish Threat
    • Support Tools
      • Sophos integrations
      • Free tools
  • Column 2
    • Network Security
      • Sophos Firewall
      • Sophos ZTNA
      • Sophos Switch
      • UTM Firewall
      • Sophos Wireless
      • Sophos NDR
    • Cloud Security
      • Sophos Central
      • Sophos Cloud Optix
  • Column 3
    • Partners
      • Find a partner
      • Managed service providers
      • Join our program
    • Current Partners
      • Partners blog
      • Local Partner Community blog
      • Partner MSG guides
      • Partner news
      • Partner care
      • Partner portal login
      • Training & certification
    • Management Platform
      • Sophos Central
  • Column 4
    • Support
      • Downloads and updates
      • Support packages
      • Support portal
      • Sophos Customer Success
      • Sophos Techvids
      • Sophos Learning Center
      • Sophos status
      • Tech support
    • Learn
      • Threat intelligence
      • X-Ops threat research
      • Trust center
      • Security blogs
      • Sophos Academy
  • Column 5
    • Getting Started
      • How to get started
      • Community FAQs
    • Member Recognition
      • Recognition program
      • Leaderboard
    • Events & Webinars
      • Webinars
      • Calendar
      • Recordings
  • Column 6
    • Try for Free
      • Free trials
      • Product demos
    • Sophos Home Premium
      • Sophos Home support
      • Contact Home support
      • Mac antivirus download
      • PC antivirus download
    • About Us
      • Company
      • Events
      • Press
      • Careers
  • Getting Started
  • Terms
  • Privacy
    • Privacy Notice
    • Cookies
  • Legal
    • General
    • Modern Slavery Statement
    • Speak Out
© 1997- Sophos Ltd. All Rights Reserved.