Hope you all enjoyed today's session - I love seeing this end of the chain; as Ben said on the EMEA session, this is the 'fun' bit where everything we've learnt so far comes together!
Here's links to a few resources that we mentio...
For query assistance, please see the following Best Practices guide
Watch the video from the technical demo where we cover how to use Live Discover datalake queries.
https://vimeo.com/519661823
Queries used during SophSkills Demo
DATA LAKE...
Hi Community,
A new version of Intercept X has been released to our Sophos Central customers.
The release updates:
Sophos Central Intercept X version to 2.0.20
HitmanPro.Alert component version to 3.8.1.504
Resolved issues
Resolved issues fo...
Great to see so many of you on the session today and interacting - thanks! I hope the new platform worked well for you.
Here's a few query resources that I wanted to share following Andy's session:
https://community.sophos.com/intercept-x-endpoin...
For those enrolled in the XDR & EDR Data Lake early access program (EAP), this week we will be launching new pivoting capabilities which allow administrators to rapidly navigate from the result of one query to an available Action, Query, or Enric...
Just a quick note to say that session 1 is now available at the on-demand page, for you to review and please share with colleagues!
https://events.sophos.com/threatacademyondemand
We'll get other sessions up as soon as possible after they&#...
Hi Community,
The following is being released to Sophos Central Window Servers:
Server Core Agent 2.15.4
Endpoint Advanced 10.8.10
The following are changes of note introduced in this release:
Enablement of Tamper Protection in safe boot
Upd...
Great interaction again on today's session - thanks for joining in! I loved having a proper look at how code can be executed on your network and devices, and what Sophos EDR can do to help you threat hunt. We'll see more of that power in the remainin...
I hope you enjoyed the first session - that's just a taster of the amazing content we've got for you in the next couple of weeks!
There were a couple of resources mentioned in the session which I've listed below for reference in case:
VirusTotal -&n...
The latest of our Live Response enhancements is now available to customers with the release of our new Live Response per session audit logs.
Typically a few minutes after running a Live Response session, if you navigate to the Logs and R...
Welcome! This page is where we'll post any follow-on resources from the Threat Hunting Academy series, so that you can continue to learn and explore after the sessions.
Do let us know in the Comments below if you have any feedback or extra informati...
For query assistance, please see the following Best Practices guide
With the data lake we can do some interesting IOC hunts that perform counts across all devices for similar IOC's and with some use of variables we allow for the administra...
Hello Community.
A new version of Sophos Central Endpoint for macOS and Sophos Anti-virus for macOS (OPM) has been released now.
The release versions are:
Central 10.0.4
OPM 9.10.2
Release information
This release contains th...
We're pleased to announce that the XDR & EDR Data Lake Early Access Program is now publicly available to our Intercept X Endpoint and Server customers.
For customers who join and enroll devices into these endpoint and/or server early access progr...
For anyone who's joined the XDR & EDR Data Lake Early Access Program, we've been providing instructions on the different steps to join and enroll devices but I thought it would be useful to have one full blog post covering those steps and also de...
For query assistance, please see the following Best Practices guide
(NEW) Video on Schemas for EDR and Data Lake (15 Min)
https://vimeo.com/515493008
With the addition of the data lake a significant amount of new information is available....
In this 7min video we show the features that were enabled on Feb 22nd for the Early Access Program for the XDR Data lake.
Welcome to the EAP and stay tuned more features are coming in March and April as we add
Context aware pivoting to another query...
For query assistance, please see the following Best Practices guide
One of the most frequently used queries by our threat hunting team is a flexible generic search query against the data lake.
Often you know exactly what you are looking fo...
For query assistance, please see the following Best Practices guide
Below is a query that will list all installed applications, the publisher, application name, and version number. It performs some nice counting so you don't have to deal w...
For query assistance, please see the following Best Practices guide
Below is a query that will list all installed applications, the publisher, application name, and version number. It performs some nice counting so you don't have to deal with a long...
For query assistance, please see the following Best Practices guide
One of the most frequently used queries by our threat hunting team is a flexible generic search query against the data lake.
Often you know exactly what you are looking fo...
In this brief demo video we cover the core features being add during the early access program and as part of the expected product availability in May/June 2021
Content
Data Lake and direct endpoint queries from one console (Available in EAP)
Schedul...
For query assistance, please see the following Best Practices guide
With the addition of the data lake a significant amount of new information is available. In this document we will discuss each of the core database schemas.
For thos...