<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://stage-community-sophos-comv11.telligenthosting.net/cfs-file/__key/system/syndication/atom.xsl" media="screen"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-US"><title type="html">Announcements</title><subtitle type="html" /><id>https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/atom</id><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements" /><link rel="self" type="application/atom+xml" href="https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/atom" /><generator uri="http://telligent.com" version="12.1.9.35025">Telligent Community (Build: 12.1.9.35025)</generator><updated>2021-03-08T00:00:00Z</updated><entry><title>New Detection views</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/new-detection-views" /><id>https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/new-detection-views</id><published>2022-10-19T06:47:00Z</published><updated>2022-10-19T06:47:00Z</updated><content type="html">We have been adding the ability to view more detection information both from the Sophos managed devices and from 3rd party integrations.
In this update you can now view all detections and manage filters to see just detections that map to a specific M...(&lt;a href="https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/new-detection-views"&gt;read more&lt;/a&gt;)&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=1327&amp;AppID=62&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Karl_Ackerman</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/karl_5f00_ackerman</uri></author></entry><entry><title>Now available - MS 365 Azure Audit logs and XDR Data lake</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/ms-365-azure-audit-logs-and-xdr-data-lake" /><link rel="enclosure" type="application/zip" length="17317" href="https://stage-community-sophos-comv11.telligenthosting.net/cfs-file/__key/telligent-evolution-components-attachments/01-62-00-00-00-00-10-66/MS-365-query-pack.zip" /><id>https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/ms-365-azure-audit-logs-and-xdr-data-lake</id><published>2021-12-01T20:28:00Z</published><updated>2021-12-01T20:28:00Z</updated><content type="html">For query assistance, please see the following&amp;nbsp;&lt;a href="/intercept-x-endpoint/f/recommended-reads/128529/best-practices-on-using-live-discover-response-query-forum#mcetoc_1f8ovtfbt4"&gt;Best Practices&lt;/a&gt;&amp;nbsp;guide

We&amp;nbsp;have enabled the ability to add the Office 365 Audit log information into the Sophos XDR Data Lake.
This capability is available for ALL XDR customers at NO ADDITI...(&lt;a href="https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/ms-365-azure-audit-logs-and-xdr-data-lake"&gt;read more&lt;/a&gt;)&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=1066&amp;AppID=62&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Karl_Ackerman</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/karl_5f00_ackerman</uri></author></entry><entry><title>XDR Detections EAP</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/xdr-detections-eap" /><id>https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/xdr-detections-eap</id><published>2021-10-20T12:52:00Z</published><updated>2021-10-20T12:52:00Z</updated><content type="html">Now with the XDR Detections EAP open folks can see all activity that has been classified to MITRE ATT&amp;amp;CK.
The new page is in the Threat Analysis Center and has lots of really great information on what has been observed in your environment.&amp;nbsp;&amp;amp;...(&lt;a href="https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/xdr-detections-eap"&gt;read more&lt;/a&gt;)&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=1040&amp;AppID=62&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Karl_Ackerman</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/karl_5f00_ackerman</uri></author></entry><entry><title>Winding down of the XDR &amp; EDR Data Lake Early Access Program (Update June 30, 2021)</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/winding-down-of-the-xdr-edr-data-lake-early-access-program-update-june-30-2021" /><id>https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/winding-down-of-the-xdr-edr-data-lake-early-access-program-update-june-30-2021</id><published>2021-06-30T14:18:00Z</published><updated>2021-06-30T14:18:00Z</updated><content type="html">As previously communicated, from the beginning of June, no new customers are able to enroll into the XDR &amp;amp; EDR Data Lake Endpoint and Server early access programs (EAPs).&amp;nbsp; For customers who were already enrolled, they are no longer able to a...(&lt;a href="https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/winding-down-of-the-xdr-edr-data-lake-early-access-program-update-june-30-2021"&gt;read more&lt;/a&gt;)&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=945&amp;AppID=62&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Kevin Kingston</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/kevin-kingston</uri></author></entry><entry><title>Winding down of the XDR &amp; EDR Data Lake Early Access Program (Update June 16, 2021)</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/winding-down-of-the-xdr-edr-data-lake-early-access-program-update-june-16-2021" /><id>https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/winding-down-of-the-xdr-edr-data-lake-early-access-program-update-june-16-2021</id><published>2021-06-15T20:00:00Z</published><updated>2021-06-15T20:00:00Z</updated><content type="html">As previously communicated, from the beginning of June, no new customers are able to enroll into the XDR &amp;amp; EDR Data Lake Endpoint and Server early access programs (EAPs).&amp;nbsp; For customers who were already enrolled, they are no longer able to a...(&lt;a href="https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/winding-down-of-the-xdr-edr-data-lake-early-access-program-update-june-16-2021"&gt;read more&lt;/a&gt;)&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=935&amp;AppID=62&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Kevin Kingston</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/kevin-kingston</uri></author></entry><entry><title>Winding down of the XDR &amp; EDR Data Lake Early Access Program</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/winding-down-of-the-xdr-edr-data-lake-early-access-program" /><id>https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/winding-down-of-the-xdr-edr-data-lake-early-access-program</id><published>2021-06-04T11:31:00Z</published><updated>2021-06-04T11:31:00Z</updated><content type="html">Hello All,
With EDRv4 and our new XDR offering having become generally available in mid-May, Sophos will now begin the wind down of the XDR &amp;amp; EDR Data Lake Early Access Programs.&amp;nbsp; At this point we will not be introducing any new functionalit...(&lt;a href="https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/winding-down-of-the-xdr-edr-data-lake-early-access-program"&gt;read more&lt;/a&gt;)&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=923&amp;AppID=62&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Kevin Kingston</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/kevin-kingston</uri></author></entry><entry><title>Scheduled Query for automatic report generation (PREVIEW)</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/scheduled-query-for-automatic-report-generation-preview" /><id>https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/scheduled-query-for-automatic-report-generation-preview</id><published>2021-04-21T21:58:00Z</published><updated>2021-04-21T21:58:00Z</updated><content type="html">With the release of the product we will be adding scheduled query reports.&amp;nbsp; &amp;nbsp;
This feature is NOT YET available in the EAP but is coming with the general release in mid May.&amp;nbsp; For those eager to see it before it is complete I have recor...(&lt;a href="https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/scheduled-query-for-automatic-report-generation-preview"&gt;read more&lt;/a&gt;)&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=880&amp;AppID=62&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Karl_Ackerman</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/karl_5f00_ackerman</uri></author></entry><entry><title>EMAIL information now in the data lake</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/email-information-now-in-the-data-lake" /><id>https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/email-information-now-in-the-data-lake</id><published>2021-04-21T18:06:00Z</published><updated>2021-04-21T18:06:00Z</updated><content type="html">BRIEF Video on EMAIL and the Data Lake.
In this video we show the EMAIL Attachment and URL table that is available in the data lake, we also pivot from a URL seen an an email to ask if any endpoint have ever communicated to that URL and if so what pr...(&lt;a href="https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/email-information-now-in-the-data-lake"&gt;read more&lt;/a&gt;)&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=879&amp;AppID=62&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Karl_Ackerman</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/karl_5f00_ackerman</uri></author></entry><entry><title>Intercept X EDR XDR Overview</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/intercept-x-edr-xdr-overview" /><id>https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/intercept-x-edr-xdr-overview</id><published>2021-04-20T21:58:00Z</published><updated>2021-04-20T21:58:00Z</updated><content type="html">A 30 min tour of some of the capabilities of Sophos Intercept X with EDR XDR.&amp;nbsp; In this 30 min video I touch on some of the core concepts in the product and explain a bit about how queries work and show some of the features. It by no means covers...(&lt;a href="https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/intercept-x-edr-xdr-overview"&gt;read more&lt;/a&gt;)&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=876&amp;AppID=62&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Karl_Ackerman</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/karl_5f00_ackerman</uri></author></entry><entry><title>Generate Threat Case from Live Discovery file path</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/generate-threat-case-from-live-discovery-file-path" /><id>https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/generate-threat-case-from-live-discovery-file-path</id><published>2021-04-19T22:37:00Z</published><updated>2021-04-19T22:37:00Z</updated><content type="html">Often administrators would prefer to see the graphical view of the attack instead of the tables.&amp;nbsp;&amp;nbsp;
With a graphical view it is often MUCH easier to understand what was happening and come to a decision is something is malicious or not.
To he...(&lt;a href="https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/generate-threat-case-from-live-discovery-file-path"&gt;read more&lt;/a&gt;)&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=875&amp;AppID=62&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Karl_Ackerman</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/karl_5f00_ackerman</uri></author></entry><entry><title>Update XDR (EMAIL data, Scheduled Reports, Enrichment Pivots)</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/update-xdr-email-data-scheduled-reports-enrichment-pivots" /><id>https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/update-xdr-email-data-scheduled-reports-enrichment-pivots</id><published>2021-04-19T20:24:00Z</published><updated>2021-04-19T20:24:00Z</updated><content type="html">Lots of new features are going to be enabled on Wed April 21.&amp;nbsp; We are still on track for GA in mid May.

Video:
&lt;a href="https://techvids.sophos.com/watch/hzQ2iDv2gn7tYV4Q8NYSnm" rel="noopener noreferrer" target="_blank"&gt;&lt;/a&gt;(&lt;a href="https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/update-xdr-email-data-scheduled-reports-enrichment-pivots"&gt;read more&lt;/a&gt;)&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=873&amp;AppID=62&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Karl_Ackerman</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/karl_5f00_ackerman</uri></author></entry><entry><title>Pivots and the Depth of information available</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/pivots-and-the-depth-of-information-available" /><id>https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/pivots-and-the-depth-of-information-available</id><published>2021-04-08T19:29:00Z</published><updated>2021-04-08T19:29:00Z</updated><content type="html">We continue to make excellent progress to the intended May release of the Data Lake version of the product.
This week I wanted to demonstrate some of the capabilities we have just added around Pivots and the Depth of information available for admins ...(&lt;a href="https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/pivots-and-the-depth-of-information-available"&gt;read more&lt;/a&gt;)&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=870&amp;AppID=62&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Karl_Ackerman</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/karl_5f00_ackerman</uri></author></entry><entry><title>Frequently asked questions</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/frequently-asked-questions" /><id>https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/frequently-asked-questions</id><published>2021-03-24T20:16:00Z</published><updated>2021-03-24T20:16:00Z</updated><content type="html">Welcome to the EDR Data Lake EAP (Early Access Program).
How do I learn more

In this forum you will find a number of documents, videos, queries and posts explaining the program and if you have any questions you can post them to the &lt;a href="/intercept-x-endpoint/edr-data-lake-eap/f/discussions"&gt;discussions&lt;/a&gt; area ...(&lt;a href="https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/frequently-asked-questions"&gt;read more&lt;/a&gt;)&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=735&amp;AppID=62&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Karl_Ackerman</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/karl_5f00_ackerman</uri></author></entry><entry><title>Technical training on XDR Data lake with Queries used</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/technical-training-on-xdr-data-lake-with-queries-used" /><id>https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/technical-training-on-xdr-data-lake-with-queries-used</id><published>2021-03-10T16:18:00Z</published><updated>2021-03-10T16:18:00Z</updated><content type="html">For query assistance, please see the following&amp;nbsp;&lt;a href="/intercept-x-endpoint/f/recommended-reads/128529/best-practices-on-using-live-discover-response-query-forum#mcetoc_1f8ovtfbt4"&gt;Best Practices&lt;/a&gt;&amp;nbsp;guide

Watch the video from the technical demo where we cover how to use Live Discover datalake queries.
&lt;a href="https://vimeo.com/519661823"&gt;https://vimeo.com/519661823&lt;/a&gt;
Queries used during SophSkills Demo
DATA LAKE...(&lt;a href="https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/technical-training-on-xdr-data-lake-with-queries-used"&gt;read more&lt;/a&gt;)&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=847&amp;AppID=62&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Karl_Ackerman</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/karl_5f00_ackerman</uri></author></entry><entry><title>Live Discover Pivoting</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/live-discover-pivoting" /><id>https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/live-discover-pivoting</id><published>2021-03-08T08:00:00Z</published><updated>2021-03-08T08:00:00Z</updated><content type="html">For those enrolled in the XDR &amp;amp; EDR Data Lake early access program (EAP), this week we will be launching new pivoting capabilities which allow administrators to rapidly navigate from the result of one query to an available Action, Query, or Enric...(&lt;a href="https://stage-community-sophos-comv11.telligenthosting.net/intercept-x-endpoint/edr-data-lake-eap/b/announcements/posts/live-discover-pivoting"&gt;read more&lt;/a&gt;)&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=829&amp;AppID=62&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Karl_Ackerman</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/karl_5f00_ackerman</uri></author></entry></feed>