Guest User!

You are not Sophos Staff.

  • sophos_ips_windows

    • Under Review on
    • 0 Comments
    Sophos record of IPS activity on Windows SCHEMA destination_ip string The destination ip address of the ip event destination_port int The destination port of the ip event pids string List of PIDs protocol int...
  • threat_osx_hidden_users

    • Under Review on
    • 0 Comments
    Scheduled queries with the Threat prefix are identification of potential threats that may warrant investigation. This identifies hidden users on OSX SCHEMA shell string User's configured default shell uid long The local user...
  • threat_pass_the_hash

    • Under Review on
    • 0 Comments
    Detects potential pass the hash threats SCHEMA eventid int The Windows event ID key_length int The length of NTLM Session Security key logon_process string The name of the trusted logon process that was used for the logon...
  • threat_promisc_interfaces_linux

    • Under Review on
    • 0 Comments
    Detect promiscuous interfaces on LInux https://en.wikipedia.org/wiki/Promiscuous_mode SCHEMA flags int Flags (netdevice) for the device interface string Interface name loopback long Loopback interface mac string...
  • threat_stickykeys_registry_backdoor

    • Under Review on
    • 0 Comments
    Windows sticky keys have been changed SCHEMA data string Data content of registry value key string Name of the key mtime long time of the most recent registry write name string Name of the registry value entry...
  • user_accounts

    • Under Review on
    • 0 Comments
    List user accounts SCHEMA description string Plugin description text directory string User's home directory gid long Group ID (unsigned) of the user running the process shell string User's configured default...
  • user_events_linux

    • Under Review on
    • 0 Comments
    Linux user events SCHEMA address string IPv4 address target audit_type int The file description for the process socket message string Message from the event path string Full path to the value pid long...
  • vulnerability_app_compatibility

    • Under Review on
    • 0 Comments
    This detects a potential vulnerability in application compatibility mode being set https://www.itnews.com.au/news/windows-compatibility-mode-resurfaces-old-flaws-473058 Schema analysis string JSON object representing the analysis ...
  • vulnerability_app_disabled_exception_chain_validation

    • Under Review on
    • 0 Comments
    Detect disabled exception chain validation. https://www.windowsworkstation.com/win2012/disable-sehop/ SCHEMA analysis string JSON object representing the analysis data string Data content of registry value key string ...
  • vulnerability_app_mitigation_options

    • Under Review on
    • 0 Comments
    Not sure what this is detecting have to check with the Sophos Managed Threat Response Team on it. SCHEMA analysis string JSON object representing the analysis data string Data content of registry value key string Name...
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?