Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

The RCA component in the Sophos EDB console is a great feature, but can we trust the analysis?

The RCA component in the Sophos EDB console is a great feature, but can we trust the analysis?

 

We've got 100s of endpoints on which the PUAs and malwares are detected and 100s of tickets generated in the ticketing tool.

1. Do we have to collect the SDU logs from all the endpoints to make sure its not a false-positive?

2. Can we depend  on the analysis done by the RCA? Is it trustworthy?

3. What's the best way to deal 100s of false positives detected by Sophos?

4. If there are no business files affected in the RCA analysis, can I be sure its a false positive?



This thread was automatically locked due to age.