Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Web Gateway - SophosAgentRelay.exe Behaviour

Hi, 

 

We are looking into some of the behaviour being observed by Sophos' Web Gateway, and in particular SophosAgentRelay.exe.

 

It appears a large volume of processes are spawned by this binary (not at once, but the course of day). The processes mainly seem focussed around using "sc.exe" to query for services, or using "tasklist" to query for running tasks. The latter also has its own child processes.

 

Is anyone able to define the purpose of this binary in the CWG ecosystem? - I always thought it was the proxy/scanning component for capturing and parsing traffic.

 

Why would this binary need to query services, and query images under task list?

 

Any thoughts welcome.

 

Thanks!



This thread was automatically locked due to age.
Parents Reply Children
No Data