Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

CryptoGuard detected IP that tries to encrypt network share | Whitelist

Hello all,

at the moment I have to deal with a false detection from CryptoGuard.

He detects IP's (Clients via VPN) that trys to encrypt a network share (A documentation tool that writes his files in there).

How can I whitelist this detection ? In Sophos Central I can just unblock the IP but if the User, with his Documentation tool, writes again files in there the message will appear again and CryptoGuard will lock out the IP again.  

 

Hope you can help me



This thread was automatically locked due to age.
Parents Reply Children
  • I got a quick phone call from a technician and I should submit the SDU's.

    I send the SDU's logs 5 days ago and now we still dont get a reply.

    Currently our company cant deliver some products because of this issue we cant generate documantations for the product.

    Please force the technican again to reply to the case or call us. (That seems to have helped last time)

  • Hi  

    I have informed the engineer to respond to the case as soon as possible.

    Regards,

    Jasmin
    Community Support Engineer | Sophos Support

    Sophos Support VideosKnowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'This helped me' link

  • This was not the solution. Case is still open. 

     

    To keep this post up-to-date:

    The case was finally solved today together with the Sophos Support (28.05.2020).

    I will write shortly how I fixed it because I hate it, when I search for a problem and found a forum-post but with no solution.


    Solution and way:

    I checked the HitmanPro.Alert-Event Log on our File-Server. In the Event Logs I could at least see what the "detected IP" tries to access.

    Very soon we detected that its a folder where a documentation Programm saves all his files for translating documents.

    With the folder we could find out the program on the "detected IP" clients.

    Now you need to go to Global Settings in Sophos Central => Global Exclusions => "Add Exclusion" => Exploit Mitigation => click on "Application not listed?" => Type in the complete path of the *.exe you want to exclude => turn off "Protect Application" below an click on "Add".

    Its to bad that Sophos Central don't give clear reports and logs in this case like the "Threat Analyses Center". It tooks a complete month together with the Sophos Support + more than 10GB of Logs for the Support to find out what "CryptoGuard detected IP that tries to encrypt network share" means and which program is the reason and how we can whitelist it. Also the Knowledgebase articles are very useless in this case.

  • Hi  

    Thank you for writing up the fine note which will help other users as well in the future.

    I understand your concern regarding the time of resolution, Sorry for that inconvenience but glad that issue was finally got resolved.

    Regards,

    Jasmin
    Community Support Engineer | Sophos Support

    Sophos Support VideosKnowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'This helped me' link