This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Auto unblock randsomware in Sophos Cemtral

Is it possible to change this default behaviour ?

On https://support.sophos.com/support/s/article/KB-000036287?language=en_US is

Note: The computer will automatically be unblocked after 8 hours if the Sophos Central Administrator takes no action to prevent a potentially valid application from being blocked indefinitely. If the remote attack re-occurs, it will be blocked again.

Thanks



This thread was automatically locked due to age.
Parents Reply
  • I was able to get some clarification on this point. It looks like the options to change "Isolate vs Terminate" will only be relevant for Local Cryptoguard detections.

    Remote Cryptoguard detections will continue following the same behavior in blocking the IP for a period of 8 hours. It looks like it’s not possible to change this.

Children
No Data