Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

'Lockdown' exploit prevented in Pick an app

We are seeing a lot of these prevented (400+).

Thumbprint 360f7a07529d23856076fa4eacb505fd73e9dc84269b63ee1f8e11c67008e6d9

How do I find what is causing this to remediate?

"Pick an app" is a built in Windows service, is it likely to be related to the version of Windows we are running?

Has anyone else seen this, how did you handle it?

Thanks


Alan



This thread was automatically locked due to age.
Parents
  • Hello Alan,

    Thank you for reaching out to the Sophos Community. 

    Could you try filtering the "Windows Application Event Viewer" log by "Event ID: 911"? If you see something that corresponds with the detection mentioned, please provide the event details here. 

    Thank you,

Reply
  • Hello Alan,

    Thank you for reaching out to the Sophos Community. 

    Could you try filtering the "Windows Application Event Viewer" log by "Event ID: 911"? If you see something that corresponds with the detection mentioned, please provide the event details here. 

    Thank you,

Children
No Data