Sophos Community
Sophos Community
  • User
  • Site
  • Search
  • User
  • Community & Product Forums
  • Blogs
  • Partners
  • Events & Webinars
  • Getting Started
  • Support Portal
  • Community Blogs
    • Application Control
    • Community
    • Product documentation
    • Security
  • Feedback
    • Support Portal
    • Product documentation
  • Products
    • Endpoint security
      • Sophos Endpoint
      • Sophos XDR
      • Device Encryption
      • Sophos Mobile
    • Network Security
      • Sophos Firewall
      • Sophos ZTNA
      • Sophos Switch
      • UTM Firewall
      • Sophos Wireless
      • Sophos NDR
    • Email Security
      • Sophos Email
      • Phish Threat
    • Cloud Security
      • Sophos Central
      • Sophos Cloud Optix
    • Support Tools
      • Sophos integrations
      • Free tools
    • AI Solutions
      • Sophos AI
  • Services
    • Management platform
      • Sophos Professional Services
      • Sophos Central
      • Support Portal
      • Sophos Community log in
  • Sophos Partners
    • Partners blog
    • Local Partner community
    • Partner news
  • Resources
    • MSP guides
    • Partner Care
    • Sophos Central
  • Webinars & Events
    • Webinars & Events
    • Calendar
  • Become a partner
    • Join our program
  • Events & Webinars
    • Events & Webinars
    • Calendar
    • Recordings
  • Getting started in the Community
    • How to get started
    • SophosID registration
    • How to set up your profile
    • How to contribute and participate
    • How to manage private messages
  • Member recognition
    • Recognition program
    • Leaderboard
  • Products and Services
    • Products
      • Endpoint security
        • Sophos Endpoint
        • Sophos XDR
        • Device Encryption
        • Sophos Mobile
      • Network Security
        • Sophos Firewall
        • ZTNA
        • Sophos Switch
        • UTM Firewall
        • Sophos Wireless
        • NDR
      • Email Security
        • Sophos Email
        • Phish Threat
      • Cloud Security
        • Sophos Central
        • Sophos Cloud Optix
      • Support Tools
        • Sophos integrations
        • Free tools
      • AI Solutions
        • Sophos AI
    • Services
      • Management platform
        • Sophos Professional Services
        • Sophos Central
        • Support Portal
        • Sophos Community log in
  • Blogs
    • Community Blogs
      • Application Control
      • Community
      • Product documentation
      • Security
    • Feedback
      • Support Portal
      • Product documentation
  • Partners
    • Sophos Partners
      • Partners blog
      • Local Partner community
      • Partner news
    • Resources
      • MSP guides
      • Partner Care
      • Sophos Central
    • Webinars & Events
      • Webinars & Events
      • Calendar
    • Become a partner
      • Join our program
  • Events & Webinars
    • Events & Webinars
      • Events & Webinars
      • Calendar
      • Recordings
  • Getting Started
    • Getting started in the Community
      • How to get started
      • SophosID registration
      • How to set up your profile
      • How to contribute and participate
      • How to manage private messages
    • Member recognition
      • Recognition program
      • Leaderboard
  • Support Portal
Sophos Endpoint
Sophos Endpoint
Live Discover & Response Query Forum Live Discover & Response Query Forum
  • Release Notes & News
  • Discussions
  • Recommended Reads
  • Threat Hunting Academy
  • Early Access Programs
  • Live Discover & Response Query Forum
  • Calendars
  • More
  • Cancel
  • New
Sophos Endpoint requires membership for participation - click to join
Overview
Live Discover allows you to check the devices that Sophos Central is managing, look for signs of a threat, or assess compliance.

New to Live Discover & Response queries?

See Getting Started In Live Discover - From Beginner to Advanced Query Creation

Make sure to also check out
⁃ Best Practices On Using Live Discover & Response Query Forum and Sophos EDR Threat Hunting Framework.
⁃ Query Corner Announcement and Master Index.

Notes:
For more information on Live Discover, please check out our Product Documentation
For query assistance, please see Getting LD&R Community Support.

Sophos Community XDR Queries on GitHub


Navigate to a category below to browse and submit a query

Browse Live Response and Discover Queries by Category
  • Uncategorized

  • Anomalies

  • ATT&CK

  • Cloud Optix

  • Compliance

  • Data Lake

  • Device

  • Email

  • Events

  • Files

  • Live Response

  • Network

  • Other queries

  • Processes

  • Query Tips

  • Registry

  • Threat Hunting

  • User

Latest Live Discover and Response Queries (All)
  • threat_stickykeys_registry_backdoor

    Karl_Ackerman
    Karl_Ackerman
    • Queries
    • Under Review on 14 Oct 2020
    • 0 Comments
    Windows sticky keys have been changed SCHEMA data string Data content of registry value key string Name of the key mtime long time of the most recent registry write name string Name of the registry value entry...
    • 14 Oct 2020 1:12 PM
  • threat_promisc_interfaces_linux

    Karl_Ackerman
    Karl_Ackerman
    • Queries
    • Under Review on 14 Oct 2020
    • 0 Comments
    Detect promiscuous interfaces on LInux https://en.wikipedia.org/wiki/Promiscuous_mode SCHEMA flags int Flags (netdevice) for the device interface string Interface name loopback long Loopback interface mac string...
    • 14 Oct 2020 1:08 PM
  • threat_pass_the_hash

    Karl_Ackerman
    Karl_Ackerman
    • Queries
    • Under Review on 14 Oct 2020
    • 0 Comments
    Detects potential pass the hash threats SCHEMA eventid int The Windows event ID key_length int The length of NTLM Session Security key logon_process string The name of the trusted logon process that was used for the logon...
    • 14 Oct 2020 1:05 PM
  • threat_osx_hidden_users

    Karl_Ackerman
    Karl_Ackerman
    • Queries
    • Under Review on 14 Oct 2020
    • 0 Comments
    Scheduled queries with the Threat prefix are identification of potential threats that may warrant investigation. This identifies hidden users on OSX SCHEMA shell string User's configured default shell uid long The local user...
    • 14 Oct 2020 1:02 PM
  • sophos_ips_windows

    Karl_Ackerman
    Karl_Ackerman
    • Queries
    • Under Review on 14 Oct 2020
    • 0 Comments
    Sophos record of IPS activity on Windows SCHEMA destination_ip string The destination ip address of the ip event destination_port int The destination port of the ip event pids string List of PIDs protocol int...
    • 14 Oct 2020 12:59 PM
  • running_processes_windows_sophos

    Karl_Ackerman
    Karl_Ackerman
    • Queries
    • Under Review on 14 Oct 2020
    • 0 Comments
    Windows process history SCHEMA cmdline string Process command line file_size long File size now gid long Group ID (unsigned) of the user running the process global_rep int The machine learning global reputation...
    • 14 Oct 2020 12:46 PM
  • running_processes_osx_events

    Karl_Ackerman
    Karl_Ackerman
    • Queries
    • Under Review on 14 Oct 2020
    • 0 Comments
    Mac os running process info SCHEMA cmdline string Process command line egid long Effective group ID at process start euid long Effective user ID at process start gid long Group ID (unsigned) of the user running...
    • 14 Oct 2020 12:42 PM
  • running_processes_linux_events

    Karl_Ackerman
    Karl_Ackerman
    • Queries
    • Under Review on 14 Oct 2020
    • 0 Comments
    Linux running processes SCHEMA cmdline string Process command line egid long Effective group ID at process start euid long Effective user ID at process start gid long Group ID (unsigned) of the user running...
    • 14 Oct 2020 12:38 PM
  • rpm_packages

    Karl_Ackerman
    Karl_Ackerman
    • Queries
    • Under Review on 14 Oct 2020
    • 0 Comments
    RPM package info SCHEMA arch string Architecture(s) supported name string Name of the registry value entry release string Package release source string ` version string Plugin short version ...
    • 14 Oct 2020 12:36 PM
  • pending_windows_updates_patch

    Karl_Ackerman
    Karl_Ackerman
    • Queries
    • Under Review on 14 Oct 2020
    • 0 Comments
    Pending windows updates/patches SCHEMA hotfix_id string The kb article ID for the update installed string Is the update installed mandatory string Is the update mandatory msrc_severity string Severity of the...
    • 14 Oct 2020 12:34 PM
<>
Unfiltered HTML
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?

Cookie Information Banner

Defeat Cyberattacks

Footer - Default

  • Column 1
    • Endpoint Security
      • Sophos Endpoint
      • Sophos XDR
      • Device Encryption
      • Sophos Mobile
    • Email Security
      • Sophos Email
      • Phish Threat
    • Support Tools
      • Sophos integrations
      • Free tools
  • Column 2
    • Network Security
      • Sophos Firewall
      • Sophos ZTNA
      • Sophos Switch
      • UTM Firewall
      • Sophos Wireless
      • Sophos NDR
    • Cloud Security
      • Sophos Central
      • Sophos Cloud Optix
  • Column 3
    • Partners
      • Find a partner
      • Managed service providers
      • Join our program
    • Current Partners
      • Partners blog
      • Local Partner Community blog
      • Partner MSG guides
      • Partner news
      • Partner care
      • Partner portal login
      • Training & certification
    • Management Platform
      • Sophos Central
  • Column 4
    • Support
      • Downloads and updates
      • Support packages
      • Support portal
      • Sophos Customer Success
      • Sophos Techvids
      • Sophos Learning Center
      • Sophos status
      • Tech support
    • Learn
      • Threat intelligence
      • X-Ops threat research
      • Trust center
      • Security blogs
      • Sophos Academy
  • Column 5
    • Getting Started
      • How to get started
      • Community FAQs
    • Member Recognition
      • Recognition program
      • Leaderboard
    • Events & Webinars
      • Webinars
      • Calendar
      • Recordings
  • Column 6
    • Try for Free
      • Free trials
      • Product demos
    • Sophos Home Premium
      • Sophos Home support
      • Contact Home support
      • Mac antivirus download
      • PC antivirus download
    • About Us
      • Company
      • Events
      • Press
      • Careers
  • Getting Started
  • Terms
  • Privacy
    • Privacy Notice
    • Cookies
  • Legal
    • General
    • Modern Slavery Statement
    • Speak Out
© 1997- Sophos Ltd. All Rights Reserved.