This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Why Quarantine and how do I make it stop?

Apparently I asked this in the wrong group. Hopefully this is the right one.

Hey Guys, so I've JUST started taking over Sophos management at my university and I'ms till trying to find my feet. For the meantime, I wonder if I can ask a couple of questions. This is for what is showing as Sophos Endpoint Security and Control 10.3 and the corresponding Sophos Enterprise Console 5.2.2.

1) Why does Sophos ONLY quarantine now and not clean infections and Spyware? I find a lot of products are doing this and it's frustrating. I want things gone, not just put aside.

2) Since yesterday I've been getting a notice that something has been found and moved to quarantine. Is there a way for it to only tell me once or to set it so it only pops up once an hour instead of every few seconds?

I truly find Sophos to be vastly over complicated so if there's any place I can go to get things explained or shown in much simpler terms I'd be very grateful.

:57623


This thread was automatically locked due to age.
Parents
  • Hello dwilson,.

    I've JUST started taking over Sophos management

    climbed the ladder, eh? :smileyhappy:

    Why does Sophos ONLY quarantine now

    You've asked almost the same question in March. Now, first of all, the recommended (and therefore default) settings haven't changed for quite some time but versions up to 9.7 had different settings. If your university upgraded from a pre-5.x SEC version and the policies weren't amended then your settings will not be state-of-the-art. An upgrade adds items (with appropriate defaults) to the policies as necessary but doesn't change the values of existing items.

    So, automatic cleanup is available, recommended, and the default. Keep in mind that it's not always possible and for certain threat types not available. Thus please check your policies.

    Note: Sophos' quarantine is simply a list of detections which have not (yet) (successfully) been dealt with. Files are neither moved nor gelded thus if you turn off on-access you are not protected from them.

    Since yesterday I've been getting a notice that something has been found

    likely it didn't exist before (but it might as well be the updated detection, it seems to be rather new) and you should deal with it accordingly. An alert should, well, alert you that an attempt has been made to access a (potential) threat - it wouldn't be wise to suppress the alerts, be it for a certain time or count.

    I truly find Sophos to be vastly over complicated

    Perhaps it seems so because it doesn't work the way you expect it to do? It's definitely not vastly over, if complicated at all. Feel free to ask (please start separate threads for different topics, SEC has its own board).

    Christian

    :57637
Reply
  • Hello dwilson,.

    I've JUST started taking over Sophos management

    climbed the ladder, eh? :smileyhappy:

    Why does Sophos ONLY quarantine now

    You've asked almost the same question in March. Now, first of all, the recommended (and therefore default) settings haven't changed for quite some time but versions up to 9.7 had different settings. If your university upgraded from a pre-5.x SEC version and the policies weren't amended then your settings will not be state-of-the-art. An upgrade adds items (with appropriate defaults) to the policies as necessary but doesn't change the values of existing items.

    So, automatic cleanup is available, recommended, and the default. Keep in mind that it's not always possible and for certain threat types not available. Thus please check your policies.

    Note: Sophos' quarantine is simply a list of detections which have not (yet) (successfully) been dealt with. Files are neither moved nor gelded thus if you turn off on-access you are not protected from them.

    Since yesterday I've been getting a notice that something has been found

    likely it didn't exist before (but it might as well be the updated detection, it seems to be rather new) and you should deal with it accordingly. An alert should, well, alert you that an attempt has been made to access a (potential) threat - it wouldn't be wise to suppress the alerts, be it for a certain time or count.

    I truly find Sophos to be vastly over complicated

    Perhaps it seems so because it doesn't work the way you expect it to do? It's definitely not vastly over, if complicated at all. Feel free to ask (please start separate threads for different topics, SEC has its own board).

    Christian

    :57637
Children
No Data