This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Malware Exclusions for CIDR ranges?

I have a quick question...

I work for a security firm that creates and tests malware. We use Sophos in order to detect malware we don't want on our network and it is fantastic, a little too fantastic. The question I have deals with transferring my malware between my  VM, or any other computer on my network,  and my Windows machine.

I want to keep on-demand scanning and download scanning but I want to exclude specific CIDR ranges or internally networked IP addresses from being scanned, is there a way to do this? Is it possible to tell Sophos to whitelist traffic for downloaded content, that isn't necessarily on a remote share?

I went throught the manual and didn't find much so if all else fails I'm making a feature request.

I have exclusions setup so that Sophos will not scan specific folders containing malware, the problem that I am having is in the transfer of files to my local machine from, well, anywhere to those folders. It scans them as normal which it should, but then my malware becomes quarantined everytime, and it is only slightly annoying. But an IP exclusion list would be great.

Anyway that's my story. Let me know what you think. I'll entertain questions, so long as they are on topic.

:19063


This thread was automatically locked due to age.
Parents
  • Hey thx Christian, worked like a charm.

    a bypass of Sophos is not necessarily a bypass of some other heuristic or signature based solution and vice versa. Some people have hardware based solutions that are incredibly efficient, but still have their flaws. 

    I'm not saying I'm the most amazing malware writer ever, but having my basic malware and "hacking tools"  quarantined all the time was becoming a hassle. Not only for me, but for the rest of my team. 

    Thanks for your answer. You Rock!

    :19089
Reply
  • Hey thx Christian, worked like a charm.

    a bypass of Sophos is not necessarily a bypass of some other heuristic or signature based solution and vice versa. Some people have hardware based solutions that are incredibly efficient, but still have their flaws. 

    I'm not saying I'm the most amazing malware writer ever, but having my basic malware and "hacking tools"  quarantined all the time was becoming a hassle. Not only for me, but for the rest of my team. 

    Thanks for your answer. You Rock!

    :19089
Children
No Data