Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Petya/Petrwrap/Petyawrap and Sophos XG (Noob Question)

Warning: Noob question :D

With Sophos XG, what do I need to do to protect my network from above mentioned ransomware:

Is it automatically blocked, if ...?

Or do I need to have (in addition to XG) specific end-point-protection-software installed on Windows/MacOS clients as well?

 

Assumption: All clients OS are up to date. 

 

Cheers



This thread was automatically locked due to age.
Parents
  • The IPS engine on the XG already (prior to WannaCry) has signatures to detect the network level exploitation.  It's highly unlikely that this would be the cause of infection for most people, and is typically seen as an internal lateral movement technique.

    Within your IPS policy, search for WannaCry, Petya and the various Vault7 exploitation technologies, 'Eternal Blue', 'Eternal Romance' etc.  You will find the IPS rules accordingly.

Reply
  • The IPS engine on the XG already (prior to WannaCry) has signatures to detect the network level exploitation.  It's highly unlikely that this would be the cause of infection for most people, and is typically seen as an internal lateral movement technique.

    Within your IPS policy, search for WannaCry, Petya and the various Vault7 exploitation technologies, 'Eternal Blue', 'Eternal Romance' etc.  You will find the IPS rules accordingly.

Children
No Data