Hi,
since last update, Sophos XG does not block EICAR files in real-time scan mode anymore!
The file is downloaded without scanning!
In Batch mode the file is blocked as before!
Regards Meghan
This thread was automatically locked due to age.
Hi,
since last update, Sophos XG does not block EICAR files in real-time scan mode anymore!
The file is downloaded without scanning!
In Batch mode the file is blocked as before!
Regards Meghan
Yep, I've had this concern as well, as it was one of the first things I tried to "verify" my XG was working and I was very alarmed to see that I could download it. However I do note that in the Malware Log, it is detected by XG as "EICAR-AV-Test" so I assume it is allowing it through so you can test your AV solution? I have no idea, it has been that way since day one for me, not something new with the latest firmware.
I am using decrypt, but what i have found out, is that xg removes the eicar.com file out of the zip, and all code in eicar.com file.
So, my theorie is that Xg is cleaning the files from malicious code in Realtime, while it blocks the files in batch.
Regards Meghan
Hi Megan,
Please show us what configurations are made to prevent the EICAR file and how did the network receive the EICAR file? Also, try changing the AV engines and let us know the results.
Thanks
Sachin Gurung
Team Lead | Sophos Technical Support
Knowledge Base | @SophosSupport | Video tutorials
Remember to like a post. If a post (on a question thread) solves your question use the 'This helped me' link.
I can confirm that changing from Real Time to Batch blocks the EICAR file from downloading. Change it back to Real Time and the file downloads but is apparently stripped out and empty.