Hi, the sophos adaptive learning system seems intriguing. However the wording that describes what data is transferred to sophos is rather vague and could be a cause for alarm in certain installations.
1. Is ATP an extension of av scanner and heuristic based or are we just blocking botnets for now?
2. If ATP is only processing known threats as described in the screenshot below then what is the added benefit of running ATP if AV scanner is already enabled and in essence already blocking those known threats?
Regards
Bill