Sophos advances Endpoint Detection and Response

New version of Sophos’ EDR provides industry’s first solution designed for security analysts and IT administrators now with Live Discover and Response capabilities

Sophos, a leader in next-generation cybersecurity,  unveiled an updated version of its Endpoint Detection and Response (EDR), the first solution designed for both security analysts and IT administrators, available now in Sophos Intercept X Advanced and Intercept X Advanced for Server with EDR. Significant advancements and new capabilities make it faster and easier than ever before for security analysts to identify and neutralize evasive threats, and for IT administrators to proactively maintain secure IT operations to reduce risk. Sophos also published new research, “An Insider View into the Increasingly Complex Kingminer Botnet,” underscoring the use of servers in carrying out attacks and the importance of threat intelligence in detecting such activity. The opportunistic Kingminer botnet attempts to gain server access by brute-forcing login credentials, and Sophos now finds that it’s using the infamous EternalBlue exploit in an attempt to spread malware among other attack mechanisms. The new version of Sophos EDR offers a custom-built query engine to detect indicators of compromise. Kingminer shares many of the attributes that advanced ransomware attackers use to gain access, evidence of the need for EDR with the ability to hunt active attacks. As Sophos recently discovered in its State of Ransomware 2020 survey, only 24% of organizations breached in a ransomware incident were able to detect the intrusion and stop it before it was able to encrypt their files.

Sophos’ new EDR capabilities help security and IT teams detect threats and breaches that could otherwise take months to uncover. “Cybercriminals are raising the stakes, stopping at nothing to capitalise on expanded attack surfaces as organizations increasingly move to the cloud and enable remote workforces. Servers and other endpoints are all too insufficiently protected, creating vulnerable entry points that are ripe for attackers to exploit,” said Dan Schiappa, chief product officer, Sophos. “Sophos EDR helps identify these attacks, preventing breaches and shining light on otherwise dark areas. Live querying capabilities only available with Sophos EDR in Intercept X enable organizations to search for past indicators of compromise and determine the current system state. This level of intelligence is critical in understanding changing attacker behaviors and reducing attacker dwell time.” Sophos EDR now provides powerful visibility across an organization’s entire estate, enabling security and IT practitioners to quickly answer critical threat hunting and IT security operations questions, and easily respond. New features include:

– Live Discover: Pinpoint past and present activity with up to 90 days of data retention. Out-of-the-box ready SQL queries allow administrators to answer threat hunting and IT questions, and can be selected from a library of pre-written options and fully customized by users. This flexible query engine provides access to some of the most granular and detailed endpoint activity recordings that are further enhanced with Sophos’ deep learning technology

– Live Response: Remotely respond and access endpoints and servers using a command line interface to perform further investigation and remediate issues; easily reboot devices, install and uninstall software, terminate active processes, run scripts, edit configuration files, run forensic tools, isolate machines, and more

Sophos EDR is powered by Sophos’ deep learning neural network, which is trained on hundreds of millions of samples to look for threat indicators. Security analysts and IT administrators also gain on-demand access to curated threat intelligence from SophosLabs, which tracks, deconstructs and analyzes more than 400,000 malware samples every day. Available now in Sophos Intercept X Advanced with EDR and Intercept X Advanced for Server with EDR at no added cost, Sophos EDR will support Windows, MacOS and Linux. Its new Live Discover and Live Response features are easily managed in the threat analysis center on the cloud-based Sophos Central platform for real-time information sharing with Sophos’ entire portfolio of next-generation cybersecurity solutions via its unique Synchronized Security approach. Combined with Sophos Managed Threat Response (MTR), a fully-managed threat hunting, detection and response service, organisations can boost capabilities with human analysis for a further evolved approach to proactive security protection.

See more news from Sophos here.

About Security Buyer

Security Buyer is the leading authority in global security content, delivering expert news, in-depth articles, exclusive interviews, and industry insights across print, digital, and event platforms. Published 10 times a year, the magazine is a trusted resource for professionals seeking updates and analysis on the latest developments in the security sector.

To submit an article, or for sponsorship opportunities, please contact our team below.

Rebecca Spayne picture 2025

Rebecca Spayne

Managing
EDITOR

Georgina Turner image

Georgina Turner

Sales
Manager

Afua Akoto image - Security Buyer

Afua Akoto

Marketing Manager

Read the Latest Issue

Follow us on X

Follow us on X

Click Here

Follow us on LinkedIn

Follow us on LinkedIn

Click Here

Advertise here

Reach decision makers and amplify your marketing

Advertise here

Click Here

Related News

Sophos

Joe Levy Appointed CEO of Sophos

Sophos announced that Joe Levy is now chief executive officer (CEO) of the company. Levy has been acting CEO since Feb. 15
sophos

Sophos Anticipates AI-Based Attack Techniques

Sophos, a provider in innovating and delivering cybersecurity as a service, today released two reports about the use of AI in cybercrime
Sophos

Sophos supports hybrid shift

AP6 Series to support the shift to hybrid environments with a new generation of remotely managed Wi-Fi 6 access points

Sophos to Kick-off Multi-country Roadshow in the Middle East

Sophos announced that is kicking off a multi-country roadshow for channel partners in the Middle East. The events will take place in Qatar
sophos

Ransomware Attacks on Education Institutions

Sophos has published a new sectoral survey report, The State of Ransomware in Education 2022. The findings reveal that education institutions

Sophos central management of XG Firewall now available through early access programme

Sophos have announced that its next-generation Sophos XG Firewall is now available on Sophos Central through an Early Access Programme.
Sophos

Sophos central management of XG Firewall now available through early access programme

Sophos have announced that its next-generation Sophos XG Firewall is now available on Sophos Central through an Early Access Programme.

Sophos introduces lateral movement protection to XG Firewall to stop advancing cyberattacks

New lateral movement protection exposes blind spots on network switches or LAN segments with innovative Sophos Synchronised Security technology
Sophos honours Top Performing Channel Partners at its EMEA Partner Conference in Lisbon, Portugal

Sophos honours Top Performing Channel Partners at its EMEA Partner Conference in Lisbon, Portugal

Sophos honours Top Performing Channel Partners at its EMEA Partner Conference in Lisbon, Portugal. Sophos presented awards to six of its top performing…
Scroll to Top