Jump to content

Recommended Posts

Posted

We have Sophos Central with Intercept X deployed to our EndPoints. Yesterday we had an alert to say Ransomware had been detected on a machine. It said Sophos was cleaning it up. When we look at the details on Sophos Central all it states is that "CryptoGuard detected Ransomware in C:\Program Files (x86)\Microsoft Office\Office15\WINWORD.EXE"

 

No other information, no indication of the file that caused it.

 

We isolated the machine, wiped it and re-imaged it but it would be useful to know where the Ransomware came from.

 

Anyone else using Sophos Central with Intercept X know if it can provide this information?

Posted
If they didn't change it it writes to application event log I think 911?

 

Steve

 

where do we find this log please?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...