Sophos Advances Endpoint Detection and Response (EDR)

Sophos Press Release

New Version of Sophos’ EDR Provides Industry’s First Solution Designed for Security Analysts and IT Administrators Now with Live Discover and Response Capabilities

SophosLabs Research Finds Kingminer Botnet Now Using EternalBlue Exploit to Spread Malware; New Sophos EDR Custom-Built Query Engine Detects Indicators of Compromise

OXFORD, U.K. – June 9, 2020 – Sophos, a global leader in next-generation cybersecurity, today unveiled an updated version of its Endpoint Detection and Response (EDR), the first solution designed for both security analysts and IT administrators, available now in Sophos Intercept X Advanced and Intercept X Advanced for Server with EDR. Significant advancements and new capabilities make it faster and easier than ever before for security analysts to identify and neutralize evasive threats, and for IT administrators to proactively maintain secure IT operations to reduce risk.

Sophos also published new research, “An Insider View into the Increasingly Complex Kingminer Botnet,” underscoring the use of servers in carrying out attacks and the importance of threat intelligence in detecting such activity. The opportunistic Kingminer botnet attempts to gain server access by brute-forcing login credentials, and Sophos now finds that it’s using the infamous EternalBlue exploit in an attempt to spread malware among other attack mechanisms. The new version of Sophos EDR offers a custom-built query engine to detect indicators of compromise.

Kingminer shares many of the attributes that advanced ransomware attackers use to gain access, evidence of the need for EDR with the ability to hunt active attacks. As Sophos recently discovered in its State of Ransomware 2020 survey, only 24% of organizations breached in a ransomware incident were able to detect the intrusion and stop it before it was able to encrypt their files. Sophos’ new EDR capabilities help security and IT teams detect threats and breaches that could otherwise take months to uncover.

“Cybercriminals are raising the stakes, stopping at nothing to capitalize on expanded attack surfaces as organizations increasingly move to the cloud and enable remote workforces. Servers and other endpoints are all too insufficiently protected, creating vulnerable entry points that are ripe for attackers to exploit,” said Dan Schiappa, chief product officer, Sophos. “Sophos EDR helps identify these attacks, preventing breaches and shining light on otherwise dark areas. Live querying capabilities only available with Sophos EDR in Intercept X enable organizations to search for past indicators of compromise and determine the current system state. This level of intelligence is critical in understanding changing attacker behaviors and reducing attacker dwell time.”

Sophos EDR now provides powerful visibility across an organization’s entire estate, enabling security and IT practitioners to quickly answer critical threat hunting and IT security operations questions, and easily respond. New features include:

  • Live Discover: Pinpoint past and present activity with up to 90 days of data retention. Out-of-the-box ready SQL queries allow administrators to answer threat hunting and IT questions, and can be selected from a library of pre-written options and fully customized by users. This flexible query engine provides access to some of the most granular and detailed endpoint activity recordings that are further enhanced with Sophos' deep learning technology
  • Live Response: Remotely respond and access endpoints and servers using a command line interface to perform further investigation and remediate issues; easily reboot devices, install and uninstall software, terminate active processes, run scripts, edit configuration files, run forensic tools, isolate machines, and more

“Sophos EDR is a force multiplier that gives me the tools I need to do the job of an entire team without adding additional headcount,” Ryan Miller, chief information security officer, Mission Search. “This new version drastically reduces the time it takes to detect and respond to incidents, saving me on average four to five hours per day. Easy to use SQL queries simplify the previously complex and time intensive process of investigating suspicious activity, and allow me to perform searches that are completely unique to my network. Unlike other EDR tools that are limited in what they can see and report on, Sophos EDR provides complete visibility into all of my endpoints with vast capabilities not available anywhere else. As the chief information security officer of a Joint Commission certified healthcare staffing firm, I am extremely sensitive to any time delays in receiving warnings related to suspicious activity that could be a precursor of a malicious attack designed to obtain sensitive data.”

Sophos EDR is powered by Sophos’ deep learning neural network, which is trained on hundreds of millions of samples to look for threat indicators. Security analysts and IT administrators also gain on-demand access to curated threat intelligence from SophosLabs, which tracks, deconstructs and analyzes more than 400,000 malware samples every day.

“The new version of Sophos EDR gives us the threat intelligence and security expertise needed to know how to prioritize and where to start our investigations so we can remediate issues requiring urgent action,” said Sam Heard, president, Data Integrity Services. “The new features combine the strongest protections with the industry’s most powerful EDR to automatically detect, prioritize and investigate threats, so we can remotely respond to incidents with speed and precision. The pre-configured queries in particular are a game changer not only for security pros to threat hunt, but for IT admins to do their everyday jobs.”

Available now in Sophos Intercept X Advanced with EDR and Intercept X Advanced for Server with EDR at no added cost, Sophos EDR will support Windows, MacOS and Linux. Its new Live Discover and Live Response features are easily managed in the threat analysis center on the cloud-based Sophos Central platform for real-time information sharing with Sophos’ entire portfolio of next-generation cybersecurity solutions via its unique Synchronized Security approach. Combined with Sophos Managed Threat Response (MTR), a fully-managed threat hunting, detection and response service, organizations can boost capabilities with human analysis for a further evolved approach to proactive security protection.

关于 Sophos

Sophos 是先进网络安全解决方案的全球领导者和创新者,包括托管式侦测与响应 (MDR) 和事件响应服务,各种端点、网络、电子邮件和云安全技术,帮助企业防御网络攻击。作为最大的纯网络安全供应商之一,Sophos 帮助全球超过 500,000 家企业和超过 1 亿用户抵御主动攻击对手、勒索软件、网络钓鱼、恶意软件等。Sophos 的服务和产品通过 Sophos Central 云管理控制台连接,并得到内部跨领域威胁情报部门 Sophos X-Ops 的支持。Sophos X-Ops 情报优化整个 Sophos Adaptive Cybersecurity Ecosystem 自适应网络安全生态体系,包括一个中央数据湖,为客户、合作伙伴、开发人员和其他网络安全与信息技术供应商提供一组丰富的开放 API。Sophos 为需要全托管并即使可用的安全解决方案的企业提供网络安全即服务,客户还可以直接利用 Sophos 的安全运行平台管理其网络安全,或者采用混合方法,为内部团队补充 Sophos 服务(包括威胁追踪与修复)。Sophos 通过世界各地的经销商合作伙伴和托管服务供应商 (MSP) 销售。Sophos 总部位于英国牛津。如欲了解更多信息,请访问 www.sophos.com