Showing posts with label Anti Virus. Show all posts
Showing posts with label Anti Virus. Show all posts

Sophos #How to override ACS compatibility problem

If you try to install Sophos on O.S. that not support Azure Code Signing this will not receive Sophos updates and/or install it

KB5022661—Windows support for the Trusted Signing (formerly Azure Code Signing) program

In the past there was a build that fixed problem but is is no longer supported

October 12, 2021—KB5006669 (OS Build 14393.4704) - EXPIRED

to override problem you might arrange to download new Trusted CA Certificate ( Microsoft Identity Verification Root Certificate Authority 2020) that it is related to ACS from this repository:

PKI Repository - Microsoft PKI Services

start --> certmgr.msc --> local computer --> Trusted Root Certification Authorities --> Certificates

In this way Sophos installation works properly.



Sophos #How to uninstall & install software client/server

Here they are some useful articles that indicate on how to safely uninstall Sophos Antivirus,

Sophos Central Endpoint and Server: Uninstall Sophos using the command line or a batch file

https://support.sophos.com/support/s/article/KBA-000003469?language=en_US

Remove Sophos Central without tamper protection password

https://community.sophos.com/community-chat/f/discussions/134537/remove-sophos-central-without-tamper-protection-password

SophosZap: Frequently asked questions (to be used only as last chance)

https://support.sophos.com/support/s/article/KBA-000006929?language=en_US

Sophos Central Endpoint: Automate the software deployment to Windows devices

https://support.sophos.com/support/s/article/KBA-000003140?language=en_US

Sophos Central Endpoint: Installer command line options for Mac and Windows

https://support.sophos.com/support/s/article/KBA-000004840?language=en_US


[update 2025.08.20]

If your tamper protection is not recognized you might fix following this procedure:

1. Execute command line prompt with administrative rights

2. cd "C:\Program Files\Sophos\Endpoint Defense\"

3. You will be located in C:\Program Files\Sophos\Endpoint Defense\

4. Run SEDcli.exe -TPoff password (where password is the one that you view on Sophos Central console)


Sophos #XDR feature, adaptive attack protection

About sophos Intercept X Advanced with XDR and other Sophos features I take note, on blog, about some related articles:

Sophos Intercept X Advanced with XDR: Help with Forensic Snapshots

https://support.sophos.com/support/s/article/KBA-000006333?language=en_US+

Sophos XDR-enabled devices continually capture data related to processes, files, networks, and other system activities. When threat detection occurs, a snapshot file of current activity is created on the device's disk. This snapshot helps generate the Threat Case in Sophos Central, which attempts to piece together the threat chain of an attack and identify related activities.

Data Lake uploads

https://docs.sophos.com/central/customer/help/en-us/ManageYourProducts/ThreatAnalysisCenter/LiveDiscover/DataLakeUploads/index.html

Sophos XDR: Getting Started with XDR and Data Lake Hydration

https://techvids.sophos.com/watch/JWndawT866eCh9gVXTNE2K

Sophos Intercept X: Adaptive attack protection

https://support.sophos.com/support/s/article/KBA-000008632?language=en_US

This protection feature is part of the malicious behavior protection capability in the Sophos endpoint. It consists of a series of technique-focused behavioral rules intended to disrupt the actions of a threat actor.

Admin Isolated Devices

https://docs.sophos.com/central/customer/help/en-us/ManageYourProducts/GlobalSettings/IsolatedComputers/index.html


[UPDATE 2025.06.05]

Sophos Endpoint: Adaptive Attack Protection Gets Even Better

https://news.sophos.com/en-us/2024/04/29/sophos-endpoint-adaptive-attack-protection-gets-even-better/

ANTIVIRUS #ERROR Request: WinHttpSendRequest failed: 12029 #SOPHOS

If you have a server/client 8.1/2012 facing this problem, indicated in device sophos log, you should follow this article installing correct Microsoft Patch:

https://support.sophos.com/support/s/article/KB-000039876?language=en_US

Antivirus - Windows 7 high memory usage due to SophosFileScanner.exe

Since yesterday night several Windows 7 O.S. was affected by high memory usage due to SophosFileScanner.exe process.

CPU usage was constantly at 100%.

Sophos support indicated that problem was due to this reason:

  • During a staged roll-out of an updated machine learning model, customers began reporting excess CPU usage.  As it became apparent that the performance issues were related to this silent update, the decision was made to roll back to the previous version. 
  • The problematic model version identifier is 20230629.  The rolled back version is 20230202.  The rollback should be completed imminently. 




Security - Sophos AV stop definitions updates #WORKAROUND & #DETAILS **JULY 2023**

During these latter weeks Sophos released new AV version. (Core Agent 2023.1/Server Core Agent 2023.1 )

PROBLEM

  • This letter Sophos version require that these O.S. have propter September 2021 patches installed.
  • In case you are not on track with MS updates or Windows version it will occur this problem
  • End point Sophos definition updates will stop working
    • Client: Early of July 2023
    • Server: End of July 2023

AFFECTED SYSTEMS AND DEVICES

    • Windows computers:
      • From early-June 2023, Windows 10 (x64) operating systems and above that don't support Azure Code Signing (ACS) will fail to complete the upgrade process to Core Agent 2023.1 and above.
    • Windows servers:
      • From late-July 2023, Windows 2016 operating systems and above that don't support Azure Code Signing (ACS) will fail to complete the upgrade process to Server Core Agent 2023.1 and above.

  WORKAROUND APPLICABLE TO POSTPONE PROBLEM

  • The Software Packages functionality in Sophos Central can be used to assign devices to a Fixed term support (FTS) version.
  • The current version for Windows computers and servers is FTS 2022.4.3.2 and can be assigned to devices for the duration of time it takes to apply the Windows Security Updates.
  • Note: There is an expiry date for all software package versions after which devices will stop updating.
    • The expiry date for FTS 2022.4.3.2 on Windows computers is October 10, 2023.
    • The expiry date for FTS 2022.4.3.2 on Windows servers is November 14, 2023.
  • To achieve this goal you must modify Update Management policy as indicated in below screenshots.

 


APPENDIX

Full details on required updates can be found in Microsoft’s official KB5022661 on this topic. 
https://support.microsoft.com/en-gb/topic/kb5022661-windows-support-for-the-azure-code-signing-program-4b505a31-fa1e-4ea6-85dd-6630229e8ef4

In addition to having the required Windows Security Updates to verify modules signed by Azure Code Signing, devices must have the "Microsoft Identity Verification Root Certificate Authority 2020" certificate authority (CA) installed.

Generally impacted O.S. are Windows 10/11 and Windows 2016/2019/2021 server versions.

Legacy O.S. are not impacted:

Windows 8.1

  1. Windows Server 2012 R2
  2. Windows Server 2012
  3. Windows 7.0 SP1
  4. Windows Server 2008 R2
  5. Windows Server 2008 SP2 

New Installation

From the 18th of April 2023, new installations to operating systems that don't support Azure Code Signing (ACS) will fail.

Sophos - How to recover a tamper protected system

If you have pc that was deleted on Sophos Central Console Antivirus installation cannot be done unless you do not follow this Sophos procedure:

https://support.sophos.com/support/s/article/KB-000036125?language=en_US

SQL - Antivirus Exclusions

I am taking note about SQL required Antivirus Exclusions:

https://support.microsoft.com/it-it/topic/come-scegliere-il-software-antivirus-in-esecuzione-su-computer-che-eseguono-sql-server-feda079b-3e24-186b-945a-3051f6f3a95b

Process exclusions

%ProgramFiles%\Microsoft SQL Server\<Instance_ID>.<nome istanza>\MSSQL\Binn\SQLServr.exe

%ProgramFiles%\Microsoft SQL Server\<Instance_ID>.<nome istanza>\Reporting Services\ReportServer\Bin\ReportingServicesService.exe

%ProgramFiles%\Microsoft SQL Server\<Instance_ID>.<nome istanza>\OLAP\Bin\MSMDSrv.exe

%ProgramFiles%\Microsoft SQL Server\1xx\Shared\SQLDumper.exe

 

Directory (and sub-directories):

D:\Program Files\Microsoft SQL Server

 

File extentions:

SQL Server data files:

.mdf

.ldf

.ndf

 

SQL Server backup files

.bak

.trn


Sophos - Sophos Central APIs interaction

There is possibility, on Sophos Central, to create API user for task automating, remote tools interacting, like ticket creation, end point enumeration and so on.

Mainly you will be able to call Sophos Central APIs, here it is relative link:

https://developer.sophos.com/getting-started-organization


Antivirus - Sophos Audit Logs 90 days retention and SIEM integration

Sophos has 90 days Administrative Audit logs retention limit.

This limit could be overrided configuring  SIEM Tool.

Here they are relative articles

https://www.sophos.com/en-us/legal/sophos-central

https://support.sophos.com/support/s/article/KB-000036372?language=en_US

Antivirus - Sophos Ideas

I am taking note, on blog, about link where you might request new Sophos Features to be implemented

https://ideas.sophos.com/

Antivirus - Sophos Message Relay/Cache Manager #FIREWALL PORTS

Sophos Central endpoints has possibility, to update themselves, or send messages status, to a LAN server (that operate as Sophos Update Cache and Message Relay)

Alternatively Endpoints updates, themselves, to internet.

Here they are ports that are necessary to be opened (to permit previously behaviors)

https://support.sophos.com/support/s/article/KB-000035367?language=en_US

Hacker - Banking trojans

Zimperium recently published report about 10 most diffused home banking trojans, on Android OS, affecting more than 600 home banking apps.

This trojans are injected through harmless apps available on google store.

After that these apps are installed on mobile phones, and succesfully infected mobile devices, they show, to end users, similar home banking websites and work to intercept, user, password and one time passwords.

Here they are original articles

https://www.hwupgrade.it/news/sicurezza-software/trojan-bancari-e-emergenza-i-10-piu-diffusi-prendono-di-mira-app-scaricate-un-miliardo-di-volte_107688.html

https://www.forbes.com/sites/daveywinder/2022/04/09/these-6-dangerous-phone-apps-need-to-be-deleted-immediately/

REMARK This is why I still use hardware home banking token :)


<============>

About other Security/Hacker articles please review below blog sections:

https://www.alessandromazzanti.com/search/label/Hacker

https://www.alessandromazzanti.com/search/label/Security

Antivirus - Failed to install sme64: general error #Sophos Central

During these days we faced several devices with below error (on Sophos Central console)

Failed to install sme64: general error

Due to this error no updates was no longer received on endpoints.

This is Sophos article that fixed problem (certificate error)

https://support.sophos.com/support/s/article/KB-000043788?language=en_US

[update 2022.10.13]

Here it is a similar article that could be useful to be applied:

Sophos Central: Installation Failures due to Automatic Root Certificates Update being disabled
https://support.sophos.com/support/s/article/KB-000044065?language=en_US&name=KB-000044065

Sophos Central: Locate the Central Endpoint SSL certificate
https://support.sophos.com/support/s/article/KB-000036882?language=en_US&name=KB-000036882

Consider that, in my expirience, it could be useful, navigate to below weblink

https://trusted-root-g4.chain-demos.digicert.com/

or apply, original sophos article, related to below steps:

  1. Access the file referenced in the log:
    • C:\Program Files\Sophos\Sophos ML Engine\ML1\docmodel\<timestamp>\docmodel.dll
      • Note: In this case, <timestamp> is the name of the folder specific to the device.
  2. Access the Properties of the file docmodel.dll.
  3. Click the Digital Signatures tab.
  4. Select Sophos Ltd in the Signature list and click Details.
  5. Click View Certificate and then click the Install Certificate...
  6. On the Certificate Import Wizard select Store Location Local Machine and click Next.
  7. Leave the default option Automatically select the certificate store based on the type of certificate selected and click Next, then Finish.
  8. The message 'The import was successful' should be displayed. Click OK to exit the windows.
  9. Once imported, on the next update the Sophos ML Engine should install.

Veeam 11 - CDP (RPO= 0) and immutable storage backup against ransomware

 Veeam 11 released new features, here they are two that, imo, are very interesting:


  1. Continuous Data Protection (CDP) with RPO equal to zero:

    https://community.veeam.com/blogs-and-podcasts-57/veeam-v11-continuous-data-protection-cdp-configuration-265

    Using vSphere APIs for IO Filtering (VAIO)

  2. Immutable primary backup storage with a hardware-agnostic touch: enables you to store your short-term retention backups locally onsite for fast recovery with the protection of immutability. In addition, you can now tier those backups into an immutable object storage offering offsite, giving you additional protection against unforeseen malicious activity or accidental deletion. (protecting you against ransomware and malicious acts)

    The new hardened repositories are compliant with the SEC 17a-4(f), FINRA 4511(c), and CFTC 1.31(c)-(d) regulations. They can effectively prevent ransomware encryption or accidental/malicious deletions. The great thing about the new feature is it is based on "bring your own" Linux, so there is no vendor hardware lock-in.

    The new hardened Linux-based repositories with immutable backups will take ransomware protection to the next level for on-premises backup storage. Businesses can ensure business-critical backups are protected for the time specified for the immutable backup repository.

    https://www.veeam.com/blog/v11-immutable-backup-storage.html

    https://helpcenter.veeam.com/docs/backup/vsphere/hardened_repository.html?ver=110



Other articles: