Sophos have identified an issue where Windows 10 1903 (May 2019 update) machines may hang when logging off if Sophos Intercept X or Exploit Prevention are running alongside certain third party security applications. A ML/PE-A detection is generated by Sophos Intercept X’s Machine Learning (ML) engine when it identifies malicious PE (Portable Executable) files. Simple Pricing – Select one of our bundles, which include the virtual/hardware appliance of your choice plus all the security services you need. Cloud-Based – Firewall management and selected reporting options come at no extra cost. More Than a Firewall – Our add-ons provide easy options for plug and play site-to-site connectivity, Wi-Fi access, and much more. Sophos Intercept X employs a comprehensive defense-in-depth approach to endpoint protection. This combination of the industry’s most advanced AI-based prevention, and most complete exploit and ransomware protection, protects your business better than any other endpoint protection solution. Add expertise, not headcount.
Intercept X has released, and enabled, a new protection feature called Dynamic Shellcode Protection. This is an exciting new addition to Sophos Intercept X, designed to prevent active adversaries from achieving one of their most sought-after goals: using remote access agents to gain “hands on keyboard” privileges.
According to Mark Loman, Director of Engineering at Sophos “The Dynamic Shellcode Protection is unique to Sophos. It basically puts a HARD LIMIT on ANY application to what memory they can allocate. It impacts EVERY process on the box, even Windows’ own processes! I am not overstating things when I say that imposing this limit is incredibly, incredibly bold of Sophos”.
Sophos Intercept X Review
You can read an article on Sophos News talking about this new feature.
Sophos Central Intercept X
For a technical deep dive into this attack technique and how Dynamic Shellcode Protection stops it, read Mark Loman’s excellent article also on Sophos News.
Sophos Intercept Home
Feel free to share the above articles with customers.