Skip to content
Back to skills

Sophos

ASecurity

Expert agent for Sophos Intercept X EDR. Covers deep learning malware detection, CryptoGuard anti-ransomware, exploit prevention, Adaptive Attack Protection, Sophos Central management, Sophos MDR service, and EDR/XDR capabilities. WHEN: \"Sophos\", \"Intercept X\", \"Sophos Central\", \"CryptoGuard\", \"Sophos EDR\", \"Sophos MDR\", \"deep learning detection\", \"Sophos XDR\", \"Sophos MTR\".

  • 4 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 24, 2026
securityjavascriptpythongojavashellbashsqlnodeawstesting

Works with

  • cli
  • api

Security analysis

A100/100

Scanned September 24, 2026

npx -y skills add chrishuffman5/domain-expert --skill sophos --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Sophos?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Sophos
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/chrishuffman5-sophos/badge)](https://www.skillsdirectory.com/skills/chrishuffman5-sophos)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: sophos
description: "Expert agent for Sophos Intercept X EDR. Covers deep learning malware detection, CryptoGuard anti-ransomware, exploit prevention, Adaptive Attack Protection, Sophos Central management, Sophos MDR service, and EDR/XDR capabilities. WHEN: \"Sophos\", \"Intercept X\", \"Sophos Central\", \"CryptoGuard\", \"Sophos EDR\", \"Sophos MDR\", \"deep learning detection\", \"Sophos XDR\", \"Sophos MTR\"."
license: MIT
---

# Sophos Intercept X

This skill covers Sophos Intercept X, the enterprise endpoint protection platform. It has deep expertise in deep learning malware detection, CryptoGuard anti-ransomware, exploit prevention techniques, Adaptive Attack Protection (AAP), Sophos Central management, EDR/XDR investigation, and the Sophos MDR managed service.

## How to Approach Tasks

When you receive a request:

1. **Identify the product tier** — Intercept X (NGAV only), Intercept X Advanced (+ EDR), or Intercept X Advanced with XDR (+ cross-domain telemetry). MDR service is an add-on.

2. **Classify the request type:**
   - **Deployment / management** — Sophos Central configuration and agent deployment
   - **Prevention configuration** — Deep learning, CryptoGuard, exploit prevention settings
   - **EDR investigation** — Threat analysis workflow and EDR queries
   - **Adaptive Attack Protection** — AAP triggers and behavior
   - **MDR service** — Sophos MDR capabilities and interaction model
   - **XDR hunting** — Cross-product threat hunting (XDR tier)

3. **Analyze** — Apply Sophos-specific reasoning. Sophos differentiates on deep learning (neural network-based) malware detection and CryptoGuard's real-time ransomware protection.

## Product Tier Overview

| Feature | Intercept X | Intercept X Advanced | Intercept X Advanced + XDR |
|---|---|---|---|
| Deep learning malware detection | Yes | Yes | Yes |
| CryptoGuard (anti-ransomware) | Yes | Yes | Yes |
| Exploit prevention (30+ techniques) | Yes | Yes | Yes |
| Adaptive Attack Protection (AAP) | Yes | Yes | Yes |
| AMSI integration | Yes | Yes | Yes |
| EDR (endpoint investigation) | No | Yes | Yes |
| Root Cause Analysis | No | Yes | Yes |
| On-demand endpoint queries | No | Yes | Yes |
| Cross-product XDR telemetry | No | No | Yes |
| Sophos Data Lake | No | No | Yes |
| Sophos MDR (managed service) | Add-on | Add-on | Add-on |

## Sophos Central Management

All Sophos products are managed through Sophos Central (`central.sophos.com`).

### Console Organization

```
Sophos Central
├── Dashboard — Overview of threats, devices, alerts
├── Devices — Managed endpoints, servers, mobile
├── Policies — Protection, threat protection, peripheral control
├── Alerts — Active threats and detections
├── Threat Analysis Center — EDR investigation interface
├── Logs & Reports — Audit logs, compliance reports
└── Settings — Licensing, admin accounts, API credentials
```

### Recommended Policy Structure

Organize policies by endpoint type:

| Policy | Scope | Protection Level |
|---|---|---|
| Workstations — Standard | General users | Full protection, all features |
| Workstations — Developer | Dev/power users | Adjust exploit prevention for dev tools |
| Servers — Critical | DCs, PKI, PAWs | Maximum protection |
| Servers — Application | App servers | Tune after testing; adjust for app-specific behavior |
| Test Group | Pilot devices | New settings before broad rollout |

## Agent Deployment

### Windows Installation

```powershell
# Download from Sophos Central: Devices > Download installers
# Or use Sophos Central Installer (auto-provisions with tenant)

# Silent install
.\SophosSetup.exe --quiet

# Verify installation
Get-Service -Name "Sophos Endpoint Defense" | Select Status
Get-Service -Name "SAVService" | Select Status

# Check agent version and status
"C:\Program Files\Sophos\Endpoint Defense\SophosED.exe" --version

# Force policy update
"C:\Program Files\Sophos\Sophos Network Threat Protection\bin\SNTPService.exe" --force-update
```

### macOS Installation

```bash
# Download from Sophos Central
sudo installer -pkg SophosInstall.pkg -target /

# Approve System Extension and Full Disk Access via MDM profile
# Required MDM profile keys:
# - com.sophos.endpoint.networkextension (System Extension)
# - /Library/Sophos Anti-Virus/ (Full Disk Access)

# Verify
sudo /Library/Sophos Anti-Virus/sophosav.sh status
```

### Linux Installation

```bash
# Download SophosLinux installer from Central
chmod +x sophosinstall.sh
sudo ./sophosinstall.sh

# Verify
sudo /opt/sophos-av/bin/savdstatus
systemctl status sophos-av.service
```

## Deep Learning Malware Detection

### How Deep Learning Works in Intercept X

Sophos uses a deep neural network (DNN) trained on hundreds of millions of malware and clean files. Key differences from traditional ML:

**Traditional ML (SVM/Random Forest):**
- Requires manually engineered features
- Limited generalization to new malware families
- Faster inference

**Deep Learning (Neural Network):**
- Automatically extracts features from raw file bytes
- Generalizes better to new malware variants
- Higher detection rate for novel malware
- Slightly higher computational cost

**Detection modes:**
- **Static** (pre-execution): Analyzes file before it runs. DNN scores the file; above threshold = block.
- **Dynamic** (behavioral): Monitors process behavior at runtime. Sophos's behavioral engine overlaps with but is separate from deep learning.

### Deep Learning Thresholds

Configurable sensitivity in threat protection policy:
- **Aggressive** — Higher detection rate, slight increase in false positives
- **Standard** — Balanced (recommended default)
- **Conservative** — Lower FP rate, may miss novel variants

If legitimate software is being blocked by deep learning, submit for analysis in Sophos Central (automatic FP correction) or add a file path / hash exclusion.

## CryptoGuard (Anti-Ransomware)

CryptoGuard monitors for mass file encryption patterns and terminates the responsible process chain.

### How CryptoGuard Works

1. **Monitor phase**: Tracks all file write operations in real-time
2. **Detection phase**: Detects patterns indicating encryption:
   - High file write rate
   - Files renamed with extension changes
   - Entropy increase in written data (encrypted data has high entropy)
   - Shadow copy deletion attempts
3. **Response phase**:
   - Terminates the process chain responsible for encryption
   - Restores recently encrypted files from CryptoGuard's protected backups
   - Generates alert in Sophos Central

**CryptoGuard file restoration:**
- CryptoGuard keeps protected copies of files before modification
- If ransomware is detected, those files are automatically restored
- Restoration is automatic — no manual rollback required
- Coverage: Files modified in the minutes before CryptoGuard triggers

### CryptoGuard Configuration

Navigate to: Policies > Threat Protection > Ransomware
- **Enable CryptoGuard**: On
- **Protected locations**: All locations (recommended) or specific paths
- **Protect Master Boot Record**: Enable (protects against MBR ransomware)

## Exploit Prevention

Sophos Intercept X includes 30+ exploit mitigation techniques targeting memory-based and code injection attacks.

### Exploit Prevention Techniques

| Category | Techniques |
|---|---|
| Memory protection | Stack pivot protection, ROP mitigation, heap spray protection |
| Code injection | Code cave utilization detection, dangerous API prevention |
| Privilege escalation | Local privilege escalation protection |
| Credentials | Credential theft prevention (LSASS protection) |
| Application-specific | Java JRE protection, Office applications, browsers |
| Network | Network stack protection, SEHOP |

### Configuring Exploit Prevention

Navigate to: Policies > Exploit Prevention

For each application (Java, Office, browsers, generic):
- **Detect** — Alert but do not block
- **Prevent** — Block and alert

**Common tuning scenarios:**
- Development tools triggering ROP mitigations: Add exclusion for specific dev tool path
- Custom in-house applications with non-standard memory behavior: Submit to Sophos for exclusion review

### AMSI (Antimalware Scan Interface) Integration

Sophos integrates with Windows AMSI to scan scripts before execution:
- PowerShell scripts (including cmdlets and ISE)
- JavaScript via Windows Script Host
- VBScript via Windows Script Host
- Office VBA macros (via AMSI 2.0)

AMSI integration catches obfuscated or fileless script-based attacks that would otherwise bypass file-based scanning.

## Adaptive Attack Protection (AAP)

AAP is Sophos's automatic hardening mode that activates when active attack behavior is detected on an endpoint.

### AAP Trigger Conditions

AAP activates automatically when Sophos detects patterns consistent with an active hands-on-keyboard attack:
- Suspicious reconnaissance commands (whoami, net group, nltest)
- Credential dumping attempts
- Lateral movement tool execution
- Multiple detection triggers within a short window

### What AAP Does When Active

When AAP activates on an endpoint:
1. **Increases protection** — Blocks behaviors normally only monitored (not blocked)
2. **Restricts process execution** — Tightens process execution restrictions
3. **Blocks dangerous techniques** — Activates additional exploit prevention rules
4. **Alerts SOC** — High-priority alert in Sophos Central
5. **Stays active** — Remains in hardened state until analyst manually deactivates

**AAP vs. normal mode:**
In normal operation, some detections are in "Detect" mode to reduce false positives. During AAP, these switch to "Prevent" automatically, creating a temporary high-security posture while an attack is in progress.

### Responding to AAP Activation

1. Navigate to: Alerts > filter for AAP alerts
2. Review affected endpoint and triggered behaviors
3. Initiate EDR investigation (Threat Analysis Center)
4. If confirmed attack: Isolate endpoint (Devices > select endpoint > Isolate)
5. After containment and remediation: Deactivate AAP manually to restore normal operations

## EDR Investigation (Advanced tier)

### Threat Analysis Center

The Threat Analysis Center (TAC) is Sophos's EDR investigation interface.

**Features:**
- **Root Cause Analysis** — Visual process tree showing attack chain origin
- **Live Discover** — On-demand endpoint queries (SQL-based, similar to Osquery)
- **On-demand endpoint scans** — Full scan or targeted threat hunt
- **Threat graphs** — Visual representation of threat activity

### Root Cause Analysis

Root Cause Analysis provides a visual process tree:
1. Navigate to: Alerts > click an alert > View Details > Root Cause Analysis
2. Review the process tree:
   - Entry point process (leftmost)
   - Child processes and file/network/registry activity per process
3. Use "See more" on each node for detailed event info
4. Review MITRE ATT&CK mapping for each detected technique

### Live Discover Queries

Live Discover allows SQL-based queries against endpoint state (Advanced tier+):

```sql
-- List running processes
SELECT name, pid, ppid, cmdline, path, on_disk, start_time
FROM processes
ORDER BY start_time DESC
LIMIT 100;

-- Network connections
SELECT pid, p.name, local_address, local_port, remote_address, remote_port, state
FROM process_open_sockets JOIN processes p USING (pid)
WHERE state = 'ESTABLISHED';

-- Scheduled tasks
SELECT name, action, path, enabled, hidden
FROM scheduled_tasks
WHERE enabled = 1;

-- Startup items
SELECT name, path, status, source
FROM startup_items;

-- Users
SELECT uid, gid, username, description, directory, shell
FROM users;
```

### On-Demand Endpoint Queries

For targeted investigation without Live Discover:
1. Navigate to: Devices > select endpoint
2. Actions > Request scan / Request data upload
3. Type options: Disk scan, Memory scan, Registry scan
4. Results available in Alerts / Threat Analysis Center after scan completes

## Sophos MDR (Managed Detection and Response)

Sophos MDR is a fully managed 24/7 detection and response service staffed by Sophos security analysts.

### MDR Service Levels

| Level | Capabilities |
|---|---|
| MDR Essentials | Monitoring, detection, notification, guided response |
| MDR Complete | + Full incident response by Sophos (contain, remediate) |
| MDR Complete + Response | + Proactive threat hunting by Sophos |

### MDR Interaction Model

**How MDR works:**
- Sophos analysts monitor your environment 24/7
- When a threat is detected, Sophos either:
  - **Alerts you** (Essentials) — Sophos notifies, you respond
  - **Responds on your behalf** (Complete) — Sophos contains and remediates with your approval
  - **Hunts proactively** (Complete+) — Sophos actively hunts for threats not yet alerting

**Customer responsibilities with MDR Complete:**
- Provide MDR team with admin access to Sophos Central
- Define your Response Authorization (what actions Sophos can take automatically)
- Maintain emergency contact information
- Review MDR Monthly Reports

**Response Authorization options:**
- `Notify only` — Sophos alerts but takes no action
- `Contain + Notify` — Sophos isolates compromised endpoints
- `Full Response` — Sophos contains and remediates fully

### MDR Portal and Communications

- MDR activity visible in Sophos Central: MDR > Cases
- Each investigated threat becomes a "Case" with full timeline and analyst notes
- Sophos communicates via in-portal comments + email + phone (for critical incidents)

## Device Isolation

Isolate compromised endpoints to prevent lateral movement:

```
Via Sophos Central:
1. Devices > select endpoint
2. Actions > Isolate device

Via API:
POST /endpoint/v1/endpoints/{endpointId}/isolate

Body: {"comment": "Isolated for incident investigation IR-2024-001"}
```

**Isolation behavior:**
- All network connections severed except Sophos Central communication
- Agent continues receiving policy updates and alerting
- Files can still be retrieved via Remote Desktop if network isolation allows it (typically not — use EDR data collection instead)

**Releasing isolation:**
1. Navigate to: Devices > select endpoint
2. Actions > Remove isolation
3. Add comment documenting reason for release

## Sophos API

Sophos Central provides a REST API for automation and SIEM integration.

```python
import requests

# Authenticate
auth_response = requests.post(
    "https://id.sophos.com/api/v2/oauth2/token",
    data={
        "grant_type": "client_credentials",
        "client_id": "CLIENT_ID",
        "client_secret": "CLIENT_SECRET",
        "scope": "token"
    }
)
token = auth_response.json()["access_token"]
tenant_id = "YOUR_TENANT_ID"

headers = {
    "Authorization": f"Bearer {token}",
    "X-Tenant-ID": tenant_id
}

# List alerts
alerts = requests.get(
    "https://api.central.sophos.com/common/v1/alerts",
    headers=headers,
    params={"pageSize": 100, "sort": "raisedAt:desc"}
)

# Isolate endpoint
endpoint_id = "endpoint_uuid_here"
requests.post(
    f"https://api.central.sophos.com/endpoint/v1/endpoints/{endpoint_id}/isolate",
    headers=headers,
    json={"comment": "Isolating for IR investigation"}
)
```

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…