Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Sophos Fusion: Support Assistant overview

The Sophos Support Assistant answers your security and product questions directly within Sophos Fusion (formerly Sophos Central). It’s powered by Sophos documentation, knowledge base articles, user guides, and Community content, delivering relevant, up-to-date guidance to help you find answers and resolve issues faster. Learn how to access and use the Support Assistant. Ask questions and get expert answers in the Sophos Community.

Sophos MDR Onboarding: Case workflow

Detections that generate a new MDR Case trigger the Sophos MDR Operations Team to investigate and respond to identified threats in your environment. This workflow is examined, along with the importance of adding your MDR authorized contacts, and choosing the appropriate Threat Response Mode. The detection triage process is covered in a linked video. Ask questions and get expert answers in the Sophos Community.

Ungentlemanly behavior: Insights into a ransomware operation

They call themselves The Gentlemen Behind the name is one of the most active ransomware operations of the past 12 months, linked to 683 victims and a playbook built around compromised credentials, legitimate tools, rapid privilege escalation, and aggressive defense evasion. In this video, Susie Evershed and Rafe Pilling break down the latest research from Sophos Counter Threat Unit (CTU), revealing how some affiliates can move from initial compromise to ransomware deployment in less than 24 hours.

Sophos MDR: Define MDR Contacts in Sophos Central

A step-by-step tutorial showing you how to define your Sophos Managed Detection and Response (MDR) authorized contacts and threat response mode in Sophos Central. As a Sophos MDR customer, assigning authorized contacts lets you fully utilize the service. This instructs the Sophos MDR Operations team who to contact and how to take action during an active threat. You're prompted to take these steps in Sophos Central after activating a new Sophos MDR license, and you can modify this information at any time.

Threat Actor Dark Factory (The Future of Al Hacking?) | The X-Ops Brief

A criminal talked commercial AI models past their guardrails. Then stood up a "company" of AI agents that engineered, tested and refined malware. It began when Sophos analysts found a folder named "test" on an endpoint nobody recognised. Inside was the front end of a machine: Cobalt Strike profiles, a Telegram command channel, a hidden Sliver server behind Cloudflare and scripts written with the help of AI.