Question Sophos antivirus engine

Please provide comments and solutions that are helpful to the author of this topic.

JB007

Level 26
Verified
Top Poster
Well-known
May 19, 2016
1,574
Hello :)

It's been a long time since I tested it...
When I tested it over 1 year ago, Web detection was very good. Its AV engine, however, had trouble detecting some forms of malware... And it had a lot of trouble cleaning up detected elements (either it didn't delete, or it didn't analyze everything, so the interceptor had to manage everything).
I don't know if it has evolved yet.
Hi @Shadowra
If this is your last test App Review - Sophos Home Premium 2021 ; the conclusion was not very good for Sophos :unsure:
 

Trident

Level 28
Verified
Top Poster
Well-known
Feb 7, 2023
1,737
Sophos Home, Waredot, digital-defender
Waredot and Digital-Defender only use Sophos's SDK base, which is very poor...
Waredot also uses Mal/Generic.S detection, but both antivirus programs have no access to Intercept X (ML/PE.A detection used only by Sophos Home / Sophos Endpoint).
The Sophos engine has very flexible configuration and it is up to the OEM to decide what they want to use. This includes emulation (behavioural genotype), cloud, remediation and others.
The config manual for OEMs is here:

The Mal/Generic-S (for those who don’t know) is Sophos hash-based cloud detection for High Risk (confirmed malicious files). There is Mal/Generic-R as well for low risk files such as hack tools.

The ML/PE detections are not produced by the AV engine (Sophos SAVI) but are produced by the InterceptX pre-execution machine learning. Third party vendors will not have access to that. They will have to complement the Sophos engine with other technologies. If they rely solely on Sophos, stay away from this product.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top