Surprised by Sophos Home and Ransomware

Status
Not open for further replies.
W

Wave

Thread author
Try looking at results from a product which actually has some decent zero-day protection components like HitmanPro.Alert, Emsisoft (Behaviour Blocker), Kaspersky (Application Control) and the results should be decent.

(based on my personal opinions).
 
W

Wave

Thread author
Why are you surprised. It's a free tool with basic protection. It doesn't offer the ransomware protection their enterprise products offer(HMPA).
I think he was expecting the product to have some sort of special Emsisoft Behaviour Blocker replication hidden deep in the internals of the Sophos software, but was surprised when he realised it turned out to just be part of a dream he had last night. :D :p
 

SHvFl

Level 35
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Nov 19, 2014
2,346
I think he was expecting the product to have some sort of special Emsisoft Behaviour Blocker replication hidden deep in the internals of the Sophos software, but was surprised when he realised it turned out to just be part of a dream he had last night. :D :p
Sophos free product is like all free products. Good up to a point but you need a layered protection because a free product doesn't cover all angles. If it did how would they sell their premium products and who would pay the expenses of the company.
Those poor developers and personnel need to eat.
 
R

Rodney74

Thread author
Lots of people swear by Sophos. Yes it's basic protection, but many people use it, and don't layer.

I personally believe in a security setup that is light and limited as possible, and even though that is my goal I have WinAnti-Ransom, Bitdefender Free AV, and ZoneAlarm Firewall Pro. This runs very light on my PC.
 
W

Wave

Thread author
Sophos free product is like all free products. Good up to a point but you need a layered protection because a free product doesn't cover all angles. If it did how would they sell their premium products and who would pay the expenses of the company.
Those poor developers and personnel need to eat.
I was joking earlier? :D :) And I agree with you, they have to limit their free version to make profit, money makes the world go round! (well I can think of other stuff that keeps us sane but let's stick to money for the purpose of this forum sake hahaha)
 

SHvFl

Level 35
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Nov 19, 2014
2,346
I was joking earlier? :D :) And I agree with you, they have to limit their free version to make profit, money makes the world go round! (well I can think of other stuff that keeps us sane but let's stick to money for the purpose of this forum sake hahaha)
Yeah i know you were joking and you are right money make the world go round. Something has to do it.
Also the less features you offer the less bugs and issues you will have making a free product easier to maintain and support.
 

Azure

Level 28
Verified
Top Poster
Content Creator
Oct 23, 2014
1,712
I think he was expecting the product to have some sort of special Emsisoft Behaviour Blocker replication hidden deep in the internals of the Sophos software, but was surprised when he realised it turned out to just be part of a dream he had last night. :D :p
Well...

They did say this
"I agree with you ScottKrautkramer when you say we need to make this more known to our users. I work with the Marketing on Sophos Home and we're trying to do just that. I do want to make it clear though that Sophos Home does have HIPS/zero day protections. It's a combination of signature and behavioral based protections like you find in Sophos Cloud. Patrick MacGyver thanks for helping to clarify that. Good quote."
Sohpos Home for Windows Need more layers of Security? - Sophos Home for Windows - Sophos Home - Sophos Community
 

tim one

Level 21
Verified
Honorary Member
Top Poster
Malware Hunter
Jul 31, 2014
1,086
It is evident the lack of a behavioral blocking system, but also a problem of signature detection at real-time level.
Sophos Home edition has failed but we do not forget that also enterprise solutions have failed against many ransomware variants.

If we consider a possible lack of BB, another problem is the lack of valid signatures, but above all, the main problem of the static detection is the capacity of the ransomwre to change its code to not be identified by antivirus signature based. The ransomware, follow this rule for every campaign (or even multiple times inside that ) by changing its code using obfuscation and polymorphism in order to not be detected.
 

DC47561

Level 3
Verified
Feb 3, 2017
102
This is exactly why I use a limited user account with additional restrictions - anti-executable rules.
 
  • Like
Reactions: SHvFl

vemn

Level 6
Verified
Malware Hunter
Well-known
Feb 11, 2017
264
Why are you surprised. It's a free tool with basic protection. It doesn't offer the ransomware protection their enterprise products offer(HMPA).
Agree.. free tool is the key.. lol.
*fingers-crossed* hoping all free versions eventually will add in ransomware protection module (behavior monitoring/memory inspection etc). Too wild a dream? lol
 
  • Like
Reactions: SHvFl
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top