{"id":35434,"date":"2019-06-04T19:59:56","date_gmt":"2019-06-04T11:59:56","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=35434"},"modified":"2019-06-04T19:59:58","modified_gmt":"2019-06-04T11:59:58","slug":"sophos-boosts-intercept-x-for-server-with-endpoint-detection-and-response","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2019\/06\/04\/sophos-boosts-intercept-x-for-server-with-endpoint-detection-and-response\/","title":{"rendered":"Sophos boosts Intercept X for Server with Endpoint Detection and Response"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Sophos,\u00a0a leader in network and endpoint security, announced Intercept X for Server with Endpoint Detection and Response (EDR). By adding <\/strong><a href=\"https:\/\/www.sophos.com\/en-us\/products\/server-security.aspx\"><strong>EDR to Intercept X for Server<\/strong><\/a><strong>, IT managers can investigate cyberattacks against servers, a sought-after target due to the high value of data stored there. Cybercriminals frequently evolve their methods and are now blending automation and human hacking skills to successfully carry out attacks on servers. This new type of blended attack combines the use of bots to identify potential victims with active adversaries making decisions about who and how to attack.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The SophosLabs Uncut article, <a href=\"https:\/\/news.sophos.com\/en-us\/2019\/05\/30\/worms-deliver-cryptomining-malware-to-web-servers\/\">Worms Deliver Cryptomining Malware to Web Servers<\/a>, underscores how easy it is for cybercriminals to leverage\nbots to discover soft targets. The report explains an automated attack that can\ndeliver a wide range of malicious code to servers that, as a class, tend to lag\nbehind normal update cycles. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Anatomy of a Blended Cyberattack<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once the bots identify\npotential targets, cybercriminals use their savvy to select victims based on an\norganization\u2019s scope of sensitive data or intellectual property, ability to pay\na large ransom, or access to other servers and networks. The final steps are\ncerebral and manual: break in, evade detection and move laterally to complete\nthe mission. This could be to quietly sneak around to steal intelligence and\nexit unnoticed, disable backups and encrypt servers to demand high-roller\nransoms, or use servers as launch pads to attack other companies. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cBlended cyberattacks, once a\npage in the playbook of nation state attackers, are now becoming regular\npractice for everyday cybercriminals because they are profitable. The\ndifference is that nation state attackers tend to persist inside networks for\nlong lengths of time whereas common cybercriminals are after quick-hit money\nmaking opportunities,\u201d said Dan Schiappa, chief product officer, Sophos. \u201cMost\nmalware is now automated, so it\u2019s easy for attackers to find organizations with\nweak security postures, evaluate their payday potential, and use hand-to-keyboard\nhacking techniques to do as much damage as possible.\u201d <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sophos explains how blended\ncyberattacks work in this video, Intercept X for Server with Endpoint Detection\nand Response (EDR).&nbsp; <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Sophos Intercept X for Server with EDR<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With Sophos Intercept X for\nServer with EDR, IT managers at businesses of all sizes now have visibility\nacross an entire estate. This allows them to proactively detect stealthy\nattacks, better understand the impact of a security incident and quickly\nvisualize the full attack history.&nbsp; <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cWhen adversaries break into\na network, they head straight for the server. Unfortunately, the\nmission critical nature of servers restrains many organizations from making\nchanges, often significantly delaying patch deployment. Cybercriminals are\ncounting on this window of opportunity. If organizations do fall victim to an\nattack, they need to know the full context of what devices and servers were hit\nin order to improve security as well as answer questions based on stricter\nregulatory laws. Knowing this information accurately the first time can help\nbusinesses resolve issues much faster and prevent them from a repeat data\nbreach,\u201d said Schiappa. \u201cIf regulators rely on digital forensics as evidence of\nlost data, then businesses can rely on the same forensics to demonstrate their\ndata has not been stolen. Sophos Intercept X for Server with EDR provides this\nrequired insight and security intelligence.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sophos Intercept X for Server\nwith EDR expands Sophos\u2019 offering of EDR, which was first <a href=\"https:\/\/www.sophos.com\/en-us\/press-office\/press-releases\/2018\/10\/sophos-adds-endpoint-detection-and-response-to-intercept-x-advanced.aspx\">announced for endpoints in October 2018<\/a>. Sophos EDR is powered by deep learning technology for\nmore extensive malware discovery. Sophos\u2019 deep learning neural network is\ntrained on hundreds of millions of samples to look for suspicious attributes of\nmalicious code to detect never-before-seen threats. It provides broad, expert\nanalysis of potential attacks by comparing the DNA of suspicious files against\nthe malware samples already categorized in <a href=\"https:\/\/www.sophos.com\/en-us\/labs.aspx\">SophosLabs<\/a>. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cOur research shows that concerns about security and skills\nshortages are top of mind with IT and security leadership at many\norganizations,&#8221; said Fernando Montenegro, senior industry analyst at 451\nResearch. \u201cWith cyber threats coming from multiple vectors and at a constant\nrate, businesses can\u2019t afford to have a gap in their visibility. We believe\nthat, as security teams look for opportunities to enhance their protection,\nbringing together EDR features and visibility across endpoints and servers is a\npositive step towards greater efficiency.\u201d <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With Sophos\u2019 EDR feature, IT\nmanagers also have on-demand access to curated intelligence from <a href=\"https:\/\/www.sophos.com\/en-us\/labs.aspx\">SophosLabs<\/a>, guided investigations into suspicious events, and\nrecommended next steps. To maintain full visibility into the threat landscape,\nSophosLabs tracks, deconstructs and analyzes 400,000 unique and previously\nunseen malware attacks each day. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cOur customers use Sophos\nIntercept X with EDR for their endpoints, and the feedback we\u2019ve had is that\nSophos\u2019 EDR is easy to implement, easy to use and easy to manage. This reduces\nthe skills needed to manage EDR and makes our customers much more effective at\ntheir protecting servers, a critical factor considering the high rate of\nattacks there,\u201d said Sam Heard, president of Data Integrity Services, a Sophos\npartner in Lakeland, Fla. \u201cWith EDR for servers, Sophos is building upon its\nindustry leading Intercept X endpoint protection. Sophos is also the only\nvendor to bring all of its security products together on one cloud-based\nmanagement platform, Sophos Central, and connect its endpoint and network\nprotection through Synchronized Security. Adding EDR for servers is yet another\nkey industry advancement that will protect our customers.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Pricing and\nAvailability<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Pricing and availability\ndetails are available from Sophos partners worldwide.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>By adding EDR to Intercept X for Server, IT managers can investigate cyberattacks against servers, a sought-after target due to the high value of data stored there. <\/p>\n","protected":false},"author":6,"featured_media":295,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[54,206],"class_list":["post-35434","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-security","tag-sophos"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/35434","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=35434"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/35434\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/295"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=35434"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=35434"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=35434"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}