Tamper With Sophos AV Registry Keys
Description
Detects tamper attempts to sophos av functionality via registry key modification
Query · sigma
selection: TargetObject|contains: - \Sophos Endpoint Defense\TamperProtection\Config\SAVEnabled - \Sophos Endpoint Defense\TamperProtection\Config\SEDEnabled - \Sophos\SAVService\TamperProtection\Enabled Details: DWORD (0x00000000) condition: selection
Known false positives
- Some FP may occur when the feature is disabled by the AV itself, you should always investigate if the action was legitimate