{"id":20794,"date":"2022-12-13T11:22:07","date_gmt":"2022-12-13T19:22:07","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2022\/12\/13\/news-14527\/"},"modified":"2022-12-13T11:22:07","modified_gmt":"2022-12-13T19:22:07","slug":"news-14527","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2022\/12\/13\/news-14527\/","title":{"rendered":"Sophos Endpoint Tamper Protection Thwarts a Sophisticated Ransomware Attack"},"content":{"rendered":"<p><strong>Credit to Author: Sally Adam| Date: Tue, 13 Dec 2022 18:13:11 +0000<\/strong><\/p>\n<div class=\"entry-content lg:prose-lg mx-auto prose max-w-4xl\">\n<p>Tamper Protection is one of those powerful but lesser-known protection capabilities that works away quietly in the background. It prevents adversaries from turning off defenses in <a href=\"https:\/\/www.sophos.com\/en-us\/products\/endpoint-antivirus\/\">Sophos Intercept X Endpoint<\/a>, our market leading EDR solution, so they can deploy their payloads.<\/p>\n<p>Recently, Tamper Protection was thrust into the spotlight when it was key to Sophos <a href=\"https:\/\/news.sophos.com\/en-us\/signed-driver-malware-moves-up-the-software-trust-chain\/\">identifying and thwarting a novel ransomware attack<\/a> in which the attackers used a malicious driver signed with a legitimate Windows Hardware Compatibility Publisher digital certificate from Microsoft. The driver specifically targets processes used by major endpoint detection and response (EDR) software packages and we have strong confidence that it is associated with the attack group behind Cuba ransomware.<\/p>\n<p>Creating a malicious driver from scratch and getting it signed by a legitimate authority is very difficult, but it\u2019s also incredibly effective because the driver can essentially carry out any processes without question.<\/p>\n<p>Virtually all EDR software is vulnerable to this new driver but, fortunately, the Tamper Protection capability in Sophos Endpoint ensured that the adversary\u2019s attempt to disable our protection failed. This enabled other protection technologies in Sophos Endpoint to successfully halt the ransomware attack. <a href=\"https:\/\/www.sophos.com\/en-us\/products\/managed-detection-and-response\/incident-response-services\">Sophos Rapid Response<\/a>, our incident response experts, stepped in to successfully neutralize the incident, and the investigation triggered a comprehensive collaboration between Sophos and Microsoft to take action and address the threat.<\/p>\n<h2>The importance of layered protection<\/h2>\n<p>With cybersecurity there is no silver bullet, no single protection capability that will stop every threat. Each attack combines a different set of tactics, techniques, and procedures (TTPs), and as a result there is no \u2018one size fits all\u2019 protection solution. What works against one attack, will not always work against the next one.<\/p>\n<p>To optimize your defenses you need layered protection: multiple sophisticated security capabilities with each playing its part in defending against advanced attacks. Sophos Endpoint is packed with these layers of protection, including:<\/p>\n<ul>\n<li>Credential theft protection that prevents unauthorized system access<\/li>\n<li>Exploit protection to stop the techniques adversaries use<\/li>\n<li>Anti-ransomware protection which identifies and blocks malicious encryption attempts<\/li>\n<li>And, of course, tamper protection<\/li>\n<\/ul>\n<p>Combining multiple layers of protection technologies enables us to optimize our customers\u2019 defenses. Testament to the quality of our defenses \u2013 and the power of layered protection \u2013 we stop 99.98% of threats up-front (AV-TEST average score), and recently earned perfect scores in <a href=\"https:\/\/news.sophos.com\/en-us\/2022\/11\/16\/sophos-earns-perfect-scores-in-se-labs-endpoint-protection-report\/\">SE Labs endpoint protection report<\/a>.<\/p>\n<p>Plus, these layers generate high-quality signals that the defenders in <a href=\"https:\/\/www.sophos.com\/en-us\/products\/managed-detection-and-response\/contact-request\">Sophos MDR<\/a>, our market-leading 24\/7 managed detection and response service, can use to swiftly identify, investigate and respond to adversarial activities before damage is done.<\/p>\n<h2>Check Tamper Protection is enabled with the Sophos Account Health Check<\/h2>\n<p>The Sophos Account Health Check enables Sophos Endpoint EDR and server protection customers to quickly identify and address configuration issues with their Sophos protected devices. Available to all customers that manage their Sophos security through the Sophos Central platform, it performs a number of key checks:<\/p>\n<ul>\n<li>Software assignment \u2013 do devices have all the right software assigned to them?<\/li>\n<li>Threat policy \u200b\u2013 are policies using recommended settings?<\/li>\n<li>Exclusions\u200b \u2013 are any exclusions creating significant exposure?\u200b<\/li>\n<li>Tamper protection \u2013 has tamper protection been disabled on any computers or servers?<\/li>\n<\/ul>\n<p>Our newly released \u2018Fix Automatically\u2019 feature allows IT teams to easily enable Tamper Protection for all devices, elevating security posture in just a couple of clicks.<\/p>\n<p>Access the Account Health Check from the main Sophos Central navigation panel and use the intuitive dashboard to remediate any issues.<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/AHC-Screenshot.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88774 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/AHC-Screenshot.png\" alt=\"\" width=\"640\" height=\"340\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/AHC-Screenshot.png 3566w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/AHC-Screenshot.png?resize=300,159 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/AHC-Screenshot.png?resize=768,408 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/AHC-Screenshot.png?resize=1024,544 1024w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/AHC-Screenshot.png?resize=1536,816 1536w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/AHC-Screenshot.png?resize=2048,1088 2048w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/a><\/p>\n<p>While recommended settings are automatically applied with all new Sophos deployments, over time issues can develop as devices are added and removed, team members change, and different software subscriptions are purchased. We recommend customers review the health check at least every three months to maintain a healthy environment.<\/p>\n<p>&nbsp;<\/p>\n<\/p><\/div>\n<p><a href=\"https:\/\/news.sophos.com\/en-us\/2022\/12\/13\/sophos-endpoint-tamper-protection-thwarts-a-sophisticated-ransomware-attack\/\" target=\"bwo\" >http:\/\/feeds.feedburner.com\/sophos\/dgdY<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/EP-Blog-Post-image.png\"\/><\/p>\n<p><strong>Credit to Author: Sally Adam| Date: Tue, 13 Dec 2022 18:13:11 +0000<\/strong><\/p>\n<p>Customers were protected from a novel attack that used a malicious, signed driver to which virtually all EDR software is vulnerable.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10377],"tags":[11179,28137,24562,3765],"class_list":["post-20794","post","type-post","status-publish","format-standard","hentry","category-security","category-sophos","tag-endpoint","tag-heath-check","tag-products-services","tag-ransomware"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/20794","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=20794"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/20794\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=20794"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=20794"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=20794"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}