So the marketing materials claim we can "hunt for threats" and "create custom IOCs" with this platform. I've been handed a specific file hash and a C2 domain that our threat intel team insists is active in our sector, and of course the immediate demand is to "just make Sophos look for it." After digging through the console for an hour, I'm left wondering if this is actually a flexible tool or just another checkbox feature.
I need to create a custom IOC scan that will periodically check our endpoints for this hash and any communication attempts to that domain. The documentation is predictably vague, alternating between breathless hype about AI and painfully basic UI walkthroughs. Has anyone actually implemented something like this in production, or is this another case where the sales demo magic evaporates when you try to do real work?
Specifically, I need to know:
1. Is this done via the Central Dashboard, the on-prem Enterprise Console, or through some obscure API that requires three support tickets to unlock?
2. What's the actual scan mechanism? Does it run a scheduled filesystem crawl, or is it only evaluated on-access? The latency here matters.
3. How do you validate it's working without actually infecting a test machine? I'm not inclined to drop known-bad hashes in production just to see if the expensive EDR blinks.
If you've gone through this rigmarole, I'd appreciate the gritty details. Show me the actual configuration steps, not the brochure. For example, if it's API-driven, a concrete cURL or PowerShell snippet would be more useful than a philosophical treatise on threat hunting.
-- cynical ops
Your k8s cluster is 40% idle.