Skip to content
Notifications
Clear all

My results after a pen-test with Intercept X running: Surprising gaps found.

1 Posts
1 Users
0 Reactions
4 Views
(@miket)
Eminent Member
Joined: 1 week ago
Posts: 13
Topic starter   [#3357]

Just wrapped up a penetration test for one of our AWS-hosted web applications, which has Sophos Intercept X Advanced with EDR deployed across all endpoints. I have to say, the results were... illuminating, and not entirely in a good way.

We ran a standard web app and network pen-test from an external provider. Intercept X caught and blocked several obvious, automated exploit attempts at the server level—no surprise there, and the logs were clear. However, the tester's more sophisticated, low-and-slow post-exploitation activity on a compromised test server flew under the radar for a concerning amount of time. We saw lateral movement attempts and credential dumping that weren't flagged until after the fact, during the EDR review. The "surprising gap" for me was in the real-time behavioral detection during that critical window.

Here's my breakdown of the numbers and context:

* **Environment:** 12 EC2 instances (Linux & Windows), Intercept X Advanced agent on all.
* **Test Duration:** 48 hours of active testing.
* **What it caught immediately:** 14 blocked web shell upload attempts, 9 exploit payload blocks. Solid.
* **What it missed in real-time:** The post-breach activity chain (3 distinct techniques over about 90 minutes). The EDR console *had* the data for forensic review, but no alerts fired during the test itself.
* **Estimated "dwell time" in this scenario:** ~90 minutes until we manually reviewed the timeline based on the tester's report.

This feels like a classic "alert vs. detect" scenario. The product has the data, but the default policies might not be tuned aggressively enough for a highly sensitive environment. I'm left wondering if we need to crank up sensitivity (and accept more noise) or layer in another cloud-specific runtime protection tool.

Has anyone else done similar offensive security tests with Intercept X? What were your findings, and how did you tune your policies afterward? I'm especially curious about cost-effective ways to close this gap without just throwing another expensive SaaS solution at the problem.

—Mike


Numbers don't lie – vendors do.


   
Quote