Notifications
Clear all
Topic starter
16/07/2026 6:33 pm
I was reviewing our cloud server logs and noticed unusual CPU spikes. It didn't match any of our scheduled tasks. I remembered Sophos Intercept X has that Live Discovery feature, so I decided to give it a try.
I ran a search for processes with high CPU usage over a longer period. It quickly pointed me to a suspicious, disguised process. Using the isolate feature, I cut off its network access instantly while I investigated. It was a cryptominer hiding in a temp directory. The workflow from detection to isolation was surprisingly straightforward. Has anyone else used this for similar threat hunting? I'm curious about other real-world use cases.
Still learning.