Sophos Endpoint threat cleanup and malware remediation
Threat cleanup begins after initial alert triage. It is not merely an assessment or status change: it contains a confirmed or plausible threat, remediates it with the supported Sophos functions, and proves the outcome. The preceding triage process is covered in Manage Sophos Fusion alerts and Account Health.
Sign in to Sophos Fusion before following the management paths in this guide.
Prerequisites and decision points
Before making changes, identify the incident owner, obtain approval for isolation or restart, agree a maintenance window, assign backup and recovery responsibility, and establish a secure communication channel. The available actions depend on the Sophos Fusion role, license, and platform:
- Device scans and events are available for managed computers. According to Sophos, the scan action is not available for an XDR Sensor.
- Administrator isolation requires EDR, XDR, or MDR. Threat Graphs are available with Endpoint, EDR, XDR, and MDR and currently support Windows and macOS only, but Sophos does not create a graph for PUA detections made by Deep Learning (ML). Threat Graph actions such as Search for item and Clean and block require XDR.
- The endpoint must be able to reach Sophos Fusion. A scan requested for an offline device starts when the device reconnects; if a scan is already running, the new request is ignored.
- The high-severity Real-time protection disabled alert is raised when real-time protection has been off for more than 2.5 hours. Keep it enabled at all times. Disable it briefly for an investigation only when directed by Sophos Support; then re-enable it and verify protection status and agent communication.
- Adaptive Attack Protection applies enhanced protection for a fixed period: 24 hours by default and no more than 72 hours. Sophos Fusion provides controls to extend the active period or end it early. A device has red health while this mode is active, so record the cause rather than interpreting that expected health effect as failed cleanup.
- Before cleanup or restart, preserve the alert ID, device, user, detection name, time window, process, path, SHA-256, Sophos action, and relevant graph and event details. Handle evidence in accordance with your incident-response and data-protection processes.
Workflow: contain, remediate, prove
- Record the scope: Open the description and detection under My Environment > Alerts, then correlate device events, process relationships, and other affected users or systems.
- Assess activity: If malware is active, recurs, or could spread through shares or accounts, isolate the device after approval. Sophos Fusion management remains available through My Environment > Computers & Servers > Computer > Summary > Actions > Isolate. Alternatively, start from My Products > Endpoint > Computers.
- Interpret the Sophos result: Blocked, quarantined, and automatically cleaned are distinct states. The alert description, events, and Threat Graph indicate whether cleanup, a scan, or a restart remains necessary.
- Perform the supported action: Process the specific alert type as described below. Do not use a broad exception or improvise file, registry, or script cleanup.
- Address cause and reach: Check the entry route, triggering account, vulnerable application, network shares, and matching detections or hashes on other managed devices.
- Validate technically: Check completion events, failed-cleanup alerts, protection status, agent communication, and repeat detections.
- Decide residual risk: Remove isolation and close the graph or alert only after documented technical acceptance.
When Sophos requires further remediation
Malware not cleaned up or manual cleanup required
According to Sophos, Malware not cleaned up means malware has not been removed after 24 hours; the detection may have come from a scan that does not provide automatic cleanup. Sophos identifies a policy-scheduled scan with automatic cleanup enabled as the principal action. For Manual cleanup required or Running malware not cleaned up, follow the alert description and contact Sophos Support if required. Treat running malware as a potentially active incident, not as an invitation to invent deletion steps.
For Recurring infection, Sophos has already performed cleanup but the infection has returned. The visible detection is therefore not the whole cause: include hidden components, persistence, repeated delivery, and other devices in the scope.
For Malicious traffic detected, malicious network traffic was detected, potentially headed to a command-and-control server involved in a botnet or another malware attack. Open the alert description and preserve the destination IP or domain, port, protocol, triggering process, user, and time window. If communication continues, isolate the device, perform the scan or cleanup action specified in the alert, and investigate the process chain, persistence, and matching connections from other devices. Close the alert only when the associated threat has been remediated and the traffic does not recur; escalate to Sophos Support if the cause remains unclear or the traffic returns.
Scan or restart pending
For Computer scan required to complete cleanup, open the computer and start Scan. The current path is My Environment > Computers & Servers > Computer > Summary > Actions > Scan; Sophos also documents My Products > Endpoint > Computers as an alternative starting point. Verify completion under Reports > Logs > General logs > Events using Scan completed and successful cleanup events. Failed cleanup appears under My Environment > Alerts.
Reboot required to complete cleanup means the threat has only been partially removed. Restart within the approved maintenance window, then verify agent contact, completion events, and repeat detections. A restart alone establishes neither the entry route nor the scope.
PUA
A PUA is not necessarily malware. For a confirmed unwanted PUA, Sophos provides Cleanup PUA(s) in the selected alert. Cleanup might not be available on a network share because the agent lacks permission; involve the responsible system or share owner rather than deleting files locally without evidence.
Authorize PUA on the alert page allows the PUA on all computers. Authorize a business-required PUA only after checking the vendor, signature, hash, source, and behavior; for a limited need, prefer a narrowly scoped policy exception. See Configure Sophos Fusion exclusions safely.
Ransomware and remote origin
For Ransomware detected or Ransomware attacking a remote machine detected, Sophos blocks file-system or share write access and, under the documented conditions, automatically cleans workstations. If cleanup does not occur, Sophos requires submission of a sample through the official process.
Remotely-run ransomware detected means ransomware is running on another computer and attacking network shares. The reporting protected device is therefore not necessarily the source. Correlate the reported IP for the relevant time with asset, DHCP/NAT, account, and share data; investigate the source device and reachable neighboring systems. If Sophos Fusion manages the source, verify that Protect document files from ransomware (CryptoGuard) is active in its policy.
Use Threat Graph deliberately
Under Threat Analysis Center > Threat Graphs > Graph, Summary, Suggested next steps, and Analyze show the origin, spread, and affected processes or files. Isolate this device may be available for high-priority cases. With XDR, you can use Request latest intelligence, which uploads files from the device to Sophos for analysis, Search for item, and, after confirming maliciousness, Clean and block. Sophos describes Clean and block as cleaning found Windows devices and blocking the item on all Windows devices; document its reach and platform limits before confirmation.
Remove isolation only after the threat has been addressed. Access to Admin Isolated Devices requires the Super Admin or Admin role, or a custom role with the corresponding permission. For multiple administrator-isolated devices, the current path is Global Settings > Protection and Remediation > Allow and Block > Network > Admin Isolated Devices > Remove from Isolation. Automatically isolated devices do not appear in this list.
Validation and residual risk
Cleanup is successful only when the evidence is consistent:
- the required scan or restart has completed and successful cleanup events are present,
- there are no related failed-cleanup alerts or new matching detections,
- the agent has checked in recently and the required protection components and policy are plausible,
- the process chain, persistence indicators, entry point, and relevant accounts have been assessed,
- other potentially affected devices or shares have been checked,
- every exception is narrow, approved, time-limited, and assigned to an owner.
The resulting decision is close, continue monitoring, or escalate. Do not remove isolation while persistence is unknown, devices are unreachable, cleanup is unconfirmed, the remote source is unexplained, or possible data access remains unresolved. Use Reset health status only after correcting the problem; Sophos explicitly states that it does not clean up threats.
Escalate safely
Engage Sophos Support or the incident-response team if running malware cannot be cleaned, infection recurs, the ransomware source or scope remains unclear, Sophos Fusion actions fail, the agent does not provide reliable data, or a suspected false positive cannot be substantiated. Provide the tenant and region, alert and Threat Graph IDs, device, detection, UTC time window, hash or signature, Sophos actions and results, affected scope, relevant event or diagnostic data, and containment already applied. Submit samples only through the approved Sophos channel and in accordance with data classification.