Skip to content
Avanet

Handle Sophos Endpoint alerts and Account Health

A Sophos Fusion (formerly Sophos Central) alert is an investigation task, not automatically a confirmed security incident. Sign in to Sophos Fusion and, under My Environment > Alerts, start with the severity, affected device, detection name, and associated events. A status action belongs at the end: it removes neither malware nor an unsafe configuration.

Quick workflow for alert triage

  1. Define the alert: Record severity, status, device, time, Detection Name, and the number of grouped events.
  2. Review context: Examine alert details, associated events, device status, Last active, user, path, process, hash, and any Threat Graph.
  3. Contain active risk: If the risk is ongoing or lateral, isolate the endpoint through the approved incident process. Sophos Endpoint threat cleanup and malware remediation explains the complete remediation workflow.
  4. Handle the alert type: Perform cleanup, a scan, a restart, a policy correction, or a false-positive review as required by the notification.
  5. Validate technically: Check new events, cleanup and scan results, agent health, and the affected application.
  6. Only then complete it: Change the workflow status only after documenting the cause, action, result, and owner.

High requires rapid review. Medium is not automatically harmless: a required scan, incomplete cleanup, or remotely run ransomware can also require further work.

Do not confuse health, alerts, and events

ElementWhat it tells you
EventAn individual observation on a device or in Sophos Fusion.
AlertAn assessed notification that requires investigation or action and can contain multiple events.
Device HealthThe aggregated protection and operational state of a device.
Account HealthA Sophos Fusion-wide assessment of selected Sophos recommendations.

These signals are not calculated in the same way. An endpoint can be green after a detection was successfully blocked or quarantined and still have an alert worth investigating. Conversely, a health problem can exist without an open threat alert. A green state therefore confirms only the status reported by Sophos, not that the device is completely safe.

The Account Health Check deliberately belongs in a separate Sophos Fusion-wide review. Use Sophos Fusion Account Health Check correctly covers score formulas, Auto-Fix, Snooze, policy reset, Agent Mode, Tamper Protection, and PDF export. For endpoint alerts, the rule remains: a score or status change never replaces technical validation on the affected device.

Prioritise threat protection alerts

Sophos lists the following notifications among those requiring particular urgency:

  • Real-time protection disabled: Real-time protection has been disabled for more than 2.5 hours. A short diagnostic directed by Sophos Support is the only plausible exception.
  • Malware not cleaned up: Detected malware could not be removed after 24 hours even though automatic cleanup is available. Manual cleanup required means automatic cleanup is unavailable; Running malware not cleaned up means a running malicious or suspicious program could not be cleaned up. Treat the last case as the highest priority.
  • Malicious traffic detected: Suspicious network traffic may indicate command-and-control or other malware activity.
  • Recurring infection: Remediation was attempted, but the infection returned. Investigate for hidden or as-yet undetected components.
  • Ransomware detected or ransomware affecting network shares: Establish the source, target systems, and possible lateral impact immediately.
  • Outbreak detected: Sophos reports an outbreak when a device experiences 100 detections in 24 hours. Volume must not replace root-cause analysis.

Medium alerts such as Potentially Unwanted Application detected, Computer scan required to complete cleanup, Reboot required to complete cleanup, and Remotely-run ransomware detected also need a definite outcome. An offline device performs a requested scan when it comes back online. If a scan is already running, the new request is ignored and the existing scan continues.

Investigate by threat type

Ransomware and remote ransomware

For Ransomware detected, check whether Sophos stopped the process, restored affected files, ran a memory scan, and generated a Threat Graph. If cleanup is incomplete, keep the case open.

After approval under the data-classification process, select or drag a suspicious file directly into the SophosLabs Intelix portal; supply its password if the file is protected. Analyze starts the analysis without opening the file on the affected endpoint. The unauthenticated Intelix Guest Portal accepts one file per submission; after signing in with a valid Sophos ID, a batch can contain up to ten files. Accept the terms of use and privacy notice before transferring data.

Review the Static Analysis report first for its classification and findings. If behavioural analysis is required, Submit for dynamic analysis creates a sandbox report. Disagree is a Beta feature and may not be available for every report or account. Where it is offered, a user with a validated Support Portal profile can provide customer, product, and sample data plus the source and investigation context and follow the available escalation steps. Depending on eligibility, the flow may offer escalation to Sophos Support; using Disagree does not guarantee case creation, so confirm any Support case reference separately. If the portal is unavailable, the upload fails, or cleanup remains unclear, keep the device isolated; Sophos Endpoint threat cleanup and malware remediation covers the complete remediation and Support workflow.

Distinguish the two remote scenarios:

  • Remotely-run ransomware detected: Another system is attacking the share. Identify the source device from the reported IP address and determine whether Sophos Fusion manages it and CryptoGuard is active.
  • Ransomware attacking a remote machine detected: The reported endpoint itself is attempting to encrypt files on other systems. Sophos blocks its write access to network shares, but the source device still requires a complete investigation.

Blocked share access is containment, not proof of closure. Include adjacent devices, accounts used, and reachable shares in the incident scope.

Browser, exploit, and IPS detections

For a web browser attack, the Threat Graph identifies the related IP and URL connection. Assess the location and block it at the corporate firewall where appropriate. If the user entered a password, change it through the established identity process. For banking or payment access, also check for unusual account activity.

For an exploit, Sophos stops the detected activity, notifies the user, scans processes in memory, and generates a Threat Graph. Review the graph for origin, spread, and affected processes and files. A recurring cause requires more than awareness training: inspect the application, patch level, and exploit protection.

An IPS alert concerns inbound or outbound network traffic. An IPS exclusion removes matching traffic from inspection and must therefore be narrowly scoped. Configure firewall allowances separately. Configure Sophos Endpoint exclusions safely explains the safe use of detection, process, path, and network exclusions.

Deep learning and PUAs

Deep-learning malware detections use a prefix such as ML/. Detected PE files are quarantined, so device health may already be green. Restore and allow a file only when its origin, signature or hash, and business purpose reliably establish that it is legitimate.

A Potentially Unwanted Application (PUA) is not necessarily malicious but can create privacy, security, or operational risks in a business. Sophos normally blocks and cleans up PUAs automatically. Cleanup can fail when, for example, the location is read-only, a scan or restart is required, the file is inside an archive, or no cleanup instruction is available. In that case, investigate the alert and Threat Graph, remove dependent processes, and then verify the scan and events.

Authorize PUA on the Alerts page allows the PUA on all computers. For a limited business requirement, the safer choice is the narrowest possible policy exclusion. On Windows and Linux, a legitimate application can be allowed by certificate, SHA-256, or path depending on the platform; Sophos recommends the certificate on Windows. A hash applies only to that file version, whereas a path covers everything in the specified location. This allow-application feature is unavailable on macOS.

Handle false positives safely

“Known application” is not sufficient evidence for an allow decision. Before adding an exclusion, verify the vendor, signature, hash, source, affected version, Detection Name, and observed behaviour. If uncertainty remains, keep detection active and provide Sophos Support with the sample and case data.

  • Application: On supported platforms, Allow this application is available in the device details under Events > Details. A certificate is tied more closely to the publisher, SHA-256 to exactly one version, and a path to a storage location. The allowance is global for all users and computers and excludes the application from further threat detections, but exploit, ransomware, and malicious-behaviour checks remain active.
  • Exploit: Exclude this Detection ID from checking applies to all users and computers and is stored in Global Exclusions. If only certain users or devices are affected, use a targeted Threat Protection policy instead. Sophos describes excluding the entire application from every exploit check as the riskiest option and a last resort.
  • Ransomware: Exclude this Detection ID from checking in the event details applies globally to users and computers and is added to Global Exclusions. Approve that scope before confirming it.

Every exclusion needs an owner, rationale, target group, expiry date, and functional test. Remove it after the vendor provides a fix.

Route non-security alerts correctly

Installation, policy, peripheral, VDI, and restart issues are not automatic proof of malware, but they still need a technical owner:

Configure Sophos Fusion alert emails and notifications covers delivery, recipients, frequencies, and escalation. Email is only the transport channel; the alert, events, and device state in Sophos Fusion remain authoritative.

Closure criteria and Support handover

An alert is technically complete only when:

  • the cause and affected scope are known,
  • cleanup, scan, restart, or configuration correction is demonstrably complete,
  • no new related events occur,
  • device health and required protection functions are credible,
  • any exclusion is tested, time-limited, and owned,
  • the record includes the Alert ID, time, device, Detection Name, and result.

Sophos Support is appropriate when cleanup repeatedly fails, an infection returns, the agent appears damaged, or a well-founded suspected false positive cannot be allowed safely. Include the Alert ID, device, time range, Detection Name, hash, signature, relevant logs, Threat Graph findings, actions already taken, and desired outcome.

Frequently asked questions

Does Mark As Resolved remove a threat?

No. The status documents the workflow. Remediation and validation must happen first.

Can a PUA be allowed for only one group?

Yes. Use a targeted policy exclusion. Authorize PUA on the Alerts page instead applies to all computers.

Does green device health prove there is no incident?

No. Sophos can report green after blocking or quarantining a detection. You must still review the alert, events, Threat Graph, and possible follow-on impact.