Skip to content
Avanet

Safely test Sophos Endpoint protection features

An installed endpoint with a green status proves that the agent generally reports itself as healthy. It does not verify the specific controls covered here: Download Reputation, real-time scanning, Sophos behavioral protection simulations for Malicious Behavior, Adaptive Attack Protection and Critical Attack Warning, and the expected Web Control policy. After a rollout, platform change or significant policy adjustment, use harmless test artefacts to check these supported test paths.

Real malware has no place in a functional test. Use only the Security Test Tools cited by Sophos and the standard EICAR file. Run the test on an approved pilot device, not a production server or shared file location.

What a complete test demonstrates

Approve every test at several levels:

  1. The expected local protection action occurs.
  2. The user receives the appropriate notification where the platform supports it.
  3. Central shows an event with the correct device, user, policy and time.
  4. The artefact is blocked or cleaned up and is not left executable.
  5. Health State and communication remain plausible after the test.

A single EICAR detection confirms only the scan path being tested. It does not prove Exploit Protection, Ransomware Protection, Web Control, DLP or XDR telemetry.

Real-time and on-demand scanning with EICAR

EICAR is a standardised, harmless test file that antivirus products deliberately detect as malware. Obtain it directly from eicar.org or create it as a local test file according to EICAR’s instructions.

For the on-access test, save or copy the file into a local test directory. For the on-demand test, start a scan of that directory. The expected outcome is a block or cleanup action and the corresponding Central event.

Do not send the file by email, place it on a production network share or include it in a software deployment system. Otherwise, other protection layers or systems will be tested instead of the intended endpoint.

Download Reputation on Windows

To run the harmless reputation test, open Endpoint Security and select Low Reputation EXE, then follow the current instructions. Download the file in the browser, but do not run the EXE unless those instructions explicitly require it. This check works only on Windows endpoints. Expect a Download Reputation warning or the action configured in the effective policy.

If the test produces no response, check the Agent Mode, Threat Protection policy, browser download path, proxy, HTTPS inspection and event time. A browser or proxy block before the endpoint is not a successful Download Reputation test.

Sophos behavioral protection simulations

Under Endpoint Security, sophostest.com provides harmless Sophos test artefacts. Use only the files and instructions currently offered there; do not copy scripts, payloads or direct links from forums. For Malicious Behavior, expect exactly BehaveTest_2d. In the two-stage Adaptive Attack Protection test, the endpoint first visibly enters AAP mode, then a Disrupt_* rule is triggered. The Critical Attack Warning test generates BehaveTest_2c; Sophos notes that the related Central warning may be delayed.

Malicious Behavior detection names follow a fixed pattern: in Tactic_1a (T1234.123), the prefix identifies the MITRE tactic and the T... number the closest matching technique or sub-technique; mem/family-a in Tactic_1a (T1234.123 mem/family-a) identifies a malware family detected in memory. Disrupt_, Cleanup_ and Prevent_ indicate blocking active attacker behavior, removing related artefacts, and preventing interference with protection features. Before escalation, correlate the event type, complete detection name and MITRE ID with the test name, device and time. This interpretation does not apply to the legacy Detect malicious behavior (HIPS) feature.

Run one simulation at a time on the pilot device and stop it afterwards. If the expected evidence is missing, do not retry with third-party tools. Check the license, operating system, installed components, effective Threat Protection policy, agent health and Central time window, then escalate to Sophos Support with the test name, time and device.

Web Protection and Web Control

Under Sophos Security Test Tools > Web Security & Control, harmless destinations are available for spyware, malware and category tests. First decide which layer should block access: Endpoint Web Control, DNS Protection, Protected Browser or a network firewall can display different block pages.

Test at least one allowed, warned and blocked action as well as one HTTPS request. Then compare the Endpoint event with the effective policy. A block page without a matching Endpoint event may have come from another protection layer.

Test control policies with business scenarios

Application Control, Peripheral Control and DLP do not require a malware test file. Instead, use one controlled permitted and prohibited business scenario for each:

  • a known test application from the selected Application Control category,
  • one approved and one unapproved USB or MTP storage device,
  • a synthetic DLP file with test data and the actual transfer method in use.

The tests must cover not only blocking, but also the event, user notification, exception and rollback. Do not use real customer data, credentials or production confidential documents.

Document the result

A rollout acceptance record includes the date, device, operating system, Agent Mode, agent version, effective policies, test source, expected and actual result and the corresponding Central events. Resolve discrepancies before the next rollout stage.

Do not create continuous automated EICAR traffic for ongoing control. Monitor Health, update and policy status continuously; perform complete functional tests after relevant changes and periodically on a defined test device.

Cleanup and escalation

After each test, remove every remaining test file, archive and synthetic DLP record from the test directory. Do not restore quarantined objects; first preserve the Central event and local notification as evidence. Revert temporary test exclusions and policy assignments, update the pilot device and check it again. Accept the test only when the expected event identifies the correct device and time, the artefact is no longer accessible, and Health and communication are normal again.

If the device remains red, cleanup fails, or the expected event is absent after a reasonable synchronization window, do not disable protection or keep repeating the test. Isolate the device if compromise is suspected; record the time, timezone, device ID, agent version, policy, test name and screenshots, and escalate to internal security operations or Sophos Support. This article defines a procedure; it does not claim that a test was run in any specific tenant.

Frequently asked questions

Does EICAR prove that every Sophos protection feature is working?

No. EICAR confirms only the specific file-scanning path tested. Test Web Control, Exploit Protection, Ransomware Protection, DLP and XDR separately.

Can the test be performed on an XDR Sensor?

The XDR Sensor does not provide Sophos Anti-Malware or Web blocking. The existing third-party product must cover protection tests in this mode; verify Sophos sensor functions through telemetry, Live Discover and isolation.