Skip to content
Avanet

Safely test Sophos Endpoint protection features

An installed endpoint with a green status proves that the agent generally reports itself as healthy. It does not prove that Download Reputation, real-time scanning, Malicious Traffic Detection or the expected Web Control policy actually work on that device. After a rollout, platform change or significant policy adjustment, therefore test the complete protection path with harmless test artefacts.

Real malware has no place in a functional test. Use only the Security Test Tools cited by Sophos and the standard EICAR file. Run the test on an approved pilot device, not a production server or shared file location.

What a complete test demonstrates

Approve every test at several levels:

  1. The expected local protection action occurs.
  2. The user receives the appropriate notification where the platform supports it.
  3. Central shows an event with the correct device, user, policy and time.
  4. The artefact is blocked or cleaned up and is not left executable.
  5. Health State and communication remain plausible after the test.

A single EICAR detection confirms only the scan path being tested. It does not prove Exploit Protection, Ransomware Protection, Web Control, DLP or XDR telemetry.

Real-time and on-demand scanning with EICAR

EICAR is a standardised, harmless test file that antivirus products deliberately detect as malware. Obtain it directly from eicar.org or create it as a local test file according to EICAR’s instructions.

For the on-access test, save or copy the file into a local test directory. For the on-demand test, start a scan of that directory. The expected outcome is a block or cleanup action and the corresponding Central event.

Do not send the file by email, place it on a production network share or include it in a software deployment system. Otherwise, other protection layers or systems will be tested instead of the intended endpoint.

Download Reputation on Windows

Under Endpoint Security > Low Reputation EXE, sophostest.com provides a harmless reputation test. According to Sophos, this check works only on Windows endpoints. Expect a Download Reputation warning or the action configured in the effective policy.

If the test produces no response, check the Agent Mode, Threat Protection policy, browser download path, proxy, HTTPS inspection and event time. A browser or proxy block before the endpoint is not a successful Download Reputation test.

Malicious Traffic Detection

Sophos documents a harmless VBScript test that accesses a specific URL on sophostest.com. Copy the current command sequence directly from the Sophos KBA, save it as mtd.vbs on the pilot device and run it. When MTD is active, this creates a C2/generic-B detection.

The test requires the installed Sophos Network Threat Protection component. If no detection occurs, first check the Agent Mode, installed component, policy, proxy and actual URL accessibility. Delete the script after testing; do not distribute it as a general diagnostic tool.

Web Protection and Web Control

Under Sophos Security Test Tools > Web Security & Control, harmless destinations are available for spyware, malware and category tests. First decide which layer should block access: Endpoint Web Control, DNS Protection, Protected Browser or a network firewall can display different block pages.

Test at least one allowed, warned and blocked action as well as one HTTPS request. Then compare the Endpoint event with the effective policy. A block page without a matching Endpoint event may have come from another protection layer.

Test control policies with business scenarios

Application Control, Peripheral Control and DLP do not require a malware test file. Instead, use one controlled permitted and prohibited business scenario for each:

  • a known test application from the selected Application Control category,
  • one approved and one unapproved USB or MTP storage device,
  • a synthetic DLP file with test data and the actual transfer method in use.

The tests must cover not only blocking, but also the event, user notification, exception and rollback. Do not use real customer data, credentials or production confidential documents.

Document the result

A rollout acceptance record includes the date, device, operating system, Agent Mode, agent version, effective policies, test source, expected and actual result and the corresponding Central events. Resolve discrepancies before the next rollout stage.

Do not create continuous automated EICAR traffic for ongoing control. Monitor Health, update and policy status continuously; perform complete functional tests after relevant changes and periodically on a defined test device.

Frequently asked questions

Does EICAR prove that every Sophos protection feature is working?

No. EICAR confirms only the specific file-scanning path tested. Test Web Control, Exploit Protection, Ransomware Protection, DLP and XDR separately.

Can the test be performed on an XDR Sensor?

The XDR Sensor does not provide Sophos Anti-Malware or Web blocking. The existing third-party product must cover protection tests in this mode; verify Sophos sensor functions through telemetry, Live Discover and isolation.