
Over time and with the advancement of technology, hackers have been developing new methods and are now combining automation with their hacking capabilities to attack servers, which are a prime target due to the data stored on them. This new type of attack combines the use of bots to identify potential victims with human resources to decide who to attack and how. To address this issue, Sophos has announced Intercept X for Server with Endpoint Detection and Response (EDR). With the addition of EDR to Intercept X for Server, security experts can investigate cyberattacks on servers.
Using bots, cybercriminals decide which targets to choose based on the scope of sensitive data or the intellectual property of an organization, the ability to pay higher ransoms, or access to other servers and networks. Then they complete their work in the usual way: they infiltrate the system, avoid detection, steal the information they want and leave unnoticed, or in other cases they disable backups and encrypt the servers to demand ransom, or they use the servers to attack other companies.
According to Dan Schiappa, head of Sophos product services, “most malware is now automated, so it is easy for attackers to find organizations with weak security, assess their payment capabilities, and use hacking techniques to cause as much damage as possible.”
With Sophos Intercept X for Server with EDR, IT specialists in businesses of all sizes now have visibility across the entire enterprise system. This allows them to proactively detect any hidden attacks, better understand the impact of an attack and quickly map the full history of an attack.
“When hackers enter a network, they go straight to the server. Unfortunately, the critical nature of servers limits many organizations from making changes, often significantly delaying the deployment of patches. Cybercriminals rely on this. If organizations are the victims of an attack, they need to know the full context of the devices and servers affected to improve security. Knowing this information accurately can help businesses resolve issues much faster and prevent a repeat data,” said Schiappa. “Sophos Intercept X for Servers with EDR provides this required knowledge and security.”
The Sophos EDR is powered by deep learning technology for more extensive malware detection. Sophos's deep learning neural network is trained on hundreds of millions of samples to search for suspicious malicious code characteristics and detect threats that are unknown up to that point. It provides broad and specialized analysis of potential attacks, comparing the DNA of suspicious files with malware samples that have already been categorized in SophosLabs.
