%ALLUSERSPROFILE%\Sophos\Endpoint Defense\Logs\SSP.log
new file created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\SystemProtection\Telemetry\\PolicyConfiguration
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\Acknowledged\Provider\\corc_revision_id
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\Acknowledged\Provider\\core_revision_id
new registry key parameter created
%ALLUSERSPROFILE%\Sophos\Endpoint Defense\Logs\SSP_00.log
new file created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\DynamicUpdate\\rulesLoaded
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\BackgroundScanV2\\Paused
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\BackgroundScanV2\\PauseCount
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\SystemProtection\Telemetry\\BackgroundScanning
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\DecisionRulesV2\\rulesInUse
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\DynamicUpdate\\lastFailedVersion
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\DynamicUpdate\\lastError
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\SystemProtection\Telemetry\\auditModeEnabled
new registry key parameter created
%ALLUSERSPROFILE%\Sophos\Endpoint Defense\Data\historian.db
new file created
%ALLUSERSPROFILE%\Sophos\Endpoint Defense\Data\historian.db-journal
new file created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\Acknowledged\\HistorianStarted
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Health\ProcessNotification
new registry key created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Health\ProcessNotification\Sophos EDR Agent
new registry key created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Health\ProcessNotification\Sophos EDR Agent\\IsRunning
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\BackgroundScanV2\\BurndownTotalStartedCount
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\BackgroundScanV2\\BurndownLastStartedTime
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\BackgroundScanV2\\RestartCount
new registry key parameter created
%ALLUSERSPROFILE%\Sophos\Clean\Staging\scan_request_169A6EEC-4D21-402D-A1E9-5A1BA9FD03CA.json
new file created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\BackgroundScanV2\\BurndownLastWalkedFileCount
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\BackgroundScanV2\\BurndownTotalCompletedCount
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\BackgroundScanV2\\BurndownLastCompletedTime
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\SystemProtection\Telemetry\\MemoryFootprint
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\BackgroundScanV2\\OverallTotalStartedCount
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\BackgroundScanV2\\OverallLastStartedTime
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\BackgroundScanV2\\System32TotalStartedCount
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\BackgroundScanV2\\System32LastStartedTime
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\BackgroundScanV2\\System32LastWalkedFileCount
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\BackgroundScanV2\\System32TotalCompletedCount
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\BackgroundScanV2\\System32LastCompletedTime
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\BackgroundScanV2\\ProgramFilesTotalStartedCount
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\BackgroundScanV2\\ProgramFilesLastStartedTime
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\BackgroundScanV2\\ProgramFilesLastWalkedFileCount
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\BackgroundScanV2\\ProgramFilesTotalCompletedCount
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\BackgroundScanV2\\ProgramFilesLastCompletedTime
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\BackgroundScanV2\\SysWow64TotalStartedCount
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\BackgroundScanV2\\SysWow64LastStartedTime
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\BackgroundScanV2\\SysWow64LastWalkedFileCount
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\BackgroundScanV2\\SysWow64TotalCompletedCount
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\BackgroundScanV2\\SysWow64LastCompletedTime
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\BackgroundScanV2\\ProgramFilesX86TotalStartedCount
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\BackgroundScanV2\\ProgramFilesX86LastStartedTime
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\DynamicUpdate\\prepTimeMs
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\DynamicUpdate\\transitionTimeMs
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\DynamicUpdate\\outstandingAsyncEvents
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\DynamicUpdate\\numberOfEvaluators
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\Incidents\DCEE49E0FF68A4ADF2365FA7B79AA8029C1E44EDC0F30CECBC22856411EC9537
new registry key created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\Incidents\DCEE49E0FF68A4ADF2365FA7B79AA8029C1E44EDC0F30CECBC22856411EC9537\\family_id
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\Incidents\DCEE49E0FF68A4ADF2365FA7B79AA8029C1E44EDC0F30CECBC22856411EC9537\\last_updated
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\Incidents\DCEE49E0FF68A4ADF2365FA7B79AA8029C1E44EDC0F30CECBC22856411EC9537\\last_reported_local
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\Incidents\DCEE49E0FF68A4ADF2365FA7B79AA8029C1E44EDC0F30CECBC22856411EC9537\\last_reported_central
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\Incidents\DCEE49E0FF68A4ADF2365FA7B79AA8029C1E44EDC0F30CECBC22856411EC9537\\outbreak
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\Incidents\DCEE49E0FF68A4ADF2365FA7B79AA8029C1E44EDC0F30CECBC22856411EC9537\\threat_type
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\Incidents\DCEE49E0FF68A4ADF2365FA7B79AA8029C1E44EDC0F30CECBC22856411EC9537\\report_source
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\Incidents\DCEE49E0FF68A4ADF2365FA7B79AA8029C1E44EDC0F30CECBC22856411EC9537\not_rebooted_since_last_update
new registry key created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\SystemProtection\Telemetry\\detectionEventCount
new registry key parameter created
%ALLUSERSPROFILE%\Sophos\Health\Event Store\Temp\0B6A357C-E046-4297-BECA-AF55AE672ADB.json
new file created
%ALLUSERSPROFILE%\Sophos\Endpoint Defense\Data\Events\Staging\003948f5f214df8a_93E90752-A76F-4CC5-AA7E-033DDD737DD7.xml
new file created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\Incidents\DCEE49E0FF68A4ADF2365FA7B79AA8029C1E44EDC0F30CECBC22856411EC9537\5BAB8036-87B5-49E1-B4B3-C3D240B6E689
new registry key created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\Incidents\DCEE49E0FF68A4ADF2365FA7B79AA8029C1E44EDC0F30CECBC22856411EC9537\5BAB8036-87B5-49E1-B4B3-C3D240B6E689\\type
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\Incidents\DCEE49E0FF68A4ADF2365FA7B79AA8029C1E44EDC0F30CECBC22856411EC9537\5BAB8036-87B5-49E1-B4B3-C3D240B6E689\\status
new registry key parameter created
%ALLUSERSPROFILE%\Sophos\Clean\Staging\scan_request_7F47537D-85DE-4C7A-ACFA-E2A4FA5AC161.json
new file created
%ALLUSERSPROFILE%\Sophos\Endpoint Defense\Data\Clean\Saved\0B6A357C-E046-4297-BECA-AF55AE672ADB_5BAB8036-87B5-49E1-B4B3-C3D240B6E689.xml
file moved
%ALLUSERSPROFILE%\Sophos\Endpoint Defense\Data\Events\Staging\003948f5f214df8b_86681BBF-481E-4F7A-847D-4700A7FA4811.xml
new file created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\SystemProtection\Telemetry\\cleanMEventCount
new registry key parameter created
%ALLUSERSPROFILE%\Sophos\Health\Event Store\Temp\40B6B1C2-6FBE-4760-B2BE-C5C2DBBCBA81.json
new file created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\BackgroundScanV2\\ProgramFilesX86LastWalkedFileCount
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\BackgroundScanV2\\ProgramFilesX86TotalCompletedCount
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\BackgroundScanV2\\ProgramFilesX86LastCompletedTime
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\BackgroundScanV2\\FixedDiskTotalStartedCount
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\BackgroundScanV2\\FixedDiskLastStartedTime
new registry key parameter created