Overview
What is Sophos Intercept X?
Sophos Endpoint Protection (Sophos EPP) with Intercept X is an endpoint security product providing an antivirus / antimalware solution that when upgraded with Intercept X or Intercept X Advanced provides advanced threat detection and EDR capabilities.
good and modern product - always updated.
Sophos Intercept X Delivers On All Fronts!
Sophos Intercept X Endpoint Protection review
Sophos Intercept X, Better than the rest
Sophos Intercept X Endpoint Review
It does the job!
A great centralized security platform.
Sophos Intercept X is to antivirus as Rod Woodson is to cornerbacks - it intercepts everything.
Intercept X intercepts everything
Sophos Intercept X Review
Sophos Intercept X will give you peace of mind
Sophos is Supreme Program
Can’t go wrong with Sophos!
Superb ransomware detection and analysis!
Sophos Intercept-X Works Great!
Awards
Products that are considered exceptional by their customers based on a variety of criteria win TrustRadius awards. Learn more about the types of TrustRadius awards to make the best purchase decision. More about TrustRadius Awards
Popular Features
- Centralized Management (19)10.0100%
- Infection Remediation (19)9.898%
- Endpoint Detection and Response (EDR) (19)9.696%
- Anti-Exploit Technology (19)8.686%
Reviewer Pros & Cons
Pricing
Intercept X Advanced
$28
Intercept X Advanced with XDR
$48
Sophos Managed Threat Response
$79
Entry-level set up fee?
- No setup fee
Offerings
- Free Trial
- Free/Freemium Version
- Premium Consulting/Integration Services
Starting price (does not include set up fee)
- $28 per year per user
Product Demos
CVE-2017-11826 0day exploit vs months old Sophos Intercept X
How WannaCry ransomware works
Features
Endpoint Security
Endpoint security software protects enterprise connected devices from malware and cyber attacks.
- 8.6Anti-Exploit Technology(19) Ratings
In-memory and application layer attack blocking (e.g. ransomeware)
- 9.6Endpoint Detection and Response (EDR)(19) Ratings
Continuous monitoring and response to advanced internet threats by endpoint agents.
- 10Centralized Management(19) Ratings
Centralized management supporting multi-factor authentication, customized views, and role-based access control.
- 8Hybrid Deployment Support(3) Ratings
Administrators should be able to choose endpoint security on-premise, cloud, or hybrid.
- 9.8Infection Remediation(19) Ratings
Capability to quarantine infected endpoint and terminate malicious processes.
- 8.4Vulnerability Management(4) Ratings
Vulnerability prioritization for fixes.
- 9.8Malware Detection(19) Ratings
Detection and blocking of zero-day file and fileless malware.
Product Details
- About
- Competitors
- Tech Details
- FAQs
What is Sophos Intercept X?
Sophos Intercept X Features
Endpoint Security Features
- Supported: Anti-Exploit Technology
- Supported: Endpoint Detection and Response (EDR)
- Supported: Centralized Management
- Supported: Infection Remediation
- Supported: Malware Detection
Sophos Intercept X Screenshots
Sophos Intercept X Video
Sophos Intercept X Competitors
Sophos Intercept X Technical Details
Deployment Types | On-premise |
---|---|
Operating Systems | Windows, Mac |
Mobile Application | Apple iOS, Android, Windows Phone, Blackberry |
Frequently Asked Questions
Comparisons
Compare with
Reviews and Ratings
(202)Community Insights
- Business Problems Solved
Sophos Endpoint Protection has become a widely-used and highly regarded solution for safeguarding machines in various environments. Users rely on this product to ensure that their systems are protected and receive regular updates from the Sophos Database. With its ability to send alerts when a system hasn't been updated in a while, it helps users identify computers that are not frequently used. This feature proves to be invaluable in maintaining the security of an organization's network.
One long-time user praises Sophos Intercept X as the most secure endpoint product on the market. Its ease of deployment and management, combined with its ability to catch everything, make it the preferred choice for both home and business use. By dramatically reducing instances of malware and ransomware, Sophos Intercept X has proven itself as a reliable defense against cyber threats. It also offers powerful administrative capabilities through the Sophos Central web console, allowing users to identify and address security issues effectively.
Sophos Endpoint Protection is widely used across industries for robust protection against virus infections, web and mail downloads, and real-time threats. The product adapts to the rapidly changing digital era by offering advanced features like Anti Exploit Prevention, which safeguards users against ransomware attacks. Whether deployed in the healthcare industry or small businesses, Sophos Intercept X provides peace of mind by effectively preventing malicious software issues. Furthermore, its non-invasive nature and quick response to potential threats make it an ideal choice for organizations seeking a reliable and user-friendly endpoint security solution.
Intercept X's comprehensive protection extends beyond traditional malware detection, with features such as content filtering, application management, and cloud management with MFA authentication. It ensures security compliance, preventing ransomware attacks on devices ranging from workstations to servers. Real-time protection against various forms of malware, including web and mail protection, contributes to Sophos Endpoint Protection's reputation as an industry leader in providing information security services for enterprises.
In addition to protecting against potential attacks, Sophos Endpoint Protection requires minimal user interaction, making it a hassle-free solution for organizations. Its cloud-based architecture simplifies deployment, management, and remediation across distributed locations. Users have reported successfully defending against CryptoLocker and significantly reducing monthly infections, resulting in a more secure environment. With its advanced features like malware identification and automatic quarantine, Intercept X enhances security measures and provides excellent protection against cyber threats.
Overall, Sophos has gained praise from users as a reliable, easy-to-use, and effective endpoint solution. Whether deployed globally across entire companies or implemented organization-wide, the product delivers top-notch system behavior and manageability. It seamlessly integrates with desktops, laptops, and servers, running silently in the background without causing disruptions.
One standout feature of Sophos is its ability to send email reports that alert users of various events, allowing them to proactively address any issues before they become major problems. Users have successfully deployed Sophos across their entire infrastructure, including Windows, Linux, and Apple products. While deployment on Windows machines is easy through the enterprise console, Linux and Mac installation may require manual setup. Once installed, Sophos automatically updates all machines and runs smoothly without consuming excessive computer resources.
Intercept X, a module of Sophos Central, is widely used as an anti-malware and anti-virus agent on endpoint machines and servers. Its policy-setting capabilities for web and application access provide an additional layer of security. Small businesses rely on Sophos Intercept X not only for protection but also for timely notifications of potential threats. The product's effectiveness in preventing malicious software issues and providing a safety net against ransomware has made it the go-to solution for organizations seeking peace of mind.
Sophos Endpoint Protection has established itself as an industry leader in providing information security services for enterprises worldwide. Its real-time protection against various forms of malware, including web and mail protection, ensures a secure environment for users. Those who use Sophos Endpoint Protection have experienced successful protection against CryptoLocker, saving significant time and effort in recovery.
Overall, Sophos delivers excellent endpoint security with minimal user interaction required. Its cloud-based management simplifies deployment and remediation across distributed locations. With its reputation for robust protection and ease of use, Sophos Endpoint Protection continues to be highly regarded by organizations seeking top-notch security solutions.
Attribute Ratings
Reviews
(1-24 of 24)good and modern product - always updated.
- Application control.
- Ease of use.
- Content filtering https.
- I like to automate the cleaning less.
- Some pc looks slower.
- More secure firewall function.
Sophos Intercept X Delivers On All Fronts!
- Zero-Day Malware Detection
- Web Filtering
- End-User Device/hardware controls
- Email notifications of infected machines
- Health Status Compliance At The Device Level
- Machine and/or User-based policy control
- Logs and reports easily read
- Integration with Active Directory
- I'd love if a list of devices not running Sophos could be generated with the AD integration - so that the software could be pushed to the device. (Unsure if this exists, as I haven't found it personally).
Sophos Intercept X Endpoint Protection review
- Protects against ransomware
- Keeps PCs clean
- Easy to manage
- The site can be slow
- Higher pricing
Sophos Intercept X, Better than the rest
- Detects Malware
- Protects against Ransomware
- Centrally managed
- Easy to deploy
- Support is knowledgeable but can take some time to reach a person
- False Positives can be improved
- Add Templates
Sophos Intercept X Endpoint Review
- virus scanning
- malware detection
- Data loss prevention
- add phishing scanning
Sophos Intercept X is to antivirus as Rod Woodson is to cornerbacks - it intercepts everything.
- Sophos Intercept X is great at preventing malware infections and rolling back their effects. I have seen this happen hundreds of times since we installed it
- When combined with Sophos Central, you have an easy to use dashboard where you can manage all installations from a single pane of glass.
- It's easy to deploy on machines and stays updated.
- Good reporting features including alerts sent to the admin if there's ever something wrong with it.
- It can be a bit resource-intensive, especially on machines that are a little older. I've seen it take up too many CPU cycles and bog down the rest of the machine.
- Initial setup to get it working can be challenging if you do anything other than the default settings.
- Sometimes won't update on client machines, so they have to be brought in for a manual reinstall.
Sophos Intercept X Review
- It is easy to deploy.
- It is easy to manage.
- Sometimes the client takes up quite a bit of space on the systems it runs on.
Sophos is Supreme Program
- A powerful virus cleaner
- It stops Modern Threats
Can’t go wrong with Sophos!
- Application control.
- Web control.
- Threat remediation.
- Better integration with active directory both on premise and Azure.
Superb ransomware detection and analysis!
- Identifies ransomware
- Gives in-depth analysis on current and detected threats
- Very easy to configure on top of existing products
- GUI not very simple
- Information regarding threats often unclear and hard to decipher at basic level
- False positives on occassion
Large businesses with a large number of devices may struggle, as there's a lot of detail captured with individual threats and troubleshooting is often time consuming.
Sophos Intercept-X Works Great!
- Easy migration from Symantec to Sophos Intercept-X. A simple .msi file allowed for the automatic uninstall of Symantec.
- Sophos Central makes it very simple to mitigate potential issues immediately. I can log in and remediate from anywhere.
- Most vulnerabilities are blocked and removed without IT Helpdesk needing to touch a machine. The reporting capabilities after the fact are informative.
- There are a bunch of running Sophos processes on machines with the software installed. Some take up quite a bit of memory at times.
- Although the process to correct is easy and relatively quick, I've noticed quite a few false positives when it comes to web filtering.
- Setting up policies is a little clunky at first.
Sophos' cloud offering works well but Secure Boot messes it up
- Sophos is a little too good at DLP. But it is indeed very good at not allowing our data to leave our endpoints without strict adherence to policy.
- Sophos is very good at protecting endpoints against viruses and other malware.
- Sopho is really good at informing us of what is happening on our endpoints. OOTB reporting is way better than expected.
- Sophos OOTB policies are very strict and they don't offer anything less strict without you creating new custom policies. I'm sure this is deliberate because the product starts you out in the safest way possible but it means that you will have lots of calls to your tech support desk when you first deploy it unless you do somewhat extensive testing beforehand.
- Sophos Intercept X is currently broken (at least the DLP component) by having secure boot turned on in the UEFI/BIOS. If any user wants to be able to write data to a USB drive or floppy from their PC (yes we still have a couple users who need to use floppies) we have to turn off secure boot on their PC, even if the DLP policy for that user/PC combination specifies that the user and PC are allowed to write to USB/floppy. This would be a very serious problem if it weren't for the fact that we have very few users who need to write files to USB. For us it's OK but I bet it would be a deal-breaker for others.
- I don't see a whole lot of evidence that Intercept X is any different than any other anti-virus, so maybe their admin alerts just don't clearly identify when they have identified a zero-day threat or maybe we just haven't had any zero-day threats.
Quick alerting and automated responses for better security
- Alert notifications can be sent directly to email as soon as any suspicious activity or files are discovered.
- The endpoint agent is delivered in one installer package, allowing for ease of deployment.
- Sophos works with common SIEM products and integrates well, giving visibility of events to security analysts for pattern detection.
- Sophos is heavy on resource utilization for scanning and detecting.
- Upon installation and use, there are approximately 17 services that are installed and run the product.
- Sophos could make it easier on deployment by being able to scan a domain and push the agent out to assets that don't have protection.
Intercept X is a game changer for our organization
- Block ransomware.
- Notify administrators.
- Revert back the data to the previous stat.
- Blocks all executables from running.
- It has to be used with Sophos AV & Sophos central to have an effective solution.
We are very pleased with Intercept X it was an investment worth every penny.
- Licensing is per user not, machine. So a user could have multiple machines and not have to purchase so many licenses
- Notifications for issues on devices where it has not contacted system in awhile
- Notification when there is a threat that was cleaned and if any additional action is needed.
- Blocking unwanted applications from running in the background when browsing the internet
- I honestly cannot thing of anything negative about the Endpoint protection.
Sophos: Simple and efficient, does what it says
- Simple to setup and configure leaving engineers free to worry about other tasks.
- Sophos automatically discovered all our AWS servers with very little input enabling a clear picture of what servers we have over which sites and which are protected.
- Very easy to configure specific policies either by server type, location or office specific for end users.
- Automatic reporting of non-compliance devices could be improved as such that the engineer managing the estate can quickly see what is out of compliance and what needs to be done to fix it.
- A single pane of glass interface to see all devices would be useful as switching between servers and desktops could be simplified.
- With multiple policies being created the interface gets very busy and determining which policy is active for a particular device is not always clear.
Sophos is more than your legacy AV.
- Centralized management of endpoint security
- Easy to understand dashboards
- Protection against ransomware
- Nice graphical analysis for malware behavior and the vectors involved in the attack
- SAML login support for cloud console
- Manual malware cleanups can be frustrating
- Feature to enable reinstall from the portal if need be.
Due to its centralized management nature and immense visibility into endpoints well-being, it requires constant monitoring and timely reaction (like any other security tool) which can be a daunting task if not done regularly as it easily piles up into thousands of action items that could take days/weeks to complete. With more visibility comes more responsibility of-course.
Sophos makes financial and security sense.
We installed this across our entire company and even implemented it into a new company that was recently acquired. Security is obviously at the fore-front of all of our minds, and Sophos has given us peace of mind.
- Sophos Endpoint Protection installs very easily
- Sophos Endpoint Protection is very unobtrusive on the clients and doesn't get in the way of doing any other tasks.
- We have had no breaches since we installed Sophos and feel very confident in its protection
- It may be nice to have a weekly/monthly digest to see what is going on and how the protection is holding up.
Happy Sophos AV End user
- Cloud based management is much easier than its on-prem solution
- Easy to install and easy to get updates
- Easy on the CPU but still very powerful
- The migration from on-prem sophos to cloud sophos, could have been a little more seamless
- Would love to get more insight on what was blocked or flagged and what it was trying to do
- Better and more granular feature management from group policies
- Cloud dashboard has easy UI and the product is generally easy to manage. The capabilities are strong, so we don't have to compromise between usability and features.
- We've been happy with the detection capabilities and feel generally well protected.
- The pricing has been fairly aggressive, which is welcome in a midsize organization.
- Alerts are meaningful, making it easy for us to act and re-mediate issues.
- The MacOS client has been just as strong as the Windows client.
- We have to create new users in the access management part but Sophos also creates a new user based on every windows login. It'd be preferable if the system could automatically reconcile the user accounts.
- Special care needs to be used when planning when the client scans/updates, as this sometimes can be felt by the end-users.
- Would prefer if they didn't sell core security products separately, but included them all in one platform.
Best in its class
- The company offers one stop service for all security related needs.
- Excellent Malware protection and recovery.
- Deployment and configuration is a breeze using the consolidated web management console.
- Software can get bloated at times and consume lots of resources on machines, especially while performing incremental updates.
- Some emails and attachments are incorrectly flagged as dangerous.
- We had some issues while integrating Digital Guardian with Sophos, since it kept on blocking OS updates on the machines.
We went with the cloud version of the software suite instead of hosting it on premises. It has an extremely simple all in one web management console. Sophos End Point Protection suite comes with a very well designed and comprehensive web management console. It is the single point of access for numerous services.
Sophos - Leader and Trusted
- Malicious file identification
- Signature-based detection
- Web-based protection
- Signature visibility
- Direct endpoint management - it seems this feature has gone away in recent versions
Sophos - #1 Endpoint Security
- Simple installation (MSSC compatible.)
- Removes all conflicting software automatically.
- Small system footprint.
- Powerful Scanner/Active Shields.
- Email reports can be false positives - software should check itself and attempt to update/apply policies and then send out a notification if that fails, not before.
- It should not require admin privileges to run a manual scan.
- Email reports could use a little more detail on what exact policy/item is out of compliance to make issue easier to verify/fix.
Sophos is very easy to use with Windows
- Automatically installed on Windows machines.
- Automatically updates.
- The console gives you lots of control over your deployment. Including things like what version of the client software you want to run on your machines.
- You can easily see what machines are, or aren't, checking in with the console.
- It'd be nice if there was an automated deployment for Linux and Mac.
- Visibility into Mac/Linux machines from the console could be better. Basically the functionality with Mac/Linux is very limited.
- The enterprise console isn't very straight forward at first. It takes some time to get used to navigating the menus to find what you want.