Index / Vendors / Sophos
Product Record

Sophos

Publicly-reported techniques recorded as bypassing Sophos. Each entry is sourced to its original disclosure. This is a factual tally, maintained on the same basis for every vendor in the Index.

9
recorded bypasses
6
distinct techniques

Techniques recorded against Sophos

TechniqueEntriesHigh-confidenceMost recent
AMSI Bypass 212025-04-15
BYOVD (Vulnerable Driver) 222023-08-16
EDR Unhooking 212025-05-24
Direct Syscalls 112024-07-24
Exploitation for Priv-Esc 112025-04-11
Reflective Code Loading 102025-09-23

All entries

TechniqueConfidenceDisclosedSource
Reflective Code Loading medium 2025-09-23g3tsyst3m.com record →
EDR Unhooking medium 2025-05-24github.com record →
AMSI Bypass high 2025-04-15github.com record →
Exploitation for Priv-Esc high 2025-04-11www.sophos.com record →
AMSI Bypass medium 2024-08-02github.com record →
Direct Syscalls high 2024-07-24github.com record →
EDR Unhooking high 2023-12-27app.daily.dev record →
BYOVD (Vulnerable Driver) high 2023-08-16jmp-esp.org record →
BYOVD (Vulnerable Driver) high 2023-05-31www.bleepingcomputer.com record →

Counts reflect distinct publicly-reported events on record; absence of an entry means no confirmed public report is on file, not that a product is unaffected.