Skip to content

Sophos Endpoint Agent Technical Details๐Ÿ”—

This document describes the technical components and services of Sophos Endpoint Agent. It explains the function and availability of each component for Sophos Agent for Endpoint and Sophos Agent for Server.

Components๐Ÿ”—

The following components may be installed on Sophos Agent Windows endpoints and servers.

Component Description Availability
Sophos AutoUpdate Keeps endpoint or server components and supplemental data up to date, including itself. Endpoint, Server
Sophos Management Communications System (MCS) Receives messages from Sophos Central and routes them to other components. Sends device status back to Sophos Central. Endpoint, Server
Sophos Endpoint Firewall / Firewall Management Monitors and configures connection types on devices using Windows Firewall policy. Endpoint, Server
Sophos Network Threat Protection Manages malicious behavior detection, web filtering, heartbeat/synchronized Application Control, SATC, and ZTNA. Endpoint, Server
Sophos Endpoint Defense (SED) Core component that integrates with multiple processes. Endpoint, Server
Sophos HitmanPro Alert Provides runtime protection, including exploit mitigation and ransomware protection (CryptoGuard). Endpoint, Server
Sophos File Scanner Scans files and returns information to Sophos System Protection. Endpoint, Server
Sophos Self Help Tool Reports installation health and helps troubleshoot issues. Endpoint, Server
Sophos Endpoint UI User interface for the Sophos Agent Agent. Endpoint, Server
Sophos Message Relay Relays policy and reporting data to Sophos Central via a local server. Server only
Not present from Server Core Agent 2024.2 (now part of Sophos Management Gateway)
Sophos Server Lockdown Allows only approved applications to run on the server, preventing unauthorized modifications. Server only
Sophos Update Cache Provides updates from a local cache, saving bandwidth. Server only
Not present from Server Core Agent 2024.2 (now part of Sophos Management Gateway)
Sophos Health Monitors the health of the local installation. Endpoint, Server
Sophos File Integrity Monitoring Monitors system-critical files, folders, and registry keys/values. Server only
Sophos Live Query Allows administrators to query devices for immediate visibility and investigation. Endpoint, Server
Sophos Live Terminal Enables remote command line access for further investigation or response. Endpoint, Server
Sophos MDR Endpoint Agent
(Managed Detection and Response)
Used by the Managed Threat Response service for threat hunting and monitoring. Endpoint, Server
Not present from Core Agent 2023.2
Sophos AMSI Protection Integrates with Windows AMSI for antimalware scanning and protection. Endpoint, Server
Threat Detection Engine Provides protection against malware and other threats. Endpoint, Server
Sophos Uninstaller Uninstalls Sophos components. Endpoint, Server
Sophos Diagnostic Utility Gathers device information and logs for troubleshooting. Endpoint, Server
Machine Learning Engine Used by Sophos File Scanner during file scanning. Endpoint, Server
Sophos Data Protection Agent Installed with Device Encryption. Endpoint only
Sophos Clean Cleans up detected threats. Endpoint, Server
Not present on Windows 10 (x64) and above, or Windows Server 2016 and above
Sophos Endpoint Agent Main reference for all other components. Reports Core Agent version. Endpoint, Server
Not present on Windows 10 (x64) and above, or Windows Server 2016 and above
Sophos Management Gateway Combines Message Relay and Update Cache functionality. Server only
Available from Core Agent 2024.2

Services๐Ÿ”—

The following services run on Sophos Central-managed Windows endpoints and servers.

Service Name Process Description Availability
Sophos AutoUpdate Service ALSvc.exe Updates Sophos components. Endpoint, Server
Not present on Windows 10 (x64) and above, or Windows Server 2016 and above from Core Agent 2022.3
Sophos Clean SophosClean.exe On-demand malware scanner and cleaner.
Set to Automatic but no longer used on newer systems.
Endpoint, Server
Not present on Windows 10 (x64) and above, or Windows Server 2016 and above
Sophos Endpoint Defense Service SEDService.exe Core service for endpoints and servers. Endpoint, Server
Sophos File Scanner Service SophosFS.exe Launches worker processes for data scanning. Endpoint, Server
Sophos Live Query SophosLiveQueryService.exe Manages live and scheduled queries. Endpoint, Server
Sophos Health Service SophosHealth.exe Reports the health status of the endpoint. Endpoint, Server
Sophos MCS Agent mcsagent.exe Management Communications Agent. Endpoint, Server
Sophos MCS Client mcsclient.exe Management Communications Client. Endpoint, Server
Sophos Network Threat Protection SntpService.exe Manages malicious behavior detection, web filtering, heartbeat, SATC, and ZTNA. Endpoint, Server
Sophos SafeStore SophosSafestore64.exe Encrypted quarantine store.
Automatic startup but no longer used on newer systems.
Endpoint, Server
Not present on Windows 10 (x64) and above, or Windows Server 2016 and above
Sophos System Protection Service SSPService.exe Collects and uses information from Sophos components to detect threats. Endpoint, Server
HitmanPro.Alert Service hmpalert.exe Provides exploit mitigation and browser intrusion detection. Endpoint, Server
Sophos File Integrity Monitoring SophosFIMService.exe Monitors file integrity. Server only
Sophos Managed Threat Response SophosMTR.exe Manages osquery operations on the device.
No longer present from Core Agent 2023.2.
Endpoint, Server
Sophos Lockdown Service SLDService.exe Enforces Server Lockdown. Server only
Sophos Message Relay Service httpd.exe -k runservice Relays communication between local computers and Sophos Central.
From Server Core Agent 2023.2, present on all servers with Update Cache installed. If not enabled, the service is set to Disabled.
From Server Core Agent 2024.2, functionality is managed by the Update Cache service.
Server only
Sophos Update Cache UpdateCacheService.exe Downloads and serves Sophos updates to the local network.
From Server Core Agent 2024.2, manages Message Relay functionality.
Server only
Sophos Device Encryption Service Sophos.Encryption.BitLockerService.exe Manages BitLocker disk encryption. Endpoint only

Component and Service Availability๐Ÿ”—

Feature Endpoint Server
Sophos AutoUpdate โœ“ โœ“
Sophos Management Communications System โœ“ โœ“
Sophos Endpoint Firewall โœ“ โœ“
Sophos Network Threat Protection โœ“ โœ“
Sophos Endpoint Defense โœ“ โœ“
Sophos HitmanPro Alert โœ“ โœ“
Sophos File Scanner โœ“ โœ“
Sophos Self Help Tool โœ“ โœ“
Sophos Endpoint UI โœ“ โœ“
Sophos Message Relay โœ“ (servers only; see notes above)
Sophos Server Lockdown โœ“ (servers only)
Sophos Update Cache โœ“ (servers only; see notes above)
Sophos Health โœ“ โœ“
Sophos File Integrity Monitoring โœ“ (servers only)
Sophos Live Query โœ“ โœ“
Sophos Live Terminal โœ“ โœ“
Sophos MDR Endpoint Agent โœ“ (not present from Core Agent 2023.2) โœ“ (not present from Core Agent 2023.2)
Sophos AMSI Protection โœ“ โœ“
Threat Detection Engine โœ“ โœ“
Sophos Uninstaller โœ“ โœ“
Sophos Diagnostic Utility โœ“ โœ“
Machine Learning Engine โœ“ โœ“
Sophos Data Protection Agent โœ“ (endpoints only)
Sophos Clean โœ“ (legacy only) โœ“ (legacy only)
Sophos Endpoint Agent โœ“ (legacy only) โœ“ (legacy only)
Sophos Management Gateway โœ“ (from Core Agent 2024.2)