<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Hướng dẫn cách khôi phục 1 file bị phát hiện và xóa bởi Sophos Endpoint bằng Sophos Safestore &#8211; Thegioifirewall</title>
	<atom:link href="https://thegioifirewall.com/tag/huong-dan-cach-khoi-phuc-1-file-bi-phat-hien-va-xoa-boi-sophos-endpoint-bang-sophos-safestore/feed/" rel="self" type="application/rss+xml" />
	<link>https://thegioifirewall.com</link>
	<description>Tường lửa bảo vệ doanh nghiệp, trung tâm thông tin và giá cả</description>
	<lastBuildDate>Sun, 24 Oct 2021 21:20:27 +0000</lastBuildDate>
	<language>vi</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://thegioifirewall.com/wp-content/uploads/vacif_icon-150x150.png</url>
	<title>Hướng dẫn cách khôi phục 1 file bị phát hiện và xóa bởi Sophos Endpoint bằng Sophos Safestore &#8211; Thegioifirewall</title>
	<link>https://thegioifirewall.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Hướng dẫn cách khôi phục 1 file bị phát hiện và xóa bởi Sophos Endpoint bằng Sophos Safestore</title>
		<link>https://thegioifirewall.com/huong-dan-cach-khoi-phuc-1-file-bi-phat-hien-va-xoa-boi-sophos-endpoint-bang-sophos-safestore/</link>
					<comments>https://thegioifirewall.com/huong-dan-cach-khoi-phuc-1-file-bi-phat-hien-va-xoa-boi-sophos-endpoint-bang-sophos-safestore/#respond</comments>
		
		<dc:creator><![CDATA[TrungNghia]]></dc:creator>
		<pubDate>Tue, 12 Oct 2021 04:45:35 +0000</pubDate>
				<category><![CDATA[Endpoint Detection & Response (EDR)]]></category>
		<category><![CDATA[Hướng dẫn cách khôi phục 1 file bị phát hiện và xóa bởi Sophos Endpoint bằng Sophos Safestore]]></category>
		<guid isPermaLink="false">https://www.thegioifirewall.com/?p=12696</guid>

					<description><![CDATA[1.Mục đích bài viết Trong bài viết này thegioifirewall sẽ hướng dẫn các bạn cách khôi phục 1 file bị phát hiện và xóa bởi Sophos Endpoint. 2.Các bước chuẩn bị Thegioifirewall đã chuẩn bị 1 máy chủ chạy Windows Server có tên là adserver đã cài Sophos Endpoint. Chuẩn bị 1 folder ứng dụng [&#8230;]]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading"><strong>1.Mục đích bài viết</strong></h2>



<p class="wp-block-paragraph">Trong bài viết này thegioifirewall sẽ hướng dẫn các bạn cách khôi phục 1 file bị phát hiện và xóa bởi Sophos Endpoint.</p>



<h2 class="wp-block-heading"><strong>2.Các bước chuẩn bị</strong></h2>



<p class="wp-block-paragraph">Thegioifirewall đã chuẩn bị 1 máy chủ chạy Windows Server có tên là adserver đã cài Sophos Endpoint.</p>



<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="1024" height="549" src="https://thegioifirewall.com/wp-content/uploads/1-2-1-1-1024x549.png" alt="" class="wp-image-12697" srcset="https://thegioifirewall.com/wp-content/uploads/1-2-1-1-1024x549.png 1024w, https://thegioifirewall.com/wp-content/uploads/1-2-1-1-300x161.png 300w, https://thegioifirewall.com/wp-content/uploads/1-2-1-1-768x412.png 768w, https://thegioifirewall.com/wp-content/uploads/1-2-1-1.png 1200w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Chuẩn bị 1 folder ứng dụng có tên SysinternalSuite đã được nén bằng 7zip.</p>



<p class="wp-block-paragraph">Các bạn có thể tải xuống file SysinternalSuite tại <a href="https://drive.google.com/file/d/1mKs2PWJCtxb0-EAb2OLKBPsdhrASsJEw/view?usp=sharing" data-type="URL" data-id="https://drive.google.com/file/d/1mKs2PWJCtxb0-EAb2OLKBPsdhrASsJEw/view?usp=sharing">đây</a>.</p>



<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="539" src="https://thegioifirewall.com/wp-content/uploads/1-1-3-1024x539.png" alt="" class="wp-image-12699" srcset="https://thegioifirewall.com/wp-content/uploads/1-1-3-1024x539.png 1024w, https://thegioifirewall.com/wp-content/uploads/1-1-3-300x158.png 300w, https://thegioifirewall.com/wp-content/uploads/1-1-3-768x404.png 768w, https://thegioifirewall.com/wp-content/uploads/1-1-3-1536x808.png 1536w, https://thegioifirewall.com/wp-content/uploads/1-1-3-2048x1078.png 2048w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<h2 class="wp-block-heading"><strong>3. Hướng dẫn cấu hình</strong></h2>



<p class="wp-block-paragraph">Trên máy chủ adserver chúng ta sẽ thực hiện giải nén file zip SysinternalSuite.</p>



<p class="wp-block-paragraph">Sau khi giải nén Sophos Endpoint sẽ phát hiện và xác định 2 file pskill.exe và pskill64.exe là PUA.</p>



<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="541" src="https://thegioifirewall.com/wp-content/uploads/2-45-1024x541.png" alt="" class="wp-image-12701" srcset="https://thegioifirewall.com/wp-content/uploads/2-45-1024x541.png 1024w, https://thegioifirewall.com/wp-content/uploads/2-45-300x159.png 300w, https://thegioifirewall.com/wp-content/uploads/2-45-768x406.png 768w, https://thegioifirewall.com/wp-content/uploads/2-45-1536x812.png 1536w, https://thegioifirewall.com/wp-content/uploads/2-45-2048x1082.png 2048w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="541" src="https://thegioifirewall.com/wp-content/uploads/3-50-1024x541.png" alt="" class="wp-image-12702" srcset="https://thegioifirewall.com/wp-content/uploads/3-50-1024x541.png 1024w, https://thegioifirewall.com/wp-content/uploads/3-50-300x159.png 300w, https://thegioifirewall.com/wp-content/uploads/3-50-768x406.png 768w, https://thegioifirewall.com/wp-content/uploads/3-50-1536x812.png 1536w, https://thegioifirewall.com/wp-content/uploads/3-50-2048x1082.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Sophos Endpoint sẽ thực hiện xóa 2 file này.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="703" src="https://thegioifirewall.com/wp-content/uploads/4-50-1024x703.png" alt="" class="wp-image-12703" srcset="https://thegioifirewall.com/wp-content/uploads/4-50-1024x703.png 1024w, https://thegioifirewall.com/wp-content/uploads/4-50-300x206.png 300w, https://thegioifirewall.com/wp-content/uploads/4-50-768x527.png 768w, https://thegioifirewall.com/wp-content/uploads/4-50-1536x1054.png 1536w, https://thegioifirewall.com/wp-content/uploads/4-50.png 1981w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="702" src="https://thegioifirewall.com/wp-content/uploads/5-47-1024x702.png" alt="" class="wp-image-12704" srcset="https://thegioifirewall.com/wp-content/uploads/5-47-1024x702.png 1024w, https://thegioifirewall.com/wp-content/uploads/5-47-300x206.png 300w, https://thegioifirewall.com/wp-content/uploads/5-47-768x527.png 768w, https://thegioifirewall.com/wp-content/uploads/5-47-1536x1054.png 1536w, https://thegioifirewall.com/wp-content/uploads/5-47.png 1981w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Trong folder SysinternalSuite trên adserver cũng không còn xuất hiện 2 file pskill.exe và pskill64.exe.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="543" src="https://thegioifirewall.com/wp-content/uploads/6-47-1024x543.png" alt="" class="wp-image-12705" srcset="https://thegioifirewall.com/wp-content/uploads/6-47-1024x543.png 1024w, https://thegioifirewall.com/wp-content/uploads/6-47-300x159.png 300w, https://thegioifirewall.com/wp-content/uploads/6-47-768x407.png 768w, https://thegioifirewall.com/wp-content/uploads/6-47-1536x814.png 1536w, https://thegioifirewall.com/wp-content/uploads/6-47-2048x1085.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Trong bài hướng dẫn này thegioifirewall sẽ hướng dẫn các bạn cách khôi phục file pskill.exe đã bị xóa bởi Sophos Endpoint.</p>



<p class="wp-block-paragraph">Để khôi phục đăng nhập vào Sophos Central bằng tài khoản quản trị.</p>



<p class="wp-block-paragraph">Vào mục Device &gt; Servers &gt; nhấn vào tên adserver.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="379" src="https://thegioifirewall.com/wp-content/uploads/7-41-1024x379.png" alt="" class="wp-image-12706" srcset="https://thegioifirewall.com/wp-content/uploads/7-41-1024x379.png 1024w, https://thegioifirewall.com/wp-content/uploads/7-41-300x111.png 300w, https://thegioifirewall.com/wp-content/uploads/7-41-768x284.png 768w, https://thegioifirewall.com/wp-content/uploads/7-41-1536x568.png 1536w, https://thegioifirewall.com/wp-content/uploads/7-41-2048x758.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Chuyển sang tab Event, tại dòng PUA detected: ‘Pskill’ at … nhấn Details.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="500" src="https://thegioifirewall.com/wp-content/uploads/8-41-1024x500.png" alt="" class="wp-image-12707" srcset="https://thegioifirewall.com/wp-content/uploads/8-41-1024x500.png 1024w, https://thegioifirewall.com/wp-content/uploads/8-41-300x147.png 300w, https://thegioifirewall.com/wp-content/uploads/8-41-768x375.png 768w, https://thegioifirewall.com/wp-content/uploads/8-41-1536x750.png 1536w, https://thegioifirewall.com/wp-content/uploads/8-41-2048x1000.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Bảng Event Details sẽ xuất hiện chúng ta sẽ chọn như sau:</p>



<ul class="wp-block-list"><li>Allow by: chúng ta có thể chọn SHA256, Certificate: Microsoft Coporation hoặc Path, ở đây thegioifirewall sẽ chọn SHA 256 ( SHA-256 cho phép phiên bản này của ứng dụng. Tuy nhiên, nếu ứng dụng được cập nhật, nó có thể được phát hiện một lần nữa. Sử dụng Chứng chỉ cũng sẽ cho phép các ứng dụng có cùng chứng chỉ)</li><li>To help Sophos improve … : Các bạn có có chọn một comment có sẵn trong danh sách.</li><li>Nhấn Allow.</li></ul>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="885" height="1024" src="https://thegioifirewall.com/wp-content/uploads/9-42-885x1024.png" alt="" class="wp-image-12708" srcset="https://thegioifirewall.com/wp-content/uploads/9-42-885x1024.png 885w, https://thegioifirewall.com/wp-content/uploads/9-42-259x300.png 259w, https://thegioifirewall.com/wp-content/uploads/9-42-768x889.png 768w, https://thegioifirewall.com/wp-content/uploads/9-42-1327x1536.png 1327w, https://thegioifirewall.com/wp-content/uploads/9-42.png 1494w" sizes="auto, (max-width: 885px) 100vw, 885px" /></figure></div>



<p class="wp-block-paragraph">Thông báo thành công sẽ xuất hiện, đồng thời Sophos cũng tạo một ngoại lệ cho file này đối với adserver.</p>



<p class="wp-block-paragraph">Khi ngoại lệ được tạo, Sophos sẽ không quét file này trên adserver nữa khi nó xuất hiện.</p>



<p class="wp-block-paragraph">Để xem ngoại lệ Allowed Applications.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="312" src="https://thegioifirewall.com/wp-content/uploads/10-37-1024x312.png" alt="" class="wp-image-12709" srcset="https://thegioifirewall.com/wp-content/uploads/10-37-1024x312.png 1024w, https://thegioifirewall.com/wp-content/uploads/10-37-300x91.png 300w, https://thegioifirewall.com/wp-content/uploads/10-37-768x234.png 768w, https://thegioifirewall.com/wp-content/uploads/10-37.png 1494w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Ngoại lệ dành cho file pskill.exe đã được tạo.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="410" src="https://thegioifirewall.com/wp-content/uploads/11-38-1024x410.png" alt="" class="wp-image-12710" srcset="https://thegioifirewall.com/wp-content/uploads/11-38-1024x410.png 1024w, https://thegioifirewall.com/wp-content/uploads/11-38-300x120.png 300w, https://thegioifirewall.com/wp-content/uploads/11-38-768x307.png 768w, https://thegioifirewall.com/wp-content/uploads/11-38-1536x615.png 1536w, https://thegioifirewall.com/wp-content/uploads/11-38-2048x820.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Việc khôi phục file này được Sophos Safestore ghi lại log.</p>



<p class="wp-block-paragraph">Để xem log các bạn nhấn tổ hợp phím Alt + R và nhập vào đường dẫn %ProgramData%\Sophos\SafeStore\Logs và nhấn Enter trên adserver.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="542" src="https://thegioifirewall.com/wp-content/uploads/12-36-1024x542.png" alt="" class="wp-image-12711" srcset="https://thegioifirewall.com/wp-content/uploads/12-36-1024x542.png 1024w, https://thegioifirewall.com/wp-content/uploads/12-36-300x159.png 300w, https://thegioifirewall.com/wp-content/uploads/12-36-768x407.png 768w, https://thegioifirewall.com/wp-content/uploads/12-36-1536x814.png 1536w, https://thegioifirewall.com/wp-content/uploads/12-36-2048x1085.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Mở file safestore.log.</p>



<p class="wp-block-paragraph">Dòng Savefile: C:\Users\Administrator\&#8230;\pskill.exe là dòng thể hiện nơi file pskill.exe được lưu lúc đầu trên adserver.</p>



<p class="wp-block-paragraph">Dòng Restored: C:\Users\Administrators\&#8230;\pskill.exe là dòng thể hiện Sophos Safestore đã khôi phục file pskill và thư mục SysinternalSuite trên adserver.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="489" src="https://thegioifirewall.com/wp-content/uploads/13-32-1024x489.png" alt="" class="wp-image-12712" srcset="https://thegioifirewall.com/wp-content/uploads/13-32-1024x489.png 1024w, https://thegioifirewall.com/wp-content/uploads/13-32-300x143.png 300w, https://thegioifirewall.com/wp-content/uploads/13-32-768x367.png 768w, https://thegioifirewall.com/wp-content/uploads/13-32-1536x734.png 1536w, https://thegioifirewall.com/wp-content/uploads/13-32-2048x979.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Để kiểm tra file pskill.exe đã được khôi phục chưa chúng ta quay trở lại folder SysinternalSuite trên adserver.</p>



<p class="wp-block-paragraph">Chúng ta sẽ thấy được rằng file pskill.exe đã xuất hiện trong folder.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="539" src="https://thegioifirewall.com/wp-content/uploads/14-30-1024x539.png" alt="" class="wp-image-12713" srcset="https://thegioifirewall.com/wp-content/uploads/14-30-1024x539.png 1024w, https://thegioifirewall.com/wp-content/uploads/14-30-300x158.png 300w, https://thegioifirewall.com/wp-content/uploads/14-30-768x404.png 768w, https://thegioifirewall.com/wp-content/uploads/14-30-1536x808.png 1536w, https://thegioifirewall.com/wp-content/uploads/14-30-2048x1078.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>
]]></content:encoded>
					
					<wfw:commentRss>https://thegioifirewall.com/huong-dan-cach-khoi-phuc-1-file-bi-phat-hien-va-xoa-boi-sophos-endpoint-bang-sophos-safestore/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
