100% of Sophos XDR detections for adversary activities targeting Windows and Linux devices provide rich analytic coverage and achieve the highest possible ratings.

Sophos announced strong results in the 2024 MITRE ATT&CK Evaluations: Enterprise, where Sophos XDR detected 100% of adversary behaviors in attack scenarios targeting Windows and Linux platforms, specifically against ransomware strains from groups LockBit and CL0P. All responses to these scenarios were marked “technique,” indicating the highest rating for detailing how attacks were carried out.

Sophos XDR achieved:

  • ‘Analytic coverage’ ratings for 99% of sub-steps (79 out of 80) across three comprehensive attack scenarios.
  • Highest possible (‘Technique’) ratings for 98% of sub-steps (78 out of 80).
  • Highest possible (‘Technique’) ratings for 100% of sub-steps in the Windows and Linux ransomware attack scenarios.
“Attackers are relentless to innovate techniques to bypass trusted security defenses. This assessment from MITRE helps security buyers evaluate the effectiveness against today’s threats,” said Simon Reed, chief research and scientific officer at Sophos. “Sophos is committed to transparency and conducting third-party measurement to help security buyers make informed decisions to strengthen their security posture. We’re proud of Sophos XDR’s ongoing excellence in industry testing and real-world defenses, enabling customers to stop both known and unknown threats before they escalate.”

The MITRE ATT&CK Evaluations are recognized globally as independent tests of security solutions. The current evaluations assessed 19 vendors' capacities to detect and analyze attack techniques used by real-world adversaries. In this cycle, attacks were also simulated for macOS, with 19 out of 21 Sophos XDR detections earning a ‘technique’ rating.

Sophos XDR integrates features such as Adaptive Attack Protection, which activates enhanced defenses in response to detected attacks, alongside anti-ransomware technology and deep learning artificial intelligence. These capabilities are supported by Sophos X-Ops, a collaboration of over 500 security experts focused on threat intelligence.

For further details about the evaluation results, visit the Sophos website.

Disclaimer: MITRE does not rank or rate participants.