Skip to content

Endpoint API update

Enhancing Threat Investigations: Memory Dump Collection in Forensic Logs

Sophos Endpoint has expanded its Forensic Logs feature to include memory dump collection, providing investigators with another valuable tool for tracing the circumstances surrounding security incidents. Analysts can capture either kernel memory dumps or process-specific memory dumps from Windows devices. Initiating a memory dump request through the Sophos Central API prompts the target device to generate a memory dump of the specified process or the kernel. The dump is then securely uploaded to a customer-specified Amazon S3 bucket. Customers can configure their S3 bucket details on the 'Forensic snapshots' page in Sophos Central. For more information, please refer to our API reference documentation.