Skip to content

Sophos Events Database

Evidence: Sophos Events Database
Description: Collect Sophos Events Database
Category: Applications
Platform: macos
Short Name: sedb
Is Parsed: No
Sent to Investigation Hub: No
Collect File(s): Yes

Sophos Anti-Virus for Mac maintains an events database (events.db) that stores all security events, threat detections, scan results, and quarantine activities. This SQLite database contains comprehensive security event history.

This collector gathers structured data about sophos events database.

This collector gathers the Sophos events.db database file from the system-wide Library/Sophos Anti-Virus directory, which contains structured security event data.

The Sophos events database is critical for investigating malware detections, understanding threat timelines, identifying quarantined files, and analyzing security incidents on macOS. It provides detailed, queryable security event history.