We review products independently, but we may earn commissions if you make a purchase using affiliate links on our website. Also note that we are not antivirus software; we only provide information about some products.

Independent feature audit · retired claims and platform limits rechecked August 5, 2026

Sophos Home Exploit and Privacy Protection Explained

Sophos Home still has a strong Windows behavior layer, but the feature names around it have aged badly. Mac Privacy Guard is gone, Windows keystroke encryption and badUSB protection were removed, and an Attack Intercepted alert is evidence to investigate—not permission to exclude an application blindly.

Windows exploit controlsMac limitsWebcam privacySafe exclusions

Quick answer: Sophos Home Premium and Trial provide Windows Exploit Mitigation, Protected Applications and behavior alerts such as Attack Intercepted, APC violation and Lockdown. Current support also describes Windows-only webcam privacy. On Mac, Sophos retired Privacy Guard in September 2023 and directs users to Apple camera and microphone permissions. Windows keystroke encryption and badUSB protection were permanently removed. Verify an alert before making an exception; choose the narrower Allow Behavior action when available, and never turn off every protection layer to make one app work.

The current answer is narrower than the sales copy

Sophos Home’s current support material gives Windows users a concrete Exploits area, protected-application controls and a workflow for malicious behavior detections. The same documentation describes webcam privacy as Windows-only. That is the product behavior a household can configure and troubleshoot today.

Mac is different. Sophos still scans, blocks malware and protects web activity, but its dedicated Privacy Guard was removed. A Mac user cannot follow a Windows screenshot, turn off a nonexistent Exploits slider or assume a stale Privacy tab represents active camera control. The operating system now owns those permissions.

This distinction matters because search results preserve old reviews and live marketing pages long after controls change. Our full Sophos Home review covers the suite; this guide deals with the messiest feature boundary and tells you what to do when a real alert interrupts work.

Exploit protection watches how trusted applications are abused

An exploit uses a flaw or an unsafe behavior in software to execute code, cross a security boundary or take control of another process. The malicious file may be new, packed or absent from the disk. Sophos Home therefore watches behavior around browsers, document readers, Office applications, scripts and other exposed programs instead of depending only on a known malware signature.

On Windows, this layer can stop process hollowing, application procedure call abuse and other exploit-like techniques. A visible alert may name the protected application, the attacking process or the mitigation. The name is a clue, not the whole story: malware can inject into a legitimate process, and a legitimate anti-cheat or installer can resemble the same technique.

Exploit Mitigation does not patch the vulnerable application. It can interrupt an attack path, but the vulnerable browser or document reader still needs its vendor update. Keep Windows and applications supported and current even when Sophos reports that it blocked the attempt.

Privacy protection is not a general privacy suite

In Sophos Home, privacy language has referred mainly to webcam access and adjacent security controls that reduce credential theft. It is not a VPN, password manager, identity-monitoring service, tracker-blocking browser, encrypted cloud vault or data-broker removal tool. A green Sophos status does not make browsing anonymous or prevent every application from collecting data you agreed to share.

Current Windows webcam protection can add a behavior-aware warning or control around camera use. Native Windows permissions and a physical shutter still matter because desktop applications are handled differently from Store apps. On Mac, Apple permissions and the green or orange activity indicators are the practical camera and microphone controls after Privacy Guard’s retirement.

Safe Browsing, phishing blocking and malware detection also protect private information, but they solve different problems. Keeping the labels separate makes troubleshooting safer: a phishing exception cannot fix a webcam alert, and a camera permission does not repair an exploit mitigation.

Windows and Mac do not expose the same controls

Control in 2026Windows HomemacOS HomeWhat owns the fallback
Exploit Mitigation settingsPremium and Trial; Protection → ExploitsNo equivalent Home workflow documentedOS/app updates and Sophos malware behavior controls
Protected Applications listAvailable in the Exploits areaNot documented for current HomeApplication and OS security
Webcam privacyCurrent support describes Windows-only protectionPrivacy Guard removedWindows or macOS camera permissions
Microphone privacyUse Windows permissions; do not infer it from webcam wordingUse macOS Privacy & SecurityOperating-system controls and indicators
AMSI script inspectionAvailable on supported WindowsWindows technology; not applicableWindows AMSI plus Sophos provider
Keyboard encryption / badUSBBoth removedNot current Home featuresMalware scanning, OS/device controls and safer input practices

The current Sophos disable guide is unusually clear: exploits are Windows-only, and its privacy feature secures the webcam on Windows only. The broader feature matrix confirms Windows and Mac share major antivirus, ransomware and web layers but vary by architecture.

Trial users receive Premium features while the 30-day trial is active. A Free or expired installation should be judged by the controls visible for that device, not a Premium screenshot. Mobile protection is a separate Intercept X for Mobile app and does not add these desktop controls to the Home dashboard.

Three familiar privacy claims are no longer current

Sophos says macOS Privacy Guard, also called privGuard, reached end of life in September 2023. Its retirement notice warns that some Mac users may still see a Privacy tab; the tab can be ignored. Sophos directs camera and microphone control to Apple’s settings.

On Windows, Protect against Keyloggers and Stop malicious USB devices were permanently removed. Keyboard encryption is not quietly running behind a gray switch, and real-time scanning of files on an external drive is not the same as badUSB device protection.

Safe Browsing remains and Sophos says it can help detect man-in-the-browser activity. That is worth keeping enabled, but it does not recreate encrypted keystrokes. If a comparison table still gives Sophos Home credit for keyboard encryption, microphone Privacy Guard on Mac or badUSB blocking, the table is describing an older product.

Sophos’ own marketing and support pages disagree

The current search result for Sophos’ anti-exploit sales page still says Windows and Mac protection and includes a line about encrypting keystrokes. Its current Home support articles say Exploit Mitigation and webcam privacy are Windows-only and explicitly remove keystroke encryption. Those statements cannot all describe the same present configuration.

For an action a reader will take today, we give the newer, platform-specific support documents more weight than evergreen sales copy. The marketing page is useful for the high-level idea—behavioral and exploit defenses supplement signatures—but not for deciding which slider exists or whether an old component remains installed.

This is also why we avoid a giant inherited feature checklist. A feature name without a current platform, edition, path and support article is not enough. The useful question is whether the reader can verify the control on the selected computer and whether Sophos still documents its behavior.

Sophos Home is not Sophos Central or enterprise Intercept X

Home borrows technology and component names from Sophos’ business products, but it does not expose the same policies, telemetry or response. Central documentation can discuss more than sixty exploit mitigations, root-cause graphs, remote isolation, data-lake queries, XDR, MDR and fleet-wide policy. Those features must not be pasted into a Home tutorial.

The Home administrator sees computers, New Activity, History and a smaller set of protection switches and exclusions. An Event Viewer entry can contain technical HitmanPro.Alert detail, yet that does not create a Central Threat Analysis Center. If an online answer tells a Home user to open a Central policy, Live Discover query or Detection ID workflow, it is solving a different product.

The boundary matters most during a suspected compromise. Home can block, alert, scan and support a household. It is not a managed incident-response service that proves attacker persistence, credential theft or lateral movement is gone. Preserve evidence and get professional help when the device contains business, regulated or safety-critical data.

Read Attack Intercepted as a stopped behavior, not a verdict

The current Windows behavior-detection guide names Attack Intercepted, Malicious behavior detected, Lockdown and APC violation as possible alerts. Windows Event Viewer may also record event ID 911 from HitmanPro.Alert. These labels identify the protection layer and mitigation, not a final malware family.

A blocked process can be malicious, a legitimate application under attack, or a legitimate program performing a technique that crossed the mitigation threshold. Keep it stopped while you inspect the path and context. Do not conclude that `browser.exe` is safe because the browser is familiar, or that an obscure game executable is malicious because the message sounds severe.

Check whether the alert appeared during an expected update, game launch, installer, document open or unsolicited download. Look for a second signal: changed settings, a new process, an unexpected child process, browser redirects, account alerts or repeated blocks outside the expected action. One alert deserves investigation; multiple independent indicators change the urgency.

Use a verified-versus-uncertain decision, not trial and error

The safest split happens before any exclusion. A verified application has an expected source, valid publisher, matching version and a behavior the vendor can explain. An uncertain application stays blocked while its event and sample are preserved. “I recognize the filename” is not verification.

Sophos Home Attack Intercepted alert verification and exclusion decision map
Editorial decision map, not Sophos product UI: verify the exact executable first, then prefer the narrow behavior allowance over a broad application exception.

Do not rerun a suspicious installer repeatedly to collect a cleaner screenshot. Preserve what already exists, scan the computer and submit the sample through a trusted route. If the app is confirmed legitimate, make one narrow change, reboot when required and retest the exact action.

Preserve the fields that explain an exploit block

Record the computer name, local time, complete Sophos message, mitigation name, application and target paths, publisher, file version and what the user clicked immediately before the event. In Event Viewer, preserve the provider, event ID 911, application, target, process trace and mitigation details. A screenshot is useful, but selectable text is easier to search and compare.

Do not post a full event dump publicly without checking usernames, folder names, command lines, document paths and network details. A community Event 911 example shows how much process and module data one entry can contain; use it only to understand the fields, not as a whitelist. Share the minimum needed with the application vendor or Sophos support, and submit suspected files through the official sample channel.

History helps distinguish a single compatibility event from a pattern. Our dashboard guide explains the device view, and the scan and exclusions guide covers sample verification and why one clean multi-engine result is not proof.

Verify the executable, its source and the expected behavior together

Start with the full path. A signed updater under the vendor’s expected directory is stronger evidence than the same filename in Downloads or a temporary folder. Check the digital signature, publisher, version and hash, then compare them with the official download or vendor support. A valid signature can still belong to vulnerable or compromised software, so it is one signal rather than a pass.

Ask what the program was doing. Anti-cheat, accessibility, remote-support, virtualization, backup and security software can inject, inspect or manipulate processes. That can explain a mitigation, but the category does not make every binary safe. Confirm the exact operation and whether the vendor acknowledges the Sophos conflict.

Update the application, Windows and Sophos, restart once and reproduce only the necessary action. If the alert vanishes after a supported update, no exception is needed. If it persists, submit the file or detection and keep it blocked until the publisher or Sophos gives a defensible answer.

Allow Behavior is narrower than Allow application

From New Activity or History, a verified exploit detection can expose Show Advanced Options and Did we get this wrong? Sophos says Allow Behavior is the preferred option. It permits the named behavior while leaving other mitigations for that application in place. That is the first choice when the current alert is understood.

Allow application is broader: Sophos says it whitelists any mitigation coming from that application. It can fix a stubborn compatibility problem, but it removes more behavioral coverage. Use it only when the application is trusted, the narrower choice cannot solve the issue and the risk is documented.

ChoiceScopeWhen it fitsReview rule
Keep blockedNo exceptionUnknown source, suspicious path or unexplained behaviorScan and submit evidence
Allow BehaviorNamed mitigation/behaviorVerified app and understood false positivePreferred; remove after fix
Allow applicationAny mitigation from the appVerified app; narrower action failedBroader blind spot; time-limit it
Disable Exploit MitigationProtection layer offShort controlled test onlyRe-enable immediately

Every exception should have an owner, exact file, reason, date and removal condition. Review it after an application update or Sophos fix. A months-old exception for an executable that no longer exists is not harmless housekeeping; it is proof the protection policy cannot be audited.

Local exclusions stay on one computer—and can hide off C:

A local exclusion is added through the Windows Sophos Home application under Help → Troubleshooting → Local Exclusions. Select the verified executable, not its parent game library, Downloads folder or entire drive. A local choice is useful when only one computer has the conflict and the household does not want the exception propagated through dashboard settings.

Sophos documents a known display issue for non-system drives: an executable on D:, E: or another drive can be excluded and work even though it does not appear in the local-exclusion dialog. Record the exact path before adding it. Do not add repeated copies because the list looks empty, and contact support when you cannot prove how to remove the hidden exception.

Local exclusions and scan exceptions are not interchangeable labels for harmless files. A folder scan exception can suppress more inspection than the executable-level exploit fix the user intended. Choose the control named in the current Sophos detection guide and keep its scope as small as the interface allows.

Removing a Protected Application lowers coverage for that app

The Windows dashboard’s Protection → Exploits area includes Protected Applications. Sophos allows a named application to be unchecked, followed by a reboot and retest. This is not the same as proving the application safe or globally disabling malware scanning; it stops that application receiving the selected exploit-protection coverage.

Use the option only after the event-level Allow Behavior path and vendor verification have been considered. Browsers, Office applications, document readers and communication tools are attractive exploit targets, so removing them permanently is a serious trade. If the affected app is internet-facing, an update or replacement is usually preferable to a standing protection gap.

Record the original state before changing the list. Restore it after the compatibility issue is resolved and confirm the dashboard reports healthy. A reboot can be part of both applying and reversing the change; do not assume a blue toggle has propagated while the endpoint is still pending restart.

Games and anti-cheat can collide with behavior protections

Sophos’ current game compatibility guide documents Attack Intercepted events with Easy Anti-Cheat, Steam titles and specific games. The named mitigations include APC violation and Kernel32Trap. That makes a false positive plausible during a known launch path, but not automatic.

Use an official game store or publisher installer, update the launcher and anti-cheat, verify the exact executable, and check the Sophos article for the named title. Prefer the event’s Allow Behavior choice. A local executable exclusion can be a fallback; excluding the entire Steam, Epic, Xbox or Riot library gives every present and future binary far more trust than the problem requires.

A Home user’s Xbox/Game Pass conflict report shows why the issue is frustrating: game updates can change binaries, exclusions can be hard to audit and turning off several layers can appear to “fix” the launch. That test proves a control caused the conflict; it does not prove which file is safe. Preserve the alert and involve the vendor when the workaround requires dismantling protection.

Temporary disabling is a last diagnostic, not a compatibility mode

Sophos permits Exploit Mitigation to be turned off briefly under Protection → Exploits when exclusions cannot solve a verified installation or launch problem. Its guide warns that the computer is vulnerable during the test and requires the control to be re-enabled after the action. A reboot is part of the documented sequence.

Before that test, close browsers and unrelated documents, disconnect unneeded shares, verify the installer from the official vendor and define one exact action. Do not browse, read email or install several packages while the layer is off. Re-enable it, reboot if required, check dashboard health and run the application again only under the restored protection.

Do not turn off every blue Sophos slider because one exploit alert appeared. The general disable guide is for controlled troubleshooting and explicitly says not to disable Home when a virus is suspected. If the app works only while several layers stay off, treat that as an unresolved compatibility or trust problem, not a finished setup.

Repair Exploit mitigations are disabled before trusting the endpoint

The warning “Exploit mitigations are Disabled” or “Exploit mitigation is experiencing problems” means the layer is not healthy. Sophos lists an incomplete installation, outdated Windows, a system restore, missed Sophos updates and another antivirus or HitmanPro installation among the causes. Clicking Enable without fixing the component may not be enough.

Follow the current repair order: install Windows updates, restart, let Sophos update, enable the setting and remove competing antivirus software. Check that the computer is online and use the built-in update control. If the problem remains, use Sophos’ supported uninstall and reinstall instructions rather than a third-party cleanup utility.

Advanced troubleshooting checks whether the HitmanPro.Alert service is installed and running. Preserve the exact status before changing services. Our Sophos Home installation guide covers clean reinstall and post-install validation; the endpoint should not return to normal use until the warning is gone and updates, real-time protection and exploit status all report correctly.

Use Sophos webcam privacy with Windows camera permissions

Current Sophos support describes privacy features that secure the webcam on Windows only. Treat a camera-access alert like an exploit alert: record the process and path, decide whether the access was expected and block an unknown application. A meeting app using the camera during a call is different from an unsigned process opening it in the background.

Windows 11 also provides Settings → Privacy & security → Camera. Microsoft’s camera permission guide lets Store apps be controlled individually but warns that classic desktop apps may not appear as individual switches. Desktop browsers and meeting apps can be governed by the broader desktop-app access control and their own settings.

Keep both layers and use a physical shutter when the camera is not needed. The shutter covers failures in software policy but not the microphone, so review Windows microphone access separately. If an application needs camera access only occasionally, close it after use and remove unneeded startup/background permissions.

On Mac, Apple permissions replaced Sophos Privacy Guard

Sophos removed Mac Privacy Guard in September 2023. Its notice says a remaining Privacy tab can be ignored and points users to Apple controls. Sophos still blocks malware behavior, malicious traffic and other threats on Mac, but that security coverage must not be described as the retired per-application Privacy Guard.

Open System Settings → Privacy & Security, then review Camera and Microphone. Apple’s privacy control guide explains that apps request access and can be toggled later. A green indicator shows camera use and an orange indicator shows microphone use; Control Centre identifies the application currently or recently using the sensor.

Remove access for applications that no longer need it, uninstall unknown software and investigate unexpected indicators. A physical camera shutter remains useful. Do not install an old Sophos package or copy a dashboard screenshot from another Mac to “restore” Privacy Guard; keep the supported Home build and let macOS own sensor permissions.

AMSI, Safe Browsing and Tamper Protection solve different problems

LayerMain jobWhat it does not replace
Exploit MitigationStops exploit-like behavior around protected Windows appsVendor patches and malware investigation
AMSI integrationLets Sophos inspect obfuscated, encrypted or in-memory Windows scriptsExploit controls, macro policy or safe scripting practice
Safe BrowsingReduces phishing, compromised-site and man-in-the-browser riskRemoved keyboard encryption or a password manager
Webcam privacyAdds Windows camera-use protectionOS permissions, microphone controls or a physical shutter
Tamper ProtectionPrevents unauthorized changes to Sophos components on WindowsAccount security or incident response

The AMSI documentation is Windows-specific. It covers scripts that hide through obfuscation, encryption or direct memory execution. An AMSI detection belongs in a script investigation; it is not proof that the Privacy area or Exploit slider failed.

Windows Tamper Protection protects Sophos files, folders, logs and services. Sophos says a supported temporary disable automatically ends after four hours or a reboot. Never disable it while a malware attack is suspected. Safe Browsing should remain enabled, but remember that it survived as a different control after Protect against Keyloggers was removed.

Exploit prevention starts with supported, patched software

Patch Windows, browsers, Office, PDF readers, communication tools, game launchers and remote-access software promptly. Sophos’ current support policy expects supported operating systems. Its requirements still list Windows 10 64-bit in soft retirement, but exploit mitigation cannot replace missing operating-system security updates; use a supported patch path or move the computer to Windows 11.

Use a standard Windows account for daily work and approve administrator actions deliberately. Remove unused browser extensions, old document viewers, remote-control tools and abandoned launchers. Disable macros from untrusted documents and do not paste commands from a web page into PowerShell or Terminal merely because a “fix” says antivirus is blocking the download.

Use MFA for email, the Sophos account and software-store accounts, because a stolen account can deliver a signed-looking update through an expected channel. Keep backups versioned and outside the everyday account’s reach. The CryptoGuard guide covers the separate file-encryption layer and recovery plan.

Current evidence supports layered protection, not a Home exploit percentage

Independent whole-product tests can show whether Sophos Home or a related engine blocked malware and web attacks in a test set. They do not publish a current, reproducible percentage for the consumer Exploit Mitigation slider, Windows webcam privacy or every named mitigation across all applications. Enterprise Intercept X demonstrations are not a substitute for Home-specific measurements.

Community reports help reveal compatibility patterns—games, anti-cheat, installers and Event Viewer 911 detail—but they are directional. Old threads may refer to an earlier HitmanPro.Alert build, a business policy or a mitigation Sophos retuned. We use them to ask what can break, not to invent a universal whitelist.

The defensible conclusion is practical: keep the current Windows controls on, investigate every block with file and process context, and make the smallest verified exception. On Mac, use Apple privacy controls without pretending the retired Privacy Guard still exists. That gives the household strong layers without promising features the current product no longer ships.

Sophos Home exploit and privacy FAQ

Does Sophos Home have exploit protection?

Yes, but the current actionable Home documentation is platform-specific. Sophos Home Premium and the 30-day Trial expose Exploit Mitigation and Protected Applications on Windows. Current Sophos support describes these controls as Windows-only, even though an older marketing page still uses broader Windows-and-Mac wording. Mac continues to receive Sophos malware and web protection, but it does not expose the same Home exploit-control workflow.

What does Attack Intercepted mean in Sophos Home?

It means Sophos stopped behavior that matched an exploit mitigation. The named application may be malicious, compromised or legitimate software that crossed a behavioral rule. Keep it stopped while you record the mitigation, executable path, publisher, source, time and any Event Viewer ID 911 details. Verify the exact file before allowing a behavior or application.

Is Event Viewer ID 911 proof of malware?

No. Event ID 911 is useful evidence from the HitmanPro.Alert exploit component, not a malware verdict. Read the mitigation name, application, target, path and process details. A legitimate game, anti-cheat, installer or application can trigger a mitigation, while malware can use a trustworthy-looking process. Decide from the complete context.

Should I choose Allow Behavior or Allow application?

Choose Allow Behavior when Sophos offers it and you have verified the exact event. Sophos calls it the preferred option, and it is narrower. Allow application permits any mitigation from that application and creates a broader blind spot. Record every exception and review or remove it after the vendor or Sophos resolves the conflict.

Why is my D: or E: drive exclusion missing from the Sophos list?

Sophos documents a Windows display issue: a local exclusion for an executable on a non-system drive can apply even though it does not appear in the local-exclusion dialog. Do not keep adding duplicates. Record the exact executable, restart if required, retest once and contact Sophos if you cannot audit or remove the exception safely.

Does Sophos Home protect the webcam on Windows?

Current Sophos support describes a Windows-only privacy feature that secures the webcam. Use it together with Windows Privacy & security camera permissions and a physical shutter. Windows notes that classic desktop applications may not appear as individually controllable camera apps, so no single permission screen proves every desktop process is blocked.

Does Sophos Home Privacy Guard still work on Mac?

No. Sophos says macOS Privacy Guard, also called privGuard, was removed in September 2023. A stale Privacy tab may still appear in the Home dashboard and can be ignored. Use macOS Privacy & Security camera and microphone permissions and the green/orange activity indicators; Sophos still supplies malware protection but not the retired Privacy Guard control.

Does Sophos Home still encrypt keystrokes or block badUSB devices?

No. Sophos permanently removed Windows Protect against Keyloggers keyboard encryption and Stop malicious USB devices badUSB protection. Safe Browsing and real-time malware scanning remain, but they are different controls. A current marketing page that still mentions encrypted keystrokes should not be treated as the actionable product specification.

Can I disable Exploit Mitigation to make a game or installer work?

Only as a short, last troubleshooting test after the application is verified and narrower exclusions fail. Sophos warns that disabling Exploit Mitigation leaves the computer vulnerable and requires re-enabling it after the test. Do not disable all Home protection, browse normally or open unrelated files while the control is off.

How do I fix Exploit mitigations are disabled?

Update Windows and Sophos, restart, enable the setting, remove conflicting antivirus software and confirm the computer is online. If the warning remains, Sophos may require a supported uninstall and reinstall; its advanced check looks for the HitmanPro.Alert service. Preserve the exact warning and avoid downloading repair tools from third-party sites.

Bottom line: keep the behavior layer, retire the old claims

Sophos Home’s Windows exploit protection is useful precisely because it can stop suspicious behavior that a file signature misses. Keep it enabled, read Attack Intercepted and event ID 911 as investigation evidence, and prefer Allow Behavior over a broad application exception after the executable is genuinely verified.

Build privacy around what exists now. Use Windows webcam protection with native camera permissions and a physical shutter; use Apple permissions on Mac because Privacy Guard is gone. Do not credit Sophos Home with removed keystroke encryption or badUSB protection. Accurate boundaries make the remaining controls easier to trust and much safer to troubleshoot.