Kaspersky Anti Targeted Attack Platform

Managing Endpoint Agent host information

The application that is used as the Endpoint Agent component is installed on individual computers (hereinafter also referred to as "hosts") in the IT infrastructure of the organization. The application continuously monitors processes running on those hosts, active network connections, and files that are being modified.

Users with the Senior security officer, Security officer, Security auditor, Local administrator, or Administrator role can assess how regularly data is received from hosts with the Endpoint Agent component on the Endpoint Agents tab of the web interface window of the Central Node server for tenants to whose data the user has access. If you are using the

and mode, the web interface of the PCN server displays the list of hosts with the Endpoint Agent component for the PCN and all connected SCNs.

Users with the Local administrator and Administrator roles can configure the display of how regularly data is received from hosts with Endpoint Agent for tenants to whose data they have access.

If suspicious network activity is detected, users with the Senior security officer role can isolate from the network any host with Kaspersky Endpoint Agent, for tenants to whose data the user has access. In this case, the connection between the server with the Central Node component and a host with the Endpoint Agent component will not be interrupted.

In order to provide support in case of problems with the Endpoint Agent component, Technical Support staff may ask you to perform the following actions for debugging purposes (including in Technical Support Mode):

  • Activate collection of extended diagnostic information.
  • Modify the settings of individual application components.
  • Modify the settings for storing and sending the obtained diagnostic information.
  • Configure network traffic to be intercepted and saved to a file.

Technical Support staff will provide all the information needed to perform these operations (description of the sequence of steps, settings to be modified, configuration files, scripts, additional command line functionality, debugging modules, special-purpose utilities, and other resources) and inform you about the scope of data obtained for debugging purposes. The retrieved diagnostic information is saved on the user's computer. The retrieved data is not automatically sent to Kaspersky.

The operations listed above should be performed only when instructed by and under the supervision of Technical Support experts. Unsupervised changes to application settings performed in ways other than those described in this manual or according to the instructions of Technical Support experts can slow down or crash the operating system, reduce computer security, or compromise the availability and integrity of data being processed.

In this section

Viewing the table of hosts with the Endpoint Agent component

Configuring the display of the table of hosts with the Endpoint Agent component

Viewing information about a host

Filtering and searching hosts with the Endpoint Agent component by host name

Filtering and searching hosts with the Endpoint Agent component that have been isolated from the network

Filtering and searching hosts with the Endpoint Agent component by PCN and SCN server names

Filtering and searching hosts with the Endpoint Agent component by computer IP address

Filtering and searching hosts with the Endpoint Agent component by operating system version on the computer

Filtering and searching hosts with the Endpoint Agent component by component version

Filtering and searching hosts with the Endpoint Agent component by their activity

Quickly creating a filter for hosts with the Endpoint Agent component

Resetting the filter for hosts with the Endpoint Agent component

Removing hosts with the Endpoint Agent component

Configuring activity indicators of the Endpoint Agent component

Supported interpreters and processes

Page top
[Topic 247381_1]

Viewing the table of hosts with the Endpoint Agent component

The table of hosts with the Endpoint Agent component is located in the Endpoint Agents section of the application web interface window.

If you are using the distributed solution and multitenancy mode, the table contains information about hosts with the Endpoint Agent component connected to the PCN and all SCN servers.

The table can display the following data:

  • Number of hosts and activity indicators of the Endpoint Agent component:
    • Critical inactivity is the number of hosts from which latest data was received a very long time ago.
    • Warning is the number hosts from which latest data was received a long time ago.
    • Normal activity is the number of hosts from which latest data was recently received.
  • Host—Name of the host with the Endpoint Agent component.
  • Server is the name of the server to which the host with the Endpoint Agent component is connected.

    This column is displayed if you are using the distributed solution and multitenancy mode.

  • IP is the IP address of the host where the Endpoint Agent component is installed.
  • OS is the version of the operating system that is installed on the computer with the Endpoint Agent application.
  • Version—Version of the Endpoint Agent component installed.
  • Activity is the activity indicator of the Endpoint Agent application.
    • Normal activity for hosts from which latest data was recently received.
    • Warning for hosts from which latest data was received a long time ago.
    • Critical inactivity for hosts from which latest data was received an extremely long time ago.

Clicking the link with the host name opens a list in which you can select one of the following actions:

  • Filter by this value.
  • Exclude from filter.
  • Run the following tasks:
    • Kill process.
    • Delete file.
    • Kill by unique PID.
    • Get file.
    • Get forensics.
    • Quarantine file.
    • Run application.
  • New prevention rule.
  • Isolate from network.
  • Find events.
  • Find alerts.
  • Copy value to clipboard.

The list of available actions depends on the Endpoint Agent component type (for Windows or Linux), version, and activity indicator.

Clicking the link with the IP opens a list in which you can select one of the following actions:

  • Filter by this value.
  • Exclude from filter.
  • Find alerts.
  • Copy value to clipboard.

Clicking a link in any other column of the table opens a list in which you can select one of the following actions:

  • Filter by this value.
  • Exclude from filter.
  • Copy value to clipboard.

See also

Managing Endpoint Agent host information

Configuring the display of the table of hosts with the Endpoint Agent component

Viewing information about a host

Filtering and searching hosts with the Endpoint Agent component by host name

Filtering and searching hosts with the Endpoint Agent component that have been isolated from the network

Filtering and searching hosts with the Endpoint Agent component by PCN and SCN server names

Filtering and searching hosts with the Endpoint Agent component by computer IP address

Filtering and searching hosts with the Endpoint Agent component by operating system version on the computer

Filtering and searching hosts with the Endpoint Agent component by component version

Filtering and searching hosts with the Endpoint Agent component by their activity

Quickly creating a filter for hosts with the Endpoint Agent component

Resetting the filter for hosts with the Endpoint Agent component

Removing hosts with the Endpoint Agent component

Configuring activity indicators of the Endpoint Agent component

Supported interpreters and processes

Page top
[Topic 247382]

Configuring the display of the table of hosts with the Endpoint Agent component

You can show or hide columns and change the order of columns in the table of hosts with the Endpoint Agent component.

To configure the display of the table of hosts with the Endpoint Agent component:

  1. Select the Endpoint Agents section in the window of the application web interface.
  2. In the heading part of the table, click APT_icon_customize_table.
  3. This opens the Customize table window.
  4. If you want to show a column in the table, select the check box next to the name of the parameter that you want displayed in the table.

    If you want to hide a parameter in the table, clear the check box.

    At least one check box must be selected.

  5. If you want to change the order of columns in the table, move the mouse cursor to the row with the relevant parameter, click APT_icon_customize_columnes_order and move the row to its new place.
  6. If you want to restore default table display settings, click Default.
  7. Click Apply.

The display of the table of hosts with the Endpoint Agent component is configured.

Page top
[Topic 215333]

Viewing information about a host

To view information about a host with the Endpoint Agent component:

  1. Select the Endpoint Agents section in the window of the application web interface.
  2. Select the host for which you want to view information.

This opens a window containing information about the host.

The window contains the following information:

  • Recommendations group:
    • Clicking the Alerts link opens the Alerts section with the search condition containing the selected host.
    • Clicking the Events link opens the Threat Hunting section with the search condition containing the selected host.
    • Clicking the Events affected by prevention rules link opens the Threat Hunting section with the search condition containing the selected host and the Blocked application (prevention rule) event type.

    The Events affected by prevention rules link is not displayed in the information about hosts that use Kaspersky Endpoint Agent for Linux or Kaspersky Endpoint Security for Linux as the Endpoint Agent components.

  • On the Details tab, the Host section displays the following information:
    • Name is the name of the host with the Endpoint Agent component.
    • IP is the IP address of the host where the Endpoint Agent component is installed.
    • OS—Version of the operating system on the host with the Endpoint Agent component installed.
  • On the Details tab, the Endpoint Agent section displays the following information:
    • Version—Version of the Endpoint Agent component installed.
  • Activity is the activity indicator of the Endpoint Agent component. Possible values:
    • Normal activity for hosts from which latest data was recently received.
    • Warning for hosts from which latest data was received a long time ago.
    • Critical inactivity for hosts from which latest data was received an extremely long time ago.
  • Server—Name of the SCN or PCN server. Only displayed in distributed solution and multitenancy mode.
  • Connected to server—Name of the Central Node server.
  • Last connection—time of the last connection to the Central Node, SCN, or PCN server.
  • License key status—For example, "OK".
  • On the Prevention rules tab, you can see MD5 or SHA256 hashes for files that were prevented from running or opening on the host. The following information is displayed:
    • Name—Name of the file.
    • State—State of the prevention rule.
    • Hash—Hashing algorithm.

    The Prevention rules tab is not displayed in the information for hosts with Kaspersky Endpoint Agent for Linux and Kaspersky Endpoint Security for Linux.

  • On the Tasks tab, you can see which tasks were run on the host. The following information is displayed:
    • Time created—Task creation date and time.
    • Name—Task name.
    • Details—Full path to the file or data stream for which the task was created.
    • State—Task completion status.

Clicking the link with the host name opens a list in which you can select one of the following actions:

  • Run the following tasks:
    • Kill process.
    • Delete file.
    • Get file.
    • Get forensics.
    • Quarantine file.
    • Run application.
  • New prevention rule.
  • Isolate from network.
  • Find events.
  • Find alerts.
  • Copy value to clipboard.

    For hosts with Kaspersky Endpoint Agent for Linux and Kaspersky Endpoint Security for Linux, the list displayed by clicking the link with the host name includes only Get file, Run application, Find events, and Find alerts.

Clicking the link with the IP opens a list in which you can select one of the following actions:

  • Find alerts.
  • Copy value to clipboard.

See also

Managing Endpoint Agent host information

Viewing the table of hosts with the Endpoint Agent component

Configuring the display of the table of hosts with the Endpoint Agent component

Filtering and searching hosts with the Endpoint Agent component by host name

Filtering and searching hosts with the Endpoint Agent component that have been isolated from the network

Filtering and searching hosts with the Endpoint Agent component by PCN and SCN server names

Filtering and searching hosts with the Endpoint Agent component by computer IP address

Filtering and searching hosts with the Endpoint Agent component by operating system version on the computer

Filtering and searching hosts with the Endpoint Agent component by component version

Filtering and searching hosts with the Endpoint Agent component by their activity

Quickly creating a filter for hosts with the Endpoint Agent component

Resetting the filter for hosts with the Endpoint Agent component

Removing hosts with the Endpoint Agent component

Configuring activity indicators of the Endpoint Agent component

Supported interpreters and processes

Page top
[Topic 247388]

Filtering and searching hosts with the Endpoint Agent component by host name

To filter or search for hosts with the Endpoint Agent component by host name:

  1. Select the Endpoint Agents section in the window of the application web interface.

    This opens the table of hosts.

  2. Click the Host link to open the filter configuration window.
  3. If you want to display only isolated hosts, select the Show isolated Endpoint Agents only check box.
  4. In the drop-down list, select one of the following filtering operators:
    • Contain
    • Not contain
  5. In the entry field, specify one or several characters of the host name.
  6. To add a filter condition using a different criterion, click Apt_icon_alerts_add_filter and specify the filter condition.
  7. If you want to delete the filter condition, click the kata_icon_delete_ep button to the right of the field.
  8. Click Apply.

The filter configuration window closes.

The table displays only those hosts that match the filter criteria you have set.

You can use multiple filters at the same time.

See also

Managing Endpoint Agent host information

Viewing the table of hosts with the Endpoint Agent component

Configuring the display of the table of hosts with the Endpoint Agent component

Viewing information about a host

Filtering and searching hosts with the Endpoint Agent component that have been isolated from the network

Filtering and searching hosts with the Endpoint Agent component by PCN and SCN server names

Filtering and searching hosts with the Endpoint Agent component by computer IP address

Filtering and searching hosts with the Endpoint Agent component by operating system version on the computer

Filtering and searching hosts with the Endpoint Agent component by component version

Filtering and searching hosts with the Endpoint Agent component by their activity

Quickly creating a filter for hosts with the Endpoint Agent component

Resetting the filter for hosts with the Endpoint Agent component

Removing hosts with the Endpoint Agent component

Configuring activity indicators of the Endpoint Agent component

Supported interpreters and processes

Page top
[Topic 247545_1]

Filtering and searching hosts with the Endpoint Agent component that have been isolated from the network

To filter or search for hosts with the Endpoint Agent component that are isolated from the network:

  1. Select the Endpoint Agents section in the window of the application web interface.

    This opens the table of hosts.

  2. Click the Host link to open the filter configuration window.
  3. Select the Show isolated Endpoint Agents only check box.
  4. Click Apply.

The filter configuration window closes.

The table displays only those hosts that match the filter criteria you have set.

You can use multiple filters at the same time.

See also

Managing Endpoint Agent host information

Viewing the table of hosts with the Endpoint Agent component

Configuring the display of the table of hosts with the Endpoint Agent component

Viewing information about a host

Filtering and searching hosts with the Endpoint Agent component by host name

Filtering and searching hosts with the Endpoint Agent component by PCN and SCN server names

Filtering and searching hosts with the Endpoint Agent component by computer IP address

Filtering and searching hosts with the Endpoint Agent component by operating system version on the computer

Filtering and searching hosts with the Endpoint Agent component by component version

Filtering and searching hosts with the Endpoint Agent component by their activity

Quickly creating a filter for hosts with the Endpoint Agent component

Resetting the filter for hosts with the Endpoint Agent component

Removing hosts with the Endpoint Agent component

Configuring activity indicators of the Endpoint Agent component

Supported interpreters and processes

Page top
[Topic 247547_1]

Filtering and searching hosts with the Endpoint Agent component by PCN and SCN server names

If you are using the distributed solution and multitenancy mode, you can filter or find hosts with the Kaspersky Endpoint Agent component based on the names of PCN and SCN servers to which those hosts are connected.

To filter or search for hosts with the Endpoint Agent component by the names of PCN and SCN servers:

  1. Select the Endpoint Agents section in the window of the application web interface.

    This opens the table of hosts.

  2. Click the Servers link to open the filter configuration window.
  3. Select check boxes next to names of servers by which you want to filter or search for hosts with the Endpoint Agent component.
  4. Click Apply.

The filter configuration window closes.

The table displays only those hosts that match the filter criteria you have set.

You can use multiple filters at the same time.

See also

Managing Endpoint Agent host information

Viewing the table of hosts with the Endpoint Agent component

Configuring the display of the table of hosts with the Endpoint Agent component

Viewing information about a host

Filtering and searching hosts with the Endpoint Agent component by host name

Filtering and searching hosts with the Endpoint Agent component that have been isolated from the network

Filtering and searching hosts with the Endpoint Agent component by computer IP address

Filtering and searching hosts with the Endpoint Agent component by operating system version on the computer

Filtering and searching hosts with the Endpoint Agent component by component version

Filtering and searching hosts with the Endpoint Agent component by their activity

Quickly creating a filter for hosts with the Endpoint Agent component

Resetting the filter for hosts with the Endpoint Agent component

Removing hosts with the Endpoint Agent component

Configuring activity indicators of the Endpoint Agent component

Supported interpreters and processes

Page top
[Topic 247544_1]

Filtering and searching hosts with the Endpoint Agent component by computer IP address

To filter or search for hosts with the Endpoint Agent component by IP address of the computer on which the application is installed:

  1. Select the Endpoint Agents section in the window of the application web interface.

    This opens the table of hosts.

  2. Click the IP link to open the filter configuration window.
  3. In the drop-down list, select one of the following filtering operators:
    • Contain
    • Not contain
  4. In the entry field, specify one or several characters of the computer IP address. You can enter the IP address or subnet mask in IPv4 format (for example, 192.0.0.1 or 192.0.0.0/16).
  5. To add a filter condition using a different criterion, click Apt_icon_alerts_add_filter and specify the filter condition.
  6. If you want to delete the filter condition, click the kata_icon_delete_ep button to the right of the field.
  7. Click Apply.

The filter configuration window closes.

The table displays only those hosts that match the filter criteria you have set.

You can use multiple filters at the same time.

See also

Managing Endpoint Agent host information

Viewing the table of hosts with the Endpoint Agent component

Configuring the display of the table of hosts with the Endpoint Agent component

Viewing information about a host

Filtering and searching hosts with the Endpoint Agent component by host name

Filtering and searching hosts with the Endpoint Agent component that have been isolated from the network

Filtering and searching hosts with the Endpoint Agent component by PCN and SCN server names

Filtering and searching hosts with the Endpoint Agent component by operating system version on the computer

Filtering and searching hosts with the Endpoint Agent component by component version

Filtering and searching hosts with the Endpoint Agent component by their activity

Quickly creating a filter for hosts with the Endpoint Agent component

Resetting the filter for hosts with the Endpoint Agent component

Removing hosts with the Endpoint Agent component

Configuring activity indicators of the Endpoint Agent component

Supported interpreters and processes

Page top
[Topic 247552_1]

Filtering and searching hosts with the Endpoint Agent component by operating system version on the computer

To filter or search for hosts with the Endpoint Agent component by version of the operating system installed on the computer:

  1. Select the Endpoint Agents section in the window of the application web interface.

    This opens the table of hosts.

  2. Click the OS link to open the filter settings window.
  3. In the drop-down list, select one of the following filtering operators:
    • Contain
    • Not contain
  4. In the entry field, specify one or several characters of the operating system version.
  5. To add a filter condition using a different criterion, click Apt_icon_alerts_add_filter and specify the filter condition.
  6. If you want to delete the filter condition, click the kata_icon_delete_ep button to the right of the field.
  7. Click Apply.

The filter configuration window closes.

The table displays only those hosts that match the filter criteria you have set.

You can use multiple filters at the same time.

See also

Managing Endpoint Agent host information

Viewing the table of hosts with the Endpoint Agent component

Configuring the display of the table of hosts with the Endpoint Agent component

Viewing information about a host

Filtering and searching hosts with the Endpoint Agent component by host name

Filtering and searching hosts with the Endpoint Agent component that have been isolated from the network

Filtering and searching hosts with the Endpoint Agent component by PCN and SCN server names

Filtering and searching hosts with the Endpoint Agent component by computer IP address

Filtering and searching hosts with the Endpoint Agent component by component version

Filtering and searching hosts with the Endpoint Agent component by their activity

Quickly creating a filter for hosts with the Endpoint Agent component

Resetting the filter for hosts with the Endpoint Agent component

Removing hosts with the Endpoint Agent component

Configuring activity indicators of the Endpoint Agent component

Supported interpreters and processes

Page top
[Topic 247554_1]

Filtering and searching hosts with the Endpoint Agent component by component version

You can filter hosts by version of the application that is used in the role of the Endpoint Agent component.

To filter or search for hosts with the Endpoint Agent component by component version:

  1. Select the Endpoint Agents section in the window of the application web interface.

    This opens the table of hosts.

  2. Click the Version link to open the filter settings window.
  3. In the drop-down list, select one of the following filtering operators:
    • Contain
    • Not contain
  4. In the entry field, specify one or more characters of the version of the application that is used as the Endpoint Agent component.
  5. To add a filter condition using a different criterion, click Apt_icon_alerts_add_filter and specify the filter condition.
  6. If you want to delete the filter condition, click the kata_icon_delete_ep button to the right of the field.
  7. Click Apply.

The filter configuration window closes.

The table displays only those hosts that match the filter criteria you have set.

You can use multiple filters at the same time.

See also

Managing Endpoint Agent host information

Viewing the table of hosts with the Endpoint Agent component

Configuring the display of the table of hosts with the Endpoint Agent component

Viewing information about a host

Filtering and searching hosts with the Endpoint Agent component by host name

Filtering and searching hosts with the Endpoint Agent component that have been isolated from the network

Filtering and searching hosts with the Endpoint Agent component by PCN and SCN server names

Filtering and searching hosts with the Endpoint Agent component by computer IP address

Filtering and searching hosts with the Endpoint Agent component by operating system version on the computer

Filtering and searching hosts with the Endpoint Agent component by their activity

Quickly creating a filter for hosts with the Endpoint Agent component

Resetting the filter for hosts with the Endpoint Agent component

Removing hosts with the Endpoint Agent component

Configuring activity indicators of the Endpoint Agent component

Supported interpreters and processes

Page top
[Topic 247553_1]

Filtering and searching hosts with the Endpoint Agent component by their activity

To filter or search for hosts with the Endpoint Agent component by their activity:

  1. Select the Endpoint Agents section in the window of the application web interface.

    This opens the table of hosts.

  2. Click the Activity link to open the filter configuration window.

    Select check boxes next to one or multiple activity indicators:

    • Normal activity, if you want to find hosts from which the last data was recently received.
    • Warning, if you want to find hosts from which the last data was received a long time ago.
    • Critical inactivity, if you want to find hosts from which the last data was received an extremely long time ago.
  3. Click Apply.

The filter configuration window closes.

The table displays only those hosts that match the filter criteria you have set.

You can use multiple filters at the same time.

See also

Managing Endpoint Agent host information

Viewing the table of hosts with the Endpoint Agent component

Configuring the display of the table of hosts with the Endpoint Agent component

Viewing information about a host

Filtering and searching hosts with the Endpoint Agent component by host name

Filtering and searching hosts with the Endpoint Agent component that have been isolated from the network

Filtering and searching hosts with the Endpoint Agent component by PCN and SCN server names

Filtering and searching hosts with the Endpoint Agent component by computer IP address

Filtering and searching hosts with the Endpoint Agent component by operating system version on the computer

Filtering and searching hosts with the Endpoint Agent component by component version

Quickly creating a filter for hosts with the Endpoint Agent component

Resetting the filter for hosts with the Endpoint Agent component

Removing hosts with the Endpoint Agent component

Configuring activity indicators of the Endpoint Agent component

Supported interpreters and processes

Page top
[Topic 247546_1]

Quickly creating a filter for hosts with the Endpoint Agent component

To quickly create a filter for hosts with the Endpoint Agent component:

  1. Select the Endpoint Agents section in the window of the application web interface.

    This opens the table of hosts.

  2. Do the following to quickly add filter conditions to the filter being created:
    1. Position the mouse cursor on the link containing the table column value that you want to add as a filter condition.
    2. Left-click it.

      This opens a list of actions to perform on the value.

    3. In the list that opens, select one of the following actions:
      • Filter by this value, if you want to include this value in the filter condition.
      • Exclude from filter, if you want to exclude the value from the filter condition.

  3. If you want to add several filter conditions to the filter being created, perform the actions to quickly add each filter condition to the filter being created.

The table displays only those hosts that match the filter criteria you have set.

See also

Managing Endpoint Agent host information

Viewing the table of hosts with the Endpoint Agent component

Configuring the display of the table of hosts with the Endpoint Agent component

Viewing information about a host

Filtering and searching hosts with the Endpoint Agent component by host name

Filtering and searching hosts with the Endpoint Agent component that have been isolated from the network

Filtering and searching hosts with the Endpoint Agent component by PCN and SCN server names

Filtering and searching hosts with the Endpoint Agent component by computer IP address

Filtering and searching hosts with the Endpoint Agent component by operating system version on the computer

Filtering and searching hosts with the Endpoint Agent component by component version

Filtering and searching hosts with the Endpoint Agent component by their activity

Resetting the filter for hosts with the Endpoint Agent component

Removing hosts with the Endpoint Agent component

Configuring activity indicators of the Endpoint Agent component

Supported interpreters and processes

Page top
[Topic 247551_1]

Resetting the filter for hosts with the Endpoint Agent component

To clear the Endpoint Agent host filter for one or more filtering criteria:

  1. Select the Endpoint Agents section in the window of the application web interface.
  2. Click Delete to the right of the header of the table column for which you want to clear the filter conditions.

    If you want to clear several filter conditions, perform the necessary actions to clear each filter condition.

The selected filters are cleared.

The table displays only those hosts that match the filter criteria you have set.

See also

Managing Endpoint Agent host information

Viewing the table of hosts with the Endpoint Agent component

Configuring the display of the table of hosts with the Endpoint Agent component

Viewing information about a host

Filtering and searching hosts with the Endpoint Agent component by host name

Filtering and searching hosts with the Endpoint Agent component that have been isolated from the network

Filtering and searching hosts with the Endpoint Agent component by PCN and SCN server names

Filtering and searching hosts with the Endpoint Agent component by computer IP address

Filtering and searching hosts with the Endpoint Agent component by operating system version on the computer

Filtering and searching hosts with the Endpoint Agent component by component version

Filtering and searching hosts with the Endpoint Agent component by their activity

Quickly creating a filter for hosts with the Endpoint Agent component

Removing hosts with the Endpoint Agent component

Configuring activity indicators of the Endpoint Agent component

Supported interpreters and processes

Page top
[Topic 247555_1]

Removing hosts with the Endpoint Agent component

To remove one or more hosts from the Endpoint Agents table:

  1. Select the Endpoint Agents section in the window of the application web interface.
  2. Select check boxes next to one or more hosts that you want to remove. You can select all hosts by selecting the check box in the row containing the headers of columns.

    A control panel appears in the lower part of the window.

  3. Click Delete.
  4. This opens the action confirmation window; in that window, click Yes.

The selected hosts are removed from the Endpoint Agents table.

When hosts are removed the following changes are made in the web interface of Kaspersky Anti Targeted Attack Platform:

  • You cannot create a task, prevention rule, or network isolation rule for a removed host.
  • If a prevention rule was previously created for a host, its name in the rule window (the Prevent on field) is hidden when the host is removed. The rule continues to apply.

    If this host reconnects to the Central Node server, the host name is restored in the Prevent on field and the prevention rule is applied to it again.

  • If a network isolation rule was previously created for a host, it continues to apply until the time specified in the rule expires.

    When this host reconnects to the Central Node, the rule is reapplied to this host.

  • If an object was quarantined by the Quarantine file task on one host only and that host was removed, the Restore all button in task window is inactive because the file cannot be restored on a removed host.

Event search by the name of the removed host remains available.

Page top

[Topic 252342_1]

Configuring activity indicators of the Endpoint Agent component

Users with the Local administrator and Administrator roles can define what durations of inactivity of the application that is used as the Endpoint Agent component are to be considered normal, low, or very low activity, and can configure the activity indicators for the application. Users with the Security auditor role can only view the settings of application activity indicators. Users with the Senior security officer or Security officer role can see activity indicators that you configured for the Endpoint Agent component in the Activity field of the Endpoint Agent host table in the Endpoint Agents section of the application web interface.

To configure activity indicators for the Endpoint Agent component:

  1. Sign in to the application web interface under the Local administrator, Administrator or Senior security officer account.
  2. In the window of the application web interface, select the Settings section, Endpoint Agents subsection.
  3. In the fields under the section name, enter the number of days of inactivity of hosts with the Endpoint Agent component that you want to display as Warning and Critical inactivity.
  4. Click Apply.

Activity indicators of the Endpoint Agent component are configured.

See also

Managing Endpoint Agent host information

Viewing the table of hosts with the Endpoint Agent component

Configuring the display of the table of hosts with the Endpoint Agent component

Viewing information about a host

Filtering and searching hosts with the Endpoint Agent component by host name

Filtering and searching hosts with the Endpoint Agent component that have been isolated from the network

Filtering and searching hosts with the Endpoint Agent component by PCN and SCN server names

Filtering and searching hosts with the Endpoint Agent component by computer IP address

Filtering and searching hosts with the Endpoint Agent component by operating system version on the computer

Filtering and searching hosts with the Endpoint Agent component by component version

Filtering and searching hosts with the Endpoint Agent component by their activity

Quickly creating a filter for hosts with the Endpoint Agent component

Resetting the filter for hosts with the Endpoint Agent component

Removing hosts with the Endpoint Agent component

Supported interpreters and processes

Page top
[Topic 247556_1]

Supported interpreters and processes

Kaspersky Endpoint Agent application monitors the execution of scripts by the following interpreters:

  • cmd.exe
  • reg.exe
  • regedit.exe
  • regedt32.exe
  • cscript.exe
  • wscript.exe
  • mmc.exe
  • msiexec.exe
  • mshta.exe
  • rundll32.exe
  • runlegacycplelevated.exe
  • control.exe
  • explorer.exe
  • regsvr32.exe
  • wwahost.exe
  • powershell.exe
  • java.exe and javaw.exe (only if started with the –jar option)
  • InstallUtil.exe
  • msdt.exe
  • python.exe
  • ruby.exe
  • rubyw.exe

Information about the processes monitored by Kaspersky Endpoint Agent application is presented in the table below.

Processes and the file extensions that they open

Process

File extensions

winword.exe

rtf

doc

dot

docm

docx

dotx

dotm

docb

excel.exe

xls

xlt

xlm

xlsx

xlsm

xltx

xltm

xlsb

xla

xlam

xll

xlw

powerpnt.exe

ppt

pot

pps

pptx

pptm

potx

potm

ppam

ppsx

ppsm

sldx

sldm

acrord32.exe

pdf

wordpad.exe

docx

pdf

chrome.exe

pdf

MicrosoftEdge.exe

pdf

See also

Viewing the table of hosts with the Endpoint Agent component

Configuring the display of the table of hosts with the Endpoint Agent component

Viewing information about a host

Filtering and searching hosts with the Endpoint Agent component by host name

Filtering and searching hosts with the Endpoint Agent component that have been isolated from the network

Filtering and searching hosts with the Endpoint Agent component by PCN and SCN server names

Filtering and searching hosts with the Endpoint Agent component by computer IP address

Filtering and searching hosts with the Endpoint Agent component by operating system version on the computer

Filtering and searching hosts with the Endpoint Agent component by component version

Filtering and searching hosts with the Endpoint Agent component by their activity

Quickly creating a filter for hosts with the Endpoint Agent component

Resetting the filter for hosts with the Endpoint Agent component

Removing hosts with the Endpoint Agent component

Configuring activity indicators of the Endpoint Agent component

Page top
[Topic 194900_1]