Kaspersky Anti Targeted Attack Platform

Kaspersky Anti Targeted Attack Platform

Kaspersky Anti Targeted Attack Platform (hereinafter also referred to as "the application") is a solution designed for the protection of a corporate IT infrastructure and timely detection of threats such as zero-day attacks, targeted attacks, and complex targeted attacks known as advanced persistent threats (hereinafter also referred to as "APT"). The solution is developed for corporate users.

The Kaspersky Anti Targeted Attack Platform solution includes three functional blocks:

  • Kaspersky Anti Targeted Attack (hereinafter also referred to as "KATA"), which provides perimeter security for the enterprise IT infrastructure.
  • Kaspersky Endpoint Detection and Response (hereinafter also referred to as "KEDR"), which provides protection for the local area network of the organization.
  • Network Detection and Response (hereinafter also referred to as "NDR"), which provides protection of the corporate LAN.

The solution can receive and process data in the following ways:

  • Integrate into the local area network, receive and process mirrored , and extract objects and metadata from the HTTP, HTTP2, FTP, SMTP, DNS, SMB, and NFS protocols.
  • Connect to the proxy server via the ICAP protocol, receive and process data of HTTP, HTTP2, and FTP traffic, as well as HTTPS traffic if the administrator has configured SSL certificate replacement on the proxy server.
  • Connect to the mail server via the POP3 (S) and SMTP protocols, receive and process copies of e-mail messages.
  • Integrate with Kaspersky Secure Mail Gateway and Kaspersky Security for Linux Mail Server, receive, and process copies of email messages.
  • Receive and process copies of network traffic obtained from a remote location using the Kaspersky SD-WAN application. This functionality improves the flexibility of detecting and monitoring network activity, allowing you to analyze traffic from different points on the network and take appropriate action to ensure network security.

    For detailed information on Kaspersky Secure Mail Gateway, Kaspersky Security for Linux Mail Server and Kaspersky SD-WAN, please refer to the documentation of these applications.

  • Integrate with Kaspersky Endpoint Agent and Kaspersky Endpoint Security and receive data (events) from individual computers running Microsoft Windows and Linux operating systems in the corporate IT infrastructure. These applications continuously monitor processes running on those computers, active network connections, and files that are modified.
  • Integrate with external systems with the use of the REST API interface and scan files on these systems.

The solution uses the following means of Threat Intelligence:

  • Infrastructure of Kaspersky Security Network (also referred to as "KSN") cloud services that provides access to the online Knowledge Base of Kaspersky, which contains information about the reputation of files, web resources, and software. The use of data from Kaspersky Security Network ensures faster responses by Kaspersky applications to threats, improves the performance of some protection components, and reduces the likelihood of false alarms.
  • Integration with Kaspersky Private Security Network (KPSN) to access the reputation databases of Kaspersky Security Network and other statistical data without sending data from user computers to Kaspersky Security Network.
  • Integration with the Kaspersky information system known as Kaspersky Threat Intelligence Portal, which contains and displays information about the reputation of files and URLs.
  • IOC (Indicators of Compromise). Kaspersky Anti Targeted Attack Platform uses IOC files conforming to the OpenIOC standard, which is an open standard for describing indicators of compromise. IOC files contain a set of indicators that are compared to the indicators of an event. If the compared indicators match, the application considers the event to be an alert.
  • IOA (Indicators of Attack). Kaspersky Anti Targeted Attack Platform scans the Events database of the application and marks events or event chains that match behaviors described by TAA (IOA) rules.

The solution can detect the following events that occur within the corporate IT infrastructure:

  • A file has been downloaded or an attempt was made to download a file to a corporate LAN computer.
  • A file has been sent to the email address of a user on the corporate LAN.
  • A website link was opened on a corporate LAN computer.
  • Network activity has occurred in which the IP address or domain name of a corporate LAN computer was detected.
  • Processes have been started on a corporate LAN computer.

The application can provide the results of its operation and Threat Intelligence to the user in the following ways:

  • Display the results of work done in the web interface of the Central Node, Primary Central Node (hereinafter also PCN) or Secondary Central Node (hereinafter also SCN) servers.
  • Publish alerts to a SIEM system already being used in your organization via the Syslog protocol.
  • Integrate with external systems via the REST API and send information on alerts generated by the solution to external systems on demand.
  • Publish information on Sandbox component alerts in the local reputation database of Kaspersky Private Security Network.

Users with the Senior security officer or Security officer role can perform the following actions in the application:

  • Monitor the components of the solution.
  • View the table of detected signs of targeted attacks and intrusions into the corporate IT infrastructure, filter and search alerts, view and manage each alert, and follow recommendations for evaluating and investigating incidents.
  • Look through the table of events occurring on computers and servers of the corporate IT infrastructure, search for threats, filter, view and manage each event, follow recommendations for evaluating and investigating incidents.
  • Run tasks on computers with Kaspersky Endpoint Agent and Kaspersky Endpoint Security: run applications and stop processes, download and delete files, quarantine objects on computers with Kaspersky Endpoint Agent and Kaspersky Endpoint Security, place copies of files in Storage of Kaspersky Anti Targeted Attack Platform, and restore files from quarantine.
  • Set up policies for preventing the running of files and processes that they consider to be unsafe on selected computers with Kaspersky Endpoint Agent and Kaspersky Endpoint Security.
  • Isolate individual computers with Kaspersky Endpoint Agent and Kaspersky Endpoint Security from the network.
  • Work with TAA (IOA) rules to classify and analyze events.
  • Manage user-defined Targeted Attack Analyzer TAA (IOA), Intrusion Detection System (IDS), and YARA rules — upload rules to be used for scanning events and creating alerts.
  • Work with OpenIOC compliant files (IOC files) to search for signs of targeted attacks, infected and probably infected objects on hosts with the Endpoint Agent component and in the Alerts database.
  • Exclude TAA (IOA) rules and IDS rules defined by Kaspersky from scanning.
  • Manage objects in quarantine and copies of objects in Storage.
  • Manage reports about application performance and alerts.
  • Configure the sending of notifications about alerts and problems encountered by the application to email addresses of users.
  • Manage the list of VIP alerts and the list of data excluded from the scan, and populate the local reputation database of KPSN.
  • Store and download copies of raw network traffic for analysis in external systems.

Users with the Security auditor role can perform the following actions in the application:

  • Monitor the components of the solution.
  • View the table of detected signs of targeted attacks and intrusions into the enterprise IT infrastructure, filter and search alerts, and view the data of each alert.
  • Look through the table of events occurring on the computers and servers of the enterprise IT infrastructure, search for threats, filter and view each event.
  • View the list of hosts with the Endpoint Agent component and information about selected hosts.
  • View user-defined rules for Targeted Attack Analyzer TAA (IOA), Intrusion Detection System (IDS), and YARA.
  • View the scan-excluded TAA (IOA) rules and IDS rules defined by Kaspersky experts.
  • View reports about application performance and alerts.
  • View the list of VIP alerts and the list of data excluded from the scan.
  • View all settings made in the application web interface.
  • Store and download copies of raw network traffic for analysis in external systems.

Users with the Local administrator or Administrator role can perform the following actions in the application:

  • Edit application settings.
  • Configure servers for the distributed solution and multitenancy mode.
  • Set up the integration of the application with other applications and systems.
  • Manage TLS certificates and set up trusted connections between the Central Node server and the Sandbox server, between Kaspersky Anti Targeted Attack Platform servers and the Endpoint Agent component, and with external systems.
  • Manage accounts of application users.
  • Monitor application health.

See also

Kaspersky Anti Targeted Attack Platform Help

Data provision

Application licensing

Architecture of the application

Operating principle of the application

Distributed solution and multitenancy

Sizing Guide

Installing and performing initial configuration of the application

Configuring the sizing settings of the application

Configuring the integration of Kaspersky Anti Targeted Attack Platform with the Kaspersky Endpoint Agent component

Getting started with the application

Managing accounts of application administrators and users

Authentication using domain accounts

Participation in Kaspersky Security Network and use of Kaspersky Private Security Network

Managing the Sandbox component through the web interface

For administrators: Getting started with the application web interface

For security officers: Getting started with the application web interface

Managing user-defined Sandbox rules

Sending notifications

Managing Kaspersky Endpoint Agent for Windows

Managing Kaspersky Endpoint Security for Windows

Managing Kaspersky Endpoint Security for Linux

Managing Kaspersky Endpoint Security for Mac

Backing up and restoring data

Upgrading Kaspersky Anti Targeted Attack Platform

Interaction with external systems via API

Sources of information about the application

Contacting the Technical Support Service

Information about third-party code

Trademark notices

In this Help section

What's new

About Kaspersky Threat Intelligence Portal

Distribution kit

Hardware and software requirements

Limitations

Page top
[Topic 246848]

What's new

Kaspersky Anti Targeted Attack Platform now has the following new features:

  1. NDR license key added. With an NDR license key added, the following functions are available:
    • Saving raw network traffic.
    • Searching raw network traffic.
  2. Now you can add a license key using an activation code.
  3. Threats can be detected in encrypted traffic without decryption using the ja3 and ja3s methods. You can upload for analyzing encrypted traffic.
  4. Simplified Chinese localization is now supported in the application web interface.
  5. Added the capability to detect threats when scanning chains of events using Kaspersky TAA (IOA) rules.
  6. In the alert card, you can now view screenshots of files being executed by the Sandbox component.

Changes in Kaspersky Endpoint Agent 3.16 for Windows:

You can view the list of changes in Kaspersky Endpoint Agent 3.16 for Windows in the Kaspersky Endpoint Agent for Windows Online Help.

Changes in Kaspersky Endpoint Security 12.5 for Windows:

You can view the list of changes in Kaspersky Endpoint Security 12.5 for Windows in the Kaspersky Endpoint Security for Windows Online Help.

Changes in Kaspersky Endpoint Security 12 for Linux:

You can view the list of changes in Kaspersky Endpoint Security 12 for Linux in the Kaspersky Endpoint Security for Linux Online Help.

See also

Kaspersky Anti Targeted Attack Platform

About Kaspersky Threat Intelligence Portal

Distribution kit

Hardware and software requirements

Limitations

Page top
[Topic 247269]

About Kaspersky Threat Intelligence Portal

For additional information about files that you consider to be suspicious, you can go to the website of the Kaspersky application Kaspersky Threat Intelligence Portal, which analyzes each file for malicious code and shows information about the reputation of the file.

Access to the Kaspersky Threat Intelligence application is provided for a fee. Authorization on the application website requires that an application access certificate is installed in the certificate storage on your computer. In addition, you must have a user name and password for access to the application.

For more details about the Kaspersky Threat Intelligence Portal, please visit the Kaspersky website.

See also

Kaspersky Anti Targeted Attack Platform

What's new

Distribution kit

Hardware and software requirements

Restrictions

Page top
[Topic 157533]

Distribution kit

The Kaspersky Anti Targeted Attack Platform distribution kit includes the following files:

  1. Disk image (file with the iso extension) containing the installation files for the Ubuntu Server 24.04.4 operating system and for the Sensor and Central Node components.
  2. Disk image (file with the iso extension) containing the installation files for the CentOS 7.9 operating system and for the Sandbox component.
  3. Archive (.tar.gz file) of the Sensor, Central Node components for creating an iso image based on Astra Linux Special Edition 1.7.5.
  4. Archive (.tar.gz file) of the Sandbox component for creating an iso image based on Astra Linux Special Edition 1.7.5.
  5. Disk images (.iso files) of operating systems in which the Sandbox component runs files.
  6. Utility (.tar file) for creating an iso image based on Astra Linux Special Edition 1.7.5.
  7. Update package for the Central Node and Sensor components based on the Ubuntu operating system.
  8. Update package for the Central Node and Sensor components based on the Astra Linux operating system.
  9. File with information about third-party code used in Kaspersky Anti Targeted Attack Platform.

Kaspersky Endpoint Agent distribution kit includes the following files:

Kaspersky Endpoint Agent distribution kit

File

Description

agent\endpointagent.msi

Kaspersky Endpoint Agent installation package.

agent\endpointagent.kud

File for creating Kaspersky Endpoint Agent installation package using Kaspersky Security Center.

agent\klcfginst.msi

Installation package for Kaspersky Endpoint Agent Management administration plug-in for Kaspersky Security Center.

agent\kpd.loc\en-us.ini

Configuration file required for creating installation package for English version of Kaspersky Endpoint Agent using Kaspersky Security Center.

agent\kpd.loc\ru-ru.ini

Configuration file required for creating installation package for Russian version of Kaspersky Endpoint Agent using Kaspersky Security Center.

agent\en-us\ksn.txt

File with the text of the terms of participation in Kaspersky Security Network in English.

agent\en-us\license.txt

File with the text of the End User License Agreement and the Privacy Policy in English.

agent\en-us\release_notes.txt

File with the text of the Release Notes for Kaspersky Endpoint Agent in English.

agent\ru-ru\ksn.txt

File with the text of the terms of participation in Kaspersky Security Network in Russian.

agent\ru-ru\license.txt

File with the text of the End User License Agreement and the Privacy Policy in Russian.

agent\ru-ru\release_notes.txt

File with the text of the Release Notes for Kaspersky Endpoint Agent in Russian.

See also

Kaspersky Anti Targeted Attack Platform

What's new

About Kaspersky Threat Intelligence Portal

Hardware and software requirements

Restrictions

Page top
[Topic 247444]

Hardware and software requirements

Software requirements for virtual platforms for installing Kaspersky Anti Targeted Attack Platform

You can deploy the application on the following virtual platforms:

  • VMware ESXi 6.7.0 or 7.0
  • Brest 3.3 virtualization software
  • RED Virtualization 7.3
  • zVirt Node 4.2

Software requirements

When deploying the application on a VMware ESXI virtual platform, you must install the current update package for the hypervisor.

If you want to deploy the application on the Astra Linux operating system in a VMware ESXI hypervisor, you need to ensure that the server hardware you are using is compatible with the Astra Linux operating system. For a full list of supported server hardware, please refer to the Astra Linux developer website.

When deploying the application on the Brest, zVirt Node, and RED Virtualization virtual platforms, the following limitations apply:

  • If you want to use the Sandbox component on the Brest virtual platform, you must additionally configure the time for scanning objects using the component to increase the probability of detection.
  • High availability deployment of the application is not supported on zVirt Node and RED Virtualization virtual platforms.
  • Installation of the Sandbox component is not supported on zVirt Node and RED Virtualization virtual platforms.

For the Central Node, Sensor and Sandbox hardware requirements see the Sizing Guide.

Hardware and software requirements for installing the Endpoint Agent component

The hardware and software requirements of the Endpoint Agent component reflect the hardware and software requirements of the applications that act as the Endpoint Agent component, and are described in the documentation of these applications:

Hardware and software requirements for using the web interface of Kaspersky Anti Targeted Attack Platform

One of the following browsers must be installed on the computers in order to configure and manage the application using the web interface:

  • Mozilla Firefox for Linux.
  • Mozilla Firefox for Windows.
  • Google Chrome for Windows.
  • Google Chrome for Linux.
  • Edge (Windows).
  • Safari (Mac).

Minimum screen resolution to use web interface: 1366х768.

See also

What's new

About Kaspersky Threat Intelligence Portal

Distribution kit

Limitations

In this section

Compatibility of Kaspersky Endpoint Agent for Windows versions with Kaspersky Anti Targeted Attack Platform versions

Compatibility of Kaspersky Endpoint Agent for Windows versions with EPP applications

Compatibility of Kaspersky Endpoint Security for Windows versions with Kaspersky Anti Targeted Attack Platform versions

Compatibility of Kaspersky Endpoint Security for Linux versions with Kaspersky Anti Targeted Attack Platform versions

Compatibility of Kaspersky Endpoint Security for Mac with Kaspersky Anti Targeted Attack Platform versions

Compatibility of KUMA versions with versions of Kaspersky Anti Targeted Attack Platform

Compatibility of XDR versions with versions of Kaspersky Anti Targeted Attack Platform

Compatibility of KPSN versions with versions of Kaspersky Anti Targeted Attack Platform

Compatibility of Kaspersky Anti Targeted Attack Platform with VK Cloud

Page top
[Topic 247120]

Compatibility of Kaspersky Endpoint Agent for Windows versions with Kaspersky Anti Targeted Attack Platform versions

The Kaspersky Endpoint Agent application uses predefined settings that determine the impact that it has on the performance of the local computer under scenarios of information retrieval and interaction with the Central Node component.

If the version of Kaspersky Anti Targeted Attack Platform installed on Central Node servers is incompatible with the version of Kaspersky Endpoint Agent installed on computers on the corporate LAN, the functionality of Kaspersky Anti Targeted Attack Platform may be limited.

Information about the compatibility of Kaspersky Endpoint Agent component versions with Kaspersky Anti Targeted Attack Platform versions is listed in the table below.

Compatibility of Kaspersky Endpoint Agent for Windows versions with Kaspersky Anti Targeted Attack Platform versions

Version of
Kaspersky
Endpoint
Agent

Type
Kaspersky
Endpoint
Agent

Compatibility
with KATA 4.0

Compatibility
with KATA 4.1

Compatibility
with KATA 5.0

Compatibility
with KATA 5.1

Compatibility
with KATA 6.0

Compatibility
with KATA 6.1

Endpoint Agent
3.12

Standalone installation

Yes

There are limitations

There are limitations

There are limitations

There are limitations

There are limitations

Endpoint Agent
3.13

Standalone installation

There are limitations

Yes

There are limitations

There are limitations

There are limitations

There are limitations

Endpoint Agent
3.14

Standalone installation

There are limitations

There are limitations

Yes

Yes

Yes

There are limitations

Endpoint Agent
3.15

Standalone installation

No

No

Yes

Yes

Yes

There are limitations

Endpoint Agent
3.16

Standalone installation

No

No

No

No

Yes

Yes

Endpoint Agent
4.0

Standalone installation

No

No

No

No

No

Yes

Limited compatibility of Kaspersky Endpoint Agent for Windows versions with Kaspersky Anti Targeted Attack Platform versions

  • Integration of Kaspersky Endpoint Agent 3.12 with Kaspersky Anti Targeted Attack Platform 4.1.

    The amount of data sent by Kaspersky Endpoint Agent is limited:

    • Scanning autorun points using the Start YARA scan task is not supported.
    • The tasks Get NTFS metafiles, Get process memory dump, Get registry key are not supported.
  • Integration of Kaspersky Endpoint Agent 3.12 with Kaspersky Anti Targeted Attack Platform 5.0–6.1.

    The amount of data sent by Kaspersky Endpoint Agent is limited:

    • Scanning autorun points using the Start YARA scan task is not supported.
    • The tasks Get NTFS metafiles, Get process memory dump, Get registry key, Get disk image, Get memory dump are not supported.
    • Event information is not transmitted for the Process terminated event.
  • Integration of Kaspersky Endpoint Agent 3.13 with Kaspersky Anti Targeted Attack Platform 4.0.

    A server of this Kaspersky Anti Targeted Attack Platform version can receive a limited scope of data from the Kaspersky Endpoint Agent application: Get NTFS metafiles, Get process memory dump, Get registry key tasks cannot be created in the web interface of the application.

  • Integration of Kaspersky Endpoint Agent 3.13 with Kaspersky Anti Targeted Attack Platform 4.1–6.1.

    Kaspersky Endpoint Agent does not support the creation of the following tasks: Get disk image, Get memory dump.

  • Integration of Kaspersky Endpoint Agent 3.14 with Kaspersky Anti Targeted Attack Platform 4.0.

    The server of this Kaspersky Anti Targeted Attack Platform version can receive a limited scope of data from the Kaspersky Endpoint Agent application: creation of Get NTFS metafiles, Get process memory dump, Get registry key, Get disk image, Get memory dump tasks is not available in the web interface of the application.

  • Integration of Kaspersky Endpoint Agent 3.14 with Kaspersky Anti Targeted Attack Platform 4.1.

    A server of this Kaspersky Anti Targeted Attack Platform version can receive a limited scope of data from the Kaspersky Endpoint Agent application: the tasks Get disk image and Get memory dump cannot be created in the web interface of the application.

Page top
[Topic 247280]

Compatibility of Kaspersky Endpoint Agent for Windows versions with EPP applications

If you want to use the Kaspersky Endpoint Agent application as the Endpoint Agent component, you can install just the Kaspersky Endpoint Agent, or configure the integration of Kaspersky Endpoint Agent with workstation protection applications (Endpoint Protection Platform, hereinafter also "EPP"), Kaspersky Endpoint Security for Windows, Kaspersky Security for Windows Server, and Kaspersky Security for Virtualization Light Agent. If the integration of applications is configured, Kaspersky Endpoint Agent also sends the information about threats detected by EPP applications and their processing results to the Central Node server.

The integration scenarios described above do not work when Kaspersky Endpoint Agent is installed on a virtual desktop in Virtual Desktop Infrastructure.

Integration of Kaspersky Endpoint Agent with Kaspersky Endpoint Security for Windows and Kaspersky Security for Windows Server requires installing Kaspersky Endpoint Agent as part of those applications.

Compatibility of Kaspersky Endpoint Agent for Windows with versions of Kaspersky Security for Windows Server

You can install the following versions of Kaspersky Endpoint Agent as part of Kaspersky Security for Windows Server:

  • Kaspersky Endpoint Agent 3.9 as part of Kaspersky Security 11 for Windows Server.
  • Kaspersky Endpoint Agent 3.10 as part of Kaspersky Security 11.0.1 for Windows Server.

When you install Kaspersky Endpoint Agent as part of Kaspersky Security for Windows Server, the standalone Kaspersky Endpoint Agent of the same or earlier version is removed. If Kaspersky Endpoint Agent installed as part of Kaspersky Security for Windows Server has an earlier version, it will not be installed. In this case, you must first remove the standalone Kaspersky Endpoint Agent application.

If necessary, you can upgrade the Kaspersky Endpoint Agent application that is already installed as part of Kaspersky Security for Windows Server. Integration between compatible versions of the applications is maintained both when Kaspersky Endpoint Agent is upgraded and when Kaspersky Security for Windows Server is upgraded.

Information about the compatibility of Kaspersky Endpoint Agent versions with Kaspersky Security for Windows Server versions is listed in the table below.

Compatibility of Kaspersky Endpoint Agent versions with Kaspersky Security for Windows Server versions

Kaspersky Security for Windows Server version

Compatibility with Endpoint Agent 3.8, 3.9, 3.10

Compatibility with Endpoint Agent 3.11, 3.12

Compatibility with Endpoint Agent 3.13, 3.14, 3.15, 3.16

  • KSWS 10.1.2

Yes

No

No

  • KSWS 11

Yes

Yes

No

  • KSWS 11.0.1

No

Yes

There are limitations

When integrating with Kaspersky Endpoint Agent 3.13–3.16, Kaspersky Security for Windows Server does not transmit event information of the AMSI scan event.

For more details about installing Kaspersky Security for Windows Server, see Kaspersky Security for Windows Server Help.

Compatibility of Kaspersky Endpoint Agent for Windows with versions of Kaspersky Endpoint Security for Windows

You can install the following versions of Kaspersky Endpoint Agent (Endpoint Sensors) as part of Kaspersky Endpoint Security for Windows:

  • Kaspersky Endpoint Agent 3.7 or Kaspersky Endpoint Agent (Endpoint Sensors) 3.6.1 as part of Kaspersky Endpoint Security 11.2, 11.3 for Windows.

    Kaspersky Endpoint Agent (Endpoint Sensors) 3.6.1 is not compatible with Kaspersky Anti Targeted Attack Platform version 4.1 or higher.

    Kaspersky Endpoint Agent 3.7 is not compatible with all versions of Kaspersky Anti Targeted Attack Platform.

  • Kaspersky Endpoint Agent 3.9 as part of Kaspersky Endpoint Security 11.4, 11.5.
  • Kaspersky Endpoint Agent 3.10 as part of Kaspersky Endpoint Security 11.6.
  • Kaspersky Endpoint Agent 3.11 as part of Kaspersky Endpoint Security 11.7, 11.8.

When you install Kaspersky Endpoint Agent 3.10 or later as part of Kaspersky Endpoint Security for Windows, the standalone Kaspersky Endpoint Agent application of the same or earlier version is removed. If the separately installed Kaspersky Endpoint Agent has a later version, the application bundled with Kaspersky Endpoint Security for Windows is not installed. In this case, you must first remove the standalone Kaspersky Endpoint Agent application.

If necessary, you can upgrade the Kaspersky Endpoint Agent application that is already installed as part of Kaspersky Endpoint Security for Windows. Integration between compatible versions of the applications is maintained both when Kaspersky Endpoint Agent is upgraded and when Kaspersky Endpoint Security for Windows is upgraded. You can upgrade a previous version of Kaspersky Endpoint Agent to version 3.14 only for Kaspersky Endpoint Agent version 3.7 or higher.

Information about the compatibility of Kaspersky Endpoint Agent versions with Kaspersky Endpoint Security for Windows versions is listed in the table below.

Compatibility of Kaspersky Endpoint Agent versions with Kaspersky Endpoint Security for Windows versions

Kaspersky Endpoint Security version

Compatibility with Endpoint Agent 3.8, 3.9

Compatibility with Endpoint Agent 3.10, 3.12

Compatibility with Endpoint Agent 3.11

Compatibility with Endpoint Agent 3.13, 3.14, 3.15, 3.16

  • KES 10 SP2 MR2

No

No

No

No

  • KES 10 SP2 MR3/MR4

Yes

No

No

No

  • KES 11.0.0

No

No

No

No

  • KES 11.0.1

Yes

No

No

No

  • KES 11.1
  • KES 11.1.1

Yes

Yes

No

No

  • KES 11.2
  • KES 11.3

Yes

Yes

Yes

No

  • KES 11.4
  • KES 11.5

Yes

Yes

Yes

No

  • KES 11.6
  • KES 11.7
  • KES 11.8

Yes

Yes

Yes

Yes

  • KES version 12.1 or later

No

No

No

No

For more details about installing Kaspersky Endpoint Security, see Kaspersky Endpoint Security for Windows Help.

Compatibility of Kaspersky Endpoint Agent with versions of Kaspersky Security for Virtualization Light Agent

You can configure the integration of separately installed Kaspersky Endpoint Agent and Kaspersky Security for Virtualization Light Agent.

Information about the compatibility of Kaspersky Endpoint Agent versions with Kaspersky Security for Virtualization Light Agent versions is listed in the table below.

Compatibility of Kaspersky Endpoint Agent versions and Kaspersky Security for Virtualization Light Agent versions

Kaspersky Security for Virtualization Light Agent version

Compatibility with Endpoint Agent 3.8, 3.9, 3.10

Compatibility with Endpoint Agent 3.12

Compatibility with Endpoint Agent 3.11, 3.13, 3.14

Compatibility with Endpoint Agent 3.15

Compatibility with Endpoint Agent 3.16

  • KSV 5.1 LA

Yes

Yes

No

No

No

  • KSV 5.1.1 LA

Yes

No

No

No

No

  • KSV 5.2 LA

No

Yes

Yes

Yes

Yes

  • KSV 6.0 LA

No

Yes

Yes

Yes

No

Kaspersky Endpoint Agent and Kaspersky Security for Virtualization Light Agent installed on a virtual machine generate the same load on the Central Node server as Kaspersky Endpoint Agent and Kaspersky Security for Virtualization Light Agent installed on the host.

For more details about enabling the integration of Kaspersky Endpoint Agent with Kaspersky Security for Virtualization Light Agent, see Kaspersky Security for Virtualization Light Agent Help.

Compatibility of Kaspersky Endpoint Agent with versions of Kaspersky Industrial CyberSecurity for Nodes

You can install Kaspersky Endpoint Agent on a device with Kaspersky Industrial CyberSecurity for Nodes installed. The applications are integrated automatically.

Compatibility of Kaspersky Endpoint Agent versions with versions of Kaspersky Industrial CyberSecurity for Nodes

Kaspersky Industrial CyberSecurity for Nodes version

Compatibility with Endpoint Agent 3.11, 3.12

Compatibility with Endpoint Agent 3.13, 3.14, 3.15

Compatibility with Endpoint Agent 3.16

  • KICS for Nodes 3.0

Yes

Yes

Yes

  • KICS for Nodes 3.1

No

Yes

Yes

  • KICS for Nodes 3.2

No

No

Yes

To integrate with Kaspersky Industrial CyberSecurity for Nodes, the corresponding license key must be installed in the Kaspersky Endpoint Agent.

For detailed information, you can contact your account manager.

Page top
[Topic 247216]

Compatibility of Kaspersky Endpoint Security for Windows versions with Kaspersky Anti Targeted Attack Platform versions

You can use Kaspersky Endpoint Security as the Endpoint Agent component.

Information about the compatibility of Kaspersky Endpoint Security versions with Kaspersky Anti Targeted Attack Platform versions is listed in the table below.

Compatibility of Kaspersky Endpoint Security for Windows versions with Kaspersky Anti Targeted Attack Platform versions

Kaspersky Endpoint Security
version

Compatibility
with KATA 4.0

Compatibility
with KATA 4.1

Compatibility
with KATA 5.0

Compatibility
with KATA 5.1

Compatibility
with KATA 6.0

Compatibility
with KATA 6.1

Kaspersky Endpoint Security
12.1, 12.2

No

Yes

Yes

Yes

Yes

No

Kaspersky Endpoint Security
12.3, 12.4

No

Yes

Yes

Yes

Yes

Yes

Kaspersky Endpoint Security
12.5, 12.6

No

No

Yes

Yes

Yes

Yes

Kaspersky Endpoint Security
12.7, 12.8

No

No

There are limitations

There are limitations

There are limitations

There are limitations

To integrate Kaspersky Endpoint Security 12.1 or later with Kaspersky Anti Targeted Attack Platform, you do not need to install Kaspersky Endpoint Agent.

When integrating Kaspersky Endpoint Security 12.7, 12.8 with Kaspersky Anti Targeted Attack Platform 5.0-6.1, the Kaspersky Anti Targeted Attack Platform server receives a limited amount of data from Kaspersky Endpoint Security:

  • Information about the following events is not processed: Named pipe, WMI, LDAP, DNS, Code injection.
  • For the File modified event, information about the following subtypes is not processed: File read, Hard link created, Symbolic link created.
  • For the Registry modified event, information about the following subtypes is not processed: Registry key renamed, Registry key saved.
Page top
[Topic 246849]

Compatibility of Kaspersky Endpoint Security for Linux versions with Kaspersky Anti Targeted Attack Platform versions

You can use Kaspersky Endpoint Security as the Endpoint Agent component.

Information about the compatibility of Kaspersky Endpoint Security versions with Kaspersky Anti Targeted Attack Platform versions is listed in the table below.

Compatibility of Kaspersky Endpoint Security for Linux versions with Kaspersky Anti Targeted Attack Platform versions

Kaspersky Endpoint Security
version

Compatibility
with KATA 4.0

Compatibility
with KATA 4.1

Compatibility
with KATA 5.0

Compatibility
with KATA 5.1

Compatibility
with KATA 6.0

Compatibility
with KATA 6.1

Kaspersky Endpoint Security
11.4

No

No

No

There are limitations

There are limitations

There are limitations

Kaspersky Endpoint Security
12

No

No

There are limitations

There are limitations

There are limitations

There are limitations

Kaspersky Endpoint Security
12.1

No

No

No

There are limitations

There are limitations

There are limitations

Kaspersky Endpoint Security
12.2

No

No

No

No

There is a limitation

There are limitations

To integrate Kaspersky Endpoint Security with Kaspersky Anti Targeted Attack Platform, you do not need to install the Kaspersky Endpoint Agent.

Starting from version 12, Kaspersky Endpoint Security for Linux can be used as the Light Agent for Linux component for the Kaspersky Security for Virtualization application. For more details about the integration, see Kaspersky Security for Virtualization Light Agent Help.

When Kaspersky Endpoint Security for Linux is used as the Light Agent for Linux component, the integration of Kaspersky Endpoint Security for Linux with Kaspersky Anti Targeted Attack Platform is retained.

Limited compatibility of Kaspersky Endpoint Security for Linux versions with Kaspersky Anti Targeted Attack Platform versions

  • Integration of Kaspersky Endpoint Security 11.4 with Kaspersky Anti Targeted Attack Platform 5.1–6.1.

    The scope of data sent by Kaspersky Endpoint Security is limited:

    • Creation of network isolation rules is not supported.
    • Creation of prevention rules is not supported.
    • Searching for indicators of compromise on computers using IOC files is not supported.
    • Event information is not transmitted for the following events: Process terminated, Module loaded, Connection to remote host, Blocked application (prevention rule), Document blocked, Registry modified, Port listened, Driver loaded, Process: interpreted file run, Process: console interactive input, AMSI scan.
    • Creation of the following tasks is not supported: Get forensics, Get registry key, Get NTFS metafiles, Get process memory dump, Get disk image, Get memory dump, Kill process, Start YARA scan, Service management, Delete file, Quarantine file, Restore file from quarantine, Delete file, Kill process.
  • Integration of Kaspersky Endpoint Security 12 with Kaspersky Anti Targeted Attack Platform 5.0, 5.1.

    The scope of data sent by Kaspersky Endpoint Security is limited:

    • Creation of network isolation rules is not supported.
    • Creation of prevention rules is not supported.
    • Searching for indicators of compromise on computers using IOC files is not supported.
    • Event information is not transmitted for the following events: Process terminated, Module loaded, Connection to remote host, Blocked application (prevention rule), Document blocked, Registry modified, Port listened, Driver loaded, Process: interpreted file run, Process: console interactive input, AMSI scan.
    • Creation of the following tasks is not supported: Get forensics, Get registry key, Get NTFS metafiles, Get process memory dump, Get disk image, Get memory dump, Kill process, Start YARA scan, Service management, Delete file, Quarantine file, Restore file from quarantine, Delete file, Kill process.
  • Integration of Kaspersky Endpoint Security 12–12.1 with Kaspersky Anti Targeted Attack Platform 6.0–6.1.

    The scope of data sent by Kaspersky Endpoint Security is limited:

    • Creation of prevention rules is not supported.
    • Event information is not transmitted for the following events: Process terminated, Module loaded, Connection to remote host, Blocked application (prevention rule), Document blocked, Registry modified, Port listened, Driver loaded, Process: interpreted file run, Process: console interactive input, AMSI scan.
    • Creation of the following tasks is not supported: Get forensics, Get registry key, Get NTFS metafiles, Get process memory dump, Get disk image, Get memory dump, Kill process, Start YARA scan, Service management, Quarantine file, Restore file from quarantine.
  • Integration of Kaspersky Endpoint Security 12.1 with Kaspersky Anti Targeted Attack Platform 5.1.

    The scope of data sent by Kaspersky Endpoint Security is limited:

    • Creation of prevention rules is not supported.
    • Event information is not transmitted for the following events: Process terminated, Module loaded, Connection to remote host, Blocked application (prevention rule), Document blocked, Registry modified, Port listened, Driver loaded, Process: interpreted file run, Process: console interactive input, AMSI scan.
    • Creation of the following tasks is not supported: Get forensics, Get registry key, Get NTFS metafiles, Get process memory dump, Get disk image, Get memory dump, Kill process, Start YARA scan, Service management, Quarantine file, Restore file from quarantine.
  • Integration of Kaspersky Endpoint Security 12.2 with Kaspersky Anti Targeted Attack Platform 6.0, 6.1.

    The scope of data sent by Kaspersky Endpoint Security is limited:

    • Event information is not transmitted for the following events: Process terminated, Module loaded, Connection to remote host, Blocked application (prevention rule), Document blocked, Registry modified, Port listened, Driver loaded, Process: interpreted file run, Process: console interactive input, AMSI scan.
    • Creation of the following tasks is not supported: Get forensics, Get registry key, Get NTFS metafiles, Get process memory dump, Get disk image, Get memory dump, Kill process, Start YARA scan, Service management, Restore file from quarantine.
Page top
[Topic 247128]

Compatibility of Kaspersky Endpoint Security for Mac with Kaspersky Anti Targeted Attack Platform versions

You can use Kaspersky Endpoint Security for Mac as the Endpoint Agent component.

Information about the compatibility of Kaspersky Endpoint Security for Mac versions with Kaspersky Anti Targeted Attack Platform versions is listed in the table below.

Compatibility of Kaspersky Endpoint Security for Mac with Kaspersky Anti Targeted Attack Platform versions

Kaspersky Endpoint Security
version

Compatibility
with KATA 4.0

Compatibility
with KATA 4.1

Compatibility
with KATA 5.0

Compatibility
with KATA 5.1

Compatibility
with KATA 6.0

Compatibility
with KATA 6.1

Kaspersky Endpoint Security
12

No

No

No

No

There are limitations

There are limitations

Kaspersky Endpoint Security
12.1

No

No

No

No

There are limitations

There are limitations

Limited compatibility of Kaspersky Endpoint Security for Mac versions with Kaspersky Anti Targeted Attack Platform versions

  • Integration of Kaspersky Endpoint Security 12, 12.1 with Kaspersky Anti Targeted Attack Platform 6.0–6.1.
    • Creation of network isolation rules is not supported.
    • Creation of prevention rules is not supported.
    • Searching for indicators of compromise on computers using IOC files is not supported.
    • Event information is not transmitted for the following events: Process terminated, Module loaded, Connection to remote host, Blocked application (prevention rule), Document blocked, Registry modified, Port listened, Driver loaded, Process: interpreted file run, Process: console interactive input, AMSI scan.
    • Creation of the following tasks is not supported: Kill process, Get forensics, Start YARA scan, Delete file, Quarantine file, Restore file from quarantine, Service management, Get disk image, Get memory dump.

For detailed information about the limitations involved in the integration of Kaspersky Endpoint Security with Kaspersky Anti Targeted Attack Platform 7.0, see the Kaspersky Anti Targeted Attack Platform Help of the relevant version.

Page top
[Topic 252759]

Compatibility of KUMA versions with versions of Kaspersky Anti Targeted Attack Platform

You can use KUMA as a SIEM system.

Information about the compatibility of KUMA versions with Kaspersky Anti Targeted Attack Platform versions is listed in the table below.

Compatibility of KUMA versions with versions of Kaspersky Anti Targeted Attack Platform

KUMA
version

Compatibility
with KATA 4.1

Compatibility
with KATA 5.0

Compatibility
with KATA 5.1

Compatibility
with KATA 6.0

Compatibility
with КАТА 6.1

KUMA 2.0

Yes

Yes

No

No

No

KUMA 2.1

No

Yes

Yes

Yes

No

KUMA 3.0.2

No

No

No

Yes

Yes

KUMA 3.0.3

No

No

No

Yes

Yes

KUMA 3.2

No

No

No

Yes

Yes

Page top

[Topic 264169]

Compatibility of XDR versions with versions of Kaspersky Anti Targeted Attack Platform

You can use XDR as a SIEM system.

Information about the compatibility of XDR versions with Kaspersky Anti Targeted Attack Platform versions is listed in the table below.

Compatibility of XDR versions with versions of Kaspersky Anti Targeted Attack Platform

XDR
version

Compatibility
with KATA 4.1

Compatibility
with KATA 5.0

Compatibility
with KATA 5.1

Compatibility
with KATA 6.0

Compatibility
with КАТА 6.1

XDR
1.0

No

No

Yes

No

No

XDR
1.1

No

No

No

Yes

Yes

Page top

[Topic 264174]

Compatibility of KPSN versions with versions of Kaspersky Anti Targeted Attack Platform

You can use Kaspersky Private Security Network (KPSN) instead of Kaspersky Security Network (KSN) to avoid sending your organization's data beyond the corporate LAN.

Information about the compatibility of KPSN versions with Kaspersky Anti Targeted Attack Platform versions is listed in the table below.

Compatibility of KPSN versions with versions of Kaspersky Anti Targeted Attack Platform

KPSN
version

Compatibility
with KATA 4.1

Compatibility
with KATA 5.0

Compatibility
with KATA 5.1

Compatibility
with KATA 6.0

Compatibility
with KATA 6.1

KPSN
3.3

Yes

Yes

Yes

Yes

Yes

KPSN
3.4

No

No

No

Yes

Yes

KPSN
4.0

No

No

No

No

Yes

Page top

[Topic 264175]

Compatibility of Kaspersky Anti Targeted Attack Platform with VK Cloud

Kaspersky Anti Targeted Attack Platform supports deployment on the VK Cloud platform.

When deploying the application, you can connect Sandbox components to the Central Node component.

The following restrictions apply when deploying Kaspersky Anti Targeted Attack Platform for integration with VK Cloud:

  • Only the KATA functional block is supported.
  • Only the certified version of the application based on Astra Linux is supported.
  • Only the non-high-availability version of the application is supported.
  • You can configure integration only with an external KSMG system. For more details on integration, see KSMG Help.
  • You can use the distributed solution mode only if you are using the KSMG integration.

For the Sandbox component to work, the following requirements must be met:

  • Nested virtualization must be enabled for the virtual machine.
  • The network interface settings must be correctly configured to provide Internet access to objects being processed.

    Windows images can only be activated if the network interface is configured correctly.

  • The network interface used for Internet access of processed objects must be isolated from the local network of your organization.
  • The network interface used by processed objects for Internet access must be connected to a subnet that is not the same as the subnet to which the control interface is connected.
  • We do not recommend using a static public IP address for the network interface that handles Internet access of the objects being processed.
Page top
[Topic 264697]

Restrictions

Limitations that apply when deploying the Central Node component as a cluster:

  1. A Central Node cluster must include at least 4 servers: 2 storage servers and 2 processing servers. You can scale the cluster to increase the amount of traffic handled or the number of connected hosts in accordance with the Sizing Guide.
  2. It is recommended to add servers with the same hardware configuration to the cluster. Otherwise, a proportional increase in performance is not guaranteed.
  3. Adding an extra server to the cluster does not speed up the processing of objects that are already in the scan queue.
  4. The web interface of the application can be temporarily unavailable if the server on which it is hosted fails.
  5. If the processing server fails, you may lose ICAP, POP3, and SMTP traffic data as well as the copies of emails that are waiting to be processed and the detections associated with them.
  6. If the processing server is configured to receive mirrored traffic from SPAN ports, then SPAN traffic is not processed if this server fails.
  7. If one of the cluster servers fails or the connection between the server and the Endpoint Agent component is temporarily lost, data in the event database can temporarily become desynchronized.
  8. If the configuration of the cluster servers is changed, processing of traffic and events from computers with the Endpoint Agent component may be temporarily slowed down.

Limitations that apply to the Sensor component:

  1. Only Sensor components installed on standalone servers can be used to capture network traffic at the maximum speed of 10 Gbps.
  2. Capturing FTP traffic at the maximum speed of 10 Gbps can result in a high level of loss.
  3. If you add or remove network interfaces that send SPAN traffic to Kaspersky Anti Targeted Attack Platform, raw network traffic dumps may be downloaded from a network interface that is different from the one you selected.

Limitations that apply to the Sandbox component:

  1. The following versions of operating systems are supported for custom images:
    • Windows 7
    • Windows 8.1 64-bit
    • Windows 10 64-bit (up to version 1909)
  2. Only English and Russian localizations are fully supported for custom operating system images.
  3. License keys for activating the operating systems and software are not provided.
  4. If some of the operating systems selected in the set of operating systems on the Central Node server are not installed on the Sandbox server, Kaspersky Anti Targeted Attack Platform does not send objects to the Sandbox component for scanning. If multiple servers with the Sandbox component are connected to the server with the Central Node component, the application sends objects to those servers whose installed operating systems match the set selected on the Central Node.

Limitations that apply when integrating with Kaspersky Endpoint Agent for Windows and Kaspersky Endpoint Security for Windows:

  1. Tasks for getting RAM dumps and disk images can only be assigned to computers with Kaspersky Endpoint Agent 3.14 or later for Windows and Kaspersky Endpoint Security 12.1 or later for Windows.
  2. Tasks for getting process memory dumps, NTFS metafiles, and registry keys can only be assigned to computers with Kaspersky Endpoint Agent 3.14 or later for Windows or Kaspersky Endpoint Security 12.1 or later for Windows.
  3. The task of scanning hosts using YARA rules can only be assigned to computers with Kaspersky Endpoint Agent 3.14 or later for Windows and Kaspersky Endpoint Security 12.1 or later for Windows. If you simultaneously assign a task to computers with Kaspersky Endpoint Agent version 3.14 or later, and to computers with earlier versions of that application, the task runs only on computers with Kaspersky Endpoint Agent 3.14 or later.
  4. If autorun points are selected as the scan scope, the task runs only on computers with Kaspersky Endpoint Agent 3.14 or later and Kaspersky Endpoint Security 12.1 or later for Windows.

Limitations that apply when integrating with Kaspersky Endpoint Security for Linux:

  1. The following functionality is not available for computers running Kaspersky Endpoint Security for Linux 11.4:
    • Network isolation of a host.
    • Creating a prevention rule.

      No notifications are created about the unsuccessful application of a prevention rule on computers with Kaspersky Endpoint Security 11.4 for Linux applications.

    • Finding indicators of compromise on computers using IOC files.

      No notifications are created about the unsuccessful search of indicators of compromise on computers with Kaspersky Endpoint Security 11.4 for Linux applications.

  2. The following functionality is not available for computers running Kaspersky Endpoint Security for Linux 12:
    • Creating a prevention rule.

      No notifications are created about the unsuccessful application of a prevention rule on computers with Kaspersky Endpoint Security 12 for Linux applications.

  3. The list of events that Kaspersky Endpoint Security 11.4 or 12 for Linux logs in the event database is limited to the following types:
  4. The list of tasks that you can create on computers running Kaspersky Endpoint Security 11.4 for Linux is limited to the following types:
    • Get file

      When you create the task, the application does not attempt to verify the path to the executable file or the file that you want to retrieve.

    • Run application
  5. The list of tasks that you can create on computers running Kaspersky Endpoint Security 12 for Linux is limited to the following types:
  6. In information about events registered in the event database by Kaspersky Endpoint Security 11.4 or 12 for Linux, the Time created field displays file modification time.

Limitations that apply when integrating with Kaspersky Endpoint Security 12 for Mac:

  1. The following functionality is not available for computers running Kaspersky Endpoint Security 12 for Mac:
    • Network isolation of a host.
    • Creating a prevention rule.

      No notifications are created about the unsuccessful application of a prevention rule on computers with Kaspersky Endpoint Security 12 for Mac applications.

    • Finding indicators of compromise on computers using IOC files.

      No notifications are created about the unsuccessful search of indicators of compromise on computers with Kaspersky Endpoint Security 12 for Mac applications.

  2. The list of events that Kaspersky Endpoint Security 12 for Mac logs in the event database is limited to the following types:
  3. The list of tasks that you can create on computers running Kaspersky Endpoint Security 12 for Mac is limited to the following types:
    • Get file

      When you create the task, the application does not attempt to verify the path to the executable file or the file that you want to retrieve.

    • Run application
  4. In information about events registered in the event database by Kaspersky Endpoint Security 12 for Mac, the Time created field displays file modification time.

Limitations of Kaspersky Endpoint Agent 3.16 for Windows:

You can view the list of limitations of Kaspersky Endpoint Agent 3.16 for Windows in the Kaspersky Endpoint Agent for Windows Online Help.

Limitations of Kaspersky Endpoint Security 12.5 for Windows:

You can view the list of limitations of Kaspersky Endpoint Security 12.5 for Windows in the Kaspersky Endpoint Security for Windows Online Help.

Limitations of Kaspersky Endpoint Security 12 for Linux:

You can view the list of limitations of Kaspersky Endpoint Security 12 for Linux in the Kaspersky Endpoint Security for Linux Release Notes.

Limitations of Kaspersky Endpoint Security 12 for Mac:

You can view the list of limitations of Kaspersky Endpoint Security 12 for Mac in the Kaspersky Endpoint Security for Mac Online Help.

See also

Kaspersky Anti Targeted Attack Platform

What's new

About Kaspersky Threat Intelligence Portal

Distribution kit

Hardware and software requirements

Page top
[Topic 247274]