Kaspersky Anti Targeted Attack Platform

Managing allow rules for NDR events

Kaspersky Anti Targeted Attack Platform can monitor network interactions between devices. Allow rules are used to configure authorized and unauthorized network interactions. All network interactions that matches active allow rules is treated as allowed. When allowed interactions are detected, the application does not log NDR events or generate alerts.

You can view, create, copy, modify, delete, enable or disable allow rules.

In this section

Viewing the table of allow rules

Creating an allow rule with blank settings or settings from a template

Creating an allow rule from a registered event

Copying an allow rule

Editing the settings of an allow rule

Enabling or disabling allow rules

Deleting allow rules