Kaspersky Anti Targeted Attack Platform

NDR event registration technologies

Kaspersky Anti Targeted Attack Platform registers NDR events using one of the following technologies:

  • Intrusion Detection (IDS)

    This technology registers NDR events related to the detection of anomalies in traffic that are indicators of attacks (for example, an NDR event can be registered indicators of ARP spoofing are detected).

  • External (EXT)

    This technology registers aggregate and nested NDR events that are received by the Kaspersky Anti Targeted Attack Platform from third-party systems using the methods of the Kaspersky Anti Targeted Attack Platform API.

  • Asset Management (AM)

    This technology registers NDR events involving the detection of information about devices in traffic or in data received from EPP applications (for example, an NDR event can be registered when a device is found to have a new IP address).

  • Endpoint Protection Platform (EPP)

    This technology registers NDR events for threats detected by Kaspersky applications that protect workstations and servers (for example, a malware detection event).