Kaspersky Anti Targeted Attack Platform

Automatically adding and updating devices

The application can automatically add devices to the table and update device information. To enable automatic adding and updating of devices in Kaspersky Anti Targeted Attack Platform, you must enable and configure the Device Activity Detection (AM) technology. If the technology is enabled, the application adds and updates device information using data obtained from network traffic and the integration with the Endpoint Agent component.

When adding a device, the application sets a default device name using the following template: Device <internal device counter value>. This internal counter value in the device name may not match the device ID that is displayed in the Device ID column.

The application can automatically update vendor information of network equipment based on the MAC addresses of devices. To identify vendors by MAC addresses, the application looks up the MAC addresses of devices in the ranges of addresses registered in the open database of the Institute of Electrical and Electronics Engineers (IEEE). If the vendor of the network equipment is identified by its MAC address, the application keeps the name from the IEEE database.

After installing the application, a copy of the IEEE database is used, which contains information about MAC addresses and vendors at the time when the current version of the application was released. You can keep your local copy of the IEEE database up to date by installing updates.