Kaspersky Anti Targeted Attack Platform

NDR event statuses

NDR event statuses allow the application to display the course of processing the received information by security officers.

The following statuses can be assigned to NDR events and aggregate events:

  • New.

    This status is assigned to all NDR and aggregate events when they are registered in Kaspersky Anti Targeted Attack Platform.

  • In process.

    You can assign this status to NDR events and aggregate events that are being processed (for example, during the investigation of the reasons why these events or incidents were registered).

  • Resolved.

    You can assign this status to NDR events and aggregate events that already have been processed (for example, the investigation of the reasons of their registration is closed).

    After the Resolved status is assigned, the application ignores NDR events and aggregate events with this status when determining the security status of devices displayed in the table of device and on the network interactions map.

Statuses of NDR events and aggregate events must be changed manually. You can assign statuses sequentially in the order from New to Resolved. However, you can skip the In process status. After changing the status of an NDR event or aggregate event, you cannot re-assign one of the previous statuses.

If the Resolved status is assigned to an aggregate event, the status of all nested NDR events is automatically changed to Resolved, and the associated alerts are also closed.

If the Resolved status is assigned to an NDR event, aggregate events under which this NDR event is nested and the associated alerts are not closed.