Kaspersky Anti Targeted Attack Platform

Managing technologies

Kaspersky Anti Targeted Attack Platform uses various technologies to analyze network traffic. You can enable or disable the technologies individually. For the Device Activity Detection (AM) technology, you can select the mode: learning mode or monitoring mode.

We recommend enabling the learning mode for a predetermined time to have the application automatically switch the technology to monitoring mode at the right time. The monitoring mode is the normal mode of the technology (as opposed to the learning mode, in which the application only accumulates data for future use). When setting up the learning mode, you can configure the time when you want the technology to switch to monitoring mode.

You can specify the same technology settings for all components and monitoring points, or you can specify special settings for some components and/or monitoring points. Technology settings can be automatically inherited from parent objects to child objects. If technology inheritance is enabled for a component or monitoring point, the technology settings specified for the parent object (Central Node or Sensor) are applied to that object. If technology inheritance is disabled, you can configure special settings for technologies on that component or monitoring point.

By default, all technologies are enabled after application installation. Learning mode is enabled by default for technologies that support modes.

In this section

Enabling or disabling technologies

Configuring Device Activity Detection mode

Managing technology inheritance