Kaspersky Anti Targeted Attack Platform

Configuring integration of the Endpoint Agent component with the NDR functional block

If you use the NDR functionality, you can configure the integration of Kaspersky Anti Targeted Attack Platform with the Endpoint Agent component represented by Kaspersky Endpoint Security 12.7 for Windows and Kaspersky Endpoint Security 12.2 Linux to receive the following information about the devices on which the component is installed:

  • Information about NDR events recorded in the event database as a result of the EPP technology triggering (workstation and server protection events).
  • Device information (for example, operating system version, model or vendor information).
  • Information about the connections of devices on the network interactions map.
  • Information about protocols used to establish connections between devices.

You can connect up to 1000 Endpoint Agent components to a single Central Node component. If you want to connect more components, please contact Technical Support.

To integrate with the NDR functionality, Kaspersky Endpoint Security 12.7 for Windows or Kaspersky Endpoint Security 12.2 Linux must be activated using a KESB Advanced or KESB Total license key.

Data from computers with the Endpoint Agent component is sent to Kaspersky Anti Targeted Attack Platform through integration servers. Any server with Kaspersky Anti Targeted Attack Platform component (Central Node or Sensor) installed can function as an integration server. For integration with Endpoint Agent, add integration servers to the servers that receive data from computers with Endpoint Agent.

Computers hosting Endpoint Agent establish secure connections with integration servers over the HTTPS protocol. The connections are secured by certificates issued by the Central Node server. The following certificates can be used for connections:

  • Integration server certificate. This certificate is verified by the computer with Endpoint Agent each time a connection is established. The connection is not established until the certificate is successfully verified.
  • Client certificate. This certificate is used to authenticate integration server clients that are computers with Endpoint Agent. The same client certificate can be used by multiple computers with Endpoint Agent. By default, the integration server does not verify client certificates, but you can enable verification to improve the security of connections.

Certificates and public keys are distributed to Endpoint Agent computers using Kaspersky Endpoint Security for Windows or Kaspersky Endpoint Security for Linux. To upload this data into Kaspersky Endpoint Security, you can use a communication data package, which must be created in Kaspersky Anti Targeted Attack Platform after adding the integration server.

Only users with the Administrator role can configure the receipt of data from Endpoint Agent components. Users with the Security auditor role can view the list of integration servers.

In this section

Integration servers table

Scenario for preparing to receive data from the Endpoint Agent component

Adding an integration server

Creating a communication data package for clients of an integration server

Enabling or disabling an integration server

Editing integration server settings

Removing an integration server