Kaspersky Anti Targeted Attack Platform

Managing user-defined Sandbox rules

Users with the Senior security officer and Administrator roles can create rules for scanning files and URLs in their user environments. If no rules are added, objects are not sent for scanning.

You can create, edit, delete, enable, or disable rules. File scanning rules can also be imported and exported.

To send objects for scanning in preset images, you do not need to create rules. By default, Kaspersky Anti Targeted Attack Platform sends objects that need to be scanned for scanning.

In distributed solution mode, you must create rules for scanning files in custom environments on each PCN and SCN server from which you want to send files for scanning.

Users with the Security auditor role can view the list of rules. Users with the Security officer role cannot view this section.