Kaspersky Anti Targeted Attack Platform

Compatibility of Kaspersky Endpoint Security for Linux versions with Kaspersky Anti Targeted Attack Platform versions

You can use Kaspersky Endpoint Security as the Endpoint Agent component.

Information about the compatibility of Kaspersky Endpoint Security versions with Kaspersky Anti Targeted Attack Platform versions is listed in the table below.

Compatibility of Kaspersky Endpoint Security for Linux versions with Kaspersky Anti Targeted Attack Platform versions

Kaspersky Endpoint Security
version

Compatibility
with KATA 4.0

Compatibility
with KATA 4.1

Compatibility
with KATA 5.0

Compatibility
with KATA 5.1

Compatibility
with KATA 6.0

Compatibility
with KATA 6.1

Compatibility
with KATA 7.0

Kaspersky Endpoint Security
11.4

No

No

No

There are limitations

There are limitations

There are limitations

There are limitations

Kaspersky Endpoint Security
12

No

No

There are limitations

There are limitations

There are limitations

There are limitations

There are limitations

Kaspersky Endpoint Security
12.1

No

No

No

There are limitations

There are limitations

There are limitations

There are limitations

Kaspersky Endpoint Security
12.2

No

No

No

No

There are limitations

There are limitations

There are limitations

To integrate Kaspersky Endpoint Security with Kaspersky Anti Targeted Attack Platform, you do not need to install the Kaspersky Endpoint Agent.

Starting from version 12, Kaspersky Endpoint Security for Linux can be used as the Light Agent for Linux component for the Kaspersky Security for Virtualization application. For more details about the integration, see Kaspersky Security for Virtualization Light Agent Help.

When Kaspersky Endpoint Security for Linux is used as the Light Agent for Linux component, the integration of Kaspersky Endpoint Security for Linux with Kaspersky Anti Targeted Attack Platform is retained.

Limited compatibility of Kaspersky Endpoint Security for Linux versions with Kaspersky Anti Targeted Attack Platform versions

  • Integration of Kaspersky Endpoint Security 11.4 with Kaspersky Anti Targeted Attack Platform 5.1–6.1.

    The scope of data sent by Kaspersky Endpoint Security is limited:

    • Creation of network isolation rules is not supported.
    • Creation of prevention rules is not supported.
    • Searching for indicators of compromise on computers using IOC files is not supported.
    • Event information is not transmitted for the following events: Process terminated, Module loaded, Connection to remote host, Blocked application (prevention rule), Document blocked, Registry modified, Port listened, Driver loaded, Process: interpreted file run, Process: console interactive input, AMSI scan.
    • Creation of the following tasks is not supported: Kill process, Get forensics, Start YARA scan, Delete file, Quarantine file, Restore file from quarantine, Manage services, Get disk image, Get memory dump.
  • Integration of Kaspersky Endpoint Security 12, 12.1, 12.2 with Kaspersky Anti Targeted Attack Platform 6.0–6.1.

    The scope of data sent by Kaspersky Endpoint Security is limited:

    • Event information is not transmitted for the following events: Process terminated, Module loaded, Connection to remote host, Blocked application (prevention rule), Document blocked, Registry modified, Port listened, Driver loaded, Process: interpreted file run, Process: console interactive input, AMSI scan.
    • Creation of the following tasks is not supported: Get forensics, Start YARA scan, Quarantine file, Restore file from quarantine, Manage services, Get disk image, Get memory dump.
  • Integration of Kaspersky Endpoint Security 12.1 with Kaspersky Anti Targeted Attack Platform 5.1.

    The scope of data sent by Kaspersky Endpoint Security is limited:

    • Creation of prevention rules is not supported.
    • Event information is not transmitted for the following events: Process terminated, Module loaded, Connection to remote host, Blocked application (prevention rule), Document blocked, Registry modified, Port listened, Driver loaded, Process: interpreted file run, Process: console interactive input, AMSI scan.
    • Creation of the following tasks is not supported: Get forensics, Get registry key, Get NTFS metafiles, Get process memory dump, Get disk image, Get memory dump, Kill process, Start YARA scan, Manage services, Quarantine file, Restore file from quarantine.
  • Integration of Kaspersky Endpoint Security 11.4 with Kaspersky Anti Targeted Attack Platform 7.0.

    The scope of data sent by Kaspersky Endpoint Security is limited:

    • Creation of network isolation rules is not supported.
    • Creation of prevention rules is not supported.
    • Searching for indicators of compromise on computers using IOC files is not supported.
    • Event information is not transmitted for the following events: Process terminated, Module loaded, Connection to remote host, Blocked application (prevention rule), Document blocked, Registry modified, Port listened, Driver loaded, Process: interpreted file run, Process: console interactive input, AMSI scan, Named pipe, WMI, LDAP.
    • Creation of the following tasks is not supported: Kill process, Get forensics, Start YARA scan, Delete file, Quarantine file, Restore file from quarantine, Manage services, Get disk image, Get memory dump.
  • Integration of Kaspersky Endpoint Security 12, 12.1, 12.2 with Kaspersky Anti Targeted Attack Platform 7.0.

    The scope of data sent by Kaspersky Endpoint Security is limited:

    • Event information is not transmitted for the following events: Process terminated, Module loaded, Connection to remote host, Blocked application (prevention rule), Document blocked, Registry modified, Port listened, Driver loaded, Process: interpreted file run, Process: console interactive input, AMSI scan, Named pipe, WMI, LDAP.
    • Creation of the following tasks is not supported: Get forensics, Start YARA scan, Quarantine file, Restore file from quarantine, Manage services, Get disk image, Get memory dump.