Kaspersky Anti Targeted Attack Platform

What's new

Kaspersky Anti Targeted Attack Platform 7.0.3 introduces the following new features:

  1. Improved performance of Kaspersky Anti Targeted Attack Platform
  2. Fixed errors when displaying information about network sessions.
  3. Fixed errors that occurred when installing or upgrading Kaspersky Anti Targeted Attack Platform.
  4. Fixed vulnerabilities in the Suricata module.
  5. Optimized rules for combining events.
  6. Fixed the unstable display of virtual machine status.
  7. Fixed the single sign-on (SSO) authentication error.
  8. Fixed an error when registering events in network traffic.
  9. Fixed an error when a user with the Security officer role tries to gain access to sections of custom rules.
  10. Fixed the display of information about mirrored traffic from SPAN ports in the Dashboard section of the web interface.

Kaspersky Anti Targeted Attack Platform 7.0.1 now has the following new features:

  1. A download of mirrored traffic is completed correctly even if the next download request arrives before the previous request has completed.
  2. When searching for network packets for the last hour, all records that match the search criteria are displayed.
  3. In a cluster configuration, when integrated with a mail server, the error when sending email messages is now fixed.
  4. Fixed the error of the Embedded Sensor component that occurred after upgrading the Central Node component, which was used in distributed solution or multitenancy mode, to version 7.0.
  5. Now, when deploying a cluster, you can select the localization language for the NDR functionality.

Kaspersky Anti Targeted Attack Platform 7.0 now has the following new features:

  1. Now you can connect up to 150 SCN servers to a single PCN server in distributed solution and multitenancy mode.
  2. Now you can deploy the application in the following virtualization systems: "Brest" virtualization software, "RED Virtualization", zVirt Node.
  3. Now you can use the following localizations in custom operating system images with no impact on object scanning quality: Chinese (simplified), Arabic, and Spanish (Mexico).
  4. Now you can manually send files for scanning in Sandbox from hosts on which Kaspersky Endpoint Security for Windows and Kaspersky Endpoint Security for Linux are used in the role of the Endpoint Agent component.
  5. Now you can create a TAA (IOA) rule based on event search conditions from a YAML file with a Sigma rule.
  6. Expanded list of fields available for event search in source code mode in the Threat Hunting section.
  7. Expanded functionality for the Endpoint Agent represented by Kaspersky Endpoint Security for Windows 12.7:
    • New event types supported: Code injection, Named pipe, WMI, LDAP, DNS, Process access.
    • New subtypes of the File modified event: File read, Hard link created, Symbolic link created.
    • New subtypes of the Registry modified event: Registry key renamed, Registry key saved.
    • New fields for the Module loaded and Connection to remote host events.
  8. Expanded functionality for the Endpoint Agent represented by Kaspersky Endpoint Security for Linux 12.2:
    • New event types: Connection to remote host, Port listened, Module loaded, DNS, Process access.
    • New subtype of the File modified event: File read.
    • Now you can quarantine an object.
    • Now you can create prevention rules.
  9. Now you can enforce the user account password change.
  10. Scanning of encrypted archives downloaded from an URL in an email message is now supported.
  11. Now you can apply response actions to multiple devices.
  12. Expanded NDR functionality:
    • Now you can view events in network traffic.
    • The table of alerts now displays External Analysis alerts.
    • Added an inventory of devices on the local network of the organization.
    • Now you can view the following device information:
      • User accounts registered in the operating systems of the devices.
      • File execution on devices.
      • Address spaces of devices.
      • Now you can display risks associated with devices.
      • Dynamic IP addressing of devices is now supported.
      • Now you can monitor the network activity of devices on the network map.
      • Devices can now be actively polled to enrich information in the list of devices and build the network topology map.
      • Added the ability to analyze network sessions.
      • Now you can identify the name of the transport protocol that was used in a network session.
      • Now you can identify the name of the application-layer protocol that was used in a network session.
      • Now you can find sessions by network packets in the traffic storage, as well as download the data of individual network packets and sessions to a file.
      • New types of reports.
  13. Updated logic for managing custom IDS rules.
  14. Different ports are now used for the interaction between the Central Node and Sensor components:
    • For the Central Node server, inbound connections must be allowed to TCP ports 13520 and 7423.
    • For the Sensor server, outbound connections to TCP ports 13520 and 7423 and inbound connections to TCP port 9443 must be allowed.
    • In the distributed solution and multitenancy mode, you must enable inbound and outbound connections for TCP ports 11000:11006 on PCN and SCN servers.

Changes in Kaspersky Endpoint Agent 3.16 for Windows:

You can view the list of changes in Kaspersky Endpoint Agent 3.16 for Windows in the Kaspersky Endpoint Agent for Windows Online Help.

Changes in Kaspersky Endpoint Security 12.7 for Windows:

You can view the list of changes in Kaspersky Endpoint Security 12.5 for Windows in the Kaspersky Endpoint Security for Windows Online Help.

Changes in Kaspersky Endpoint Security 12.2 for Linux:

You can view the list of changes in Kaspersky Endpoint Security 12 for Linux in the Kaspersky Endpoint Security for Linux Online Help.

See also

Kaspersky Anti Targeted Attack Platform

About Kaspersky Threat Intelligence Portal

Distribution kit

Hardware and software requirements

Restrictions