Kaspersky Anti Targeted Attack Platform

Data on objects in Storage and Quarantine

If the Central Node component is installed on a server, data about objects in storage and quarantine is stored in the /data directory indefinitely. If Central Node is installed as a cluster, the information is stored in ceph storage indefinitely.

Kaspersky Anti Targeted Attack Platform resources provide no capability to restrict the rights of the users of servers and operating systems to which the Central Node component is installed. The administrator is advised to use any system resources at their own discretion to control how the users of servers and operating systems with the application installed may be granted access to the personal data of other users.

Data on objects in Storage and quarantine may contain the following information:

  • Name of the object.
  • Path to the object on the computer with the Endpoint Agent component.
  • MD5- and SHA256 hash of the file.
  • File size.
  • ID of the user that quarantined the object.
  • ID of the user that placed the object in Storage.
  • IP address of the computer on which the quarantined object is stored.
  • Name of the computer on which the quarantined object is stored.
  • Unique ID of the computer on which the quarantined object is stored in Storage.
  • ID of the TAA (IOA) rule by which the detection was generated.
  • Category of the detected object.
  • Results for the object scanned using individual modules and technologies of the application.
  • File download time.
  • Metadata of scanned files and their sources.
  • Resulting status of the object in Storage.

See also

Traffic data of the Sensor component

Data in detections

Data in events

Data in reports