Kaspersky Anti Targeted Attack Platform

Changing the event search conditions

To change the event search conditions, perform the following actions in the Threat Hunting section of the application web interface window:

  1. Click the form containing the event search conditions in the upper part of the window.
  2. Select one of the following tabs:
    • Builder if you want to edit the event search conditions in builder mode.
    • Source code, if you want to change the event search conditions in source code mode.
  3. Make the relevant changes.
  4. Click one of the following buttons:
    • Refresh, if you want to refresh the current event search with the new conditions.
    • New search, if you want to perform a new event search.

The table of events that satisfy the search criteria is displayed.

See also

Events database threat hunting

Searching for events in builder mode

Searching for events in source code mode

Conversion to a query to search events in source code mode

Event search criteria

Operators

Sorting events in the table

Searching for events by processing results in EPP applications

Searching for events using conditions specified in an IOC or YAML file

Creating a TAA (IOA) rule based on event search conditions