Kaspersky Anti Targeted Attack Platform

Contents of exported data

Kaspersky Anti Targeted Attack Platform may contain user data and other confidential information. The Kaspersky Anti Targeted Attack Platform administrator must take steps to ensure the security of this data when creating a backup copy, when replacing equipment on which the application is installed, or in other cases when it may be necessary to permanently delete data. The Kaspersky Anti Targeted Attack Platform administrator bears responsibility for access to data stored on application servers.

You can create a backup copy of the following data:

  • The application database.
  • Objects in Storage.
  • Files from alerts generated during a rescan.
  • Sandbox artifacts.
  • Configuration files.
  • Central Node settings.

You can clear the directory before creating a backup copy of the application.

Before restoring data from backup, the following is cleared on the Central Node server on which you are recovering the application:

  • The application database.
  • Objects in Storage.
  • Files from alerts generated during a rescan.
  • Sandbox artifacts.
  • Configuration files.
  • Central Node settings.

    Contents and amount of data exported to create a backup copy

    Data type

    Exported data

    Application operation mode

    Deployment method

    • Central Node settings
    • PCN connection settings
    • List of connected SCNs
    • The application database on Central Node:
      • Network traffic events
      • Alerts and VIP statuses of alerts
      • Tasks and task execution results
      • Policies
      • User-defined TAA (IOA) rules and exclusions
      • IDS exclusions
      • IOC files
      • Scan exclusion rules
      • Information about files in Storage
      • Information about quarantined objects
      • List of computers with Endpoint Agent
      • Inventory of device
      • Labels assigned to devices
      • List of user accounts registered in the operating systems of the devices
      • List of executable files on devices
      • Address spaces of devices
      • Information about the location of devices on the network interactions map
      • General reports and report templates
      • NDR reports and report templates
      • User account data
      • Network session data
      • Topology map
      • Notifications

    Central Node settings, if selected.

    Application databases, by default.

    Standalone Central Node server.

    All deployment methods.

    PCN settings.

    Custom

    Distributed solution and multitenancy mode.

     

    All deployment methods.

    SCN settings.

    Custom

    As for a standalone Central Node server.

    Distributed solution and multitenancy mode.

    All deployment methods.

    Application databases on the PCN:

    • Network traffic events
    • Alerts and VIP statuses of alerts
    • Task execution results
    • Policies
    • User-defined TAA (IOA) rules and exclusions
    • IDS exclusions
    • IOC files
    • List of data excluded from the scan
    • Information about files in Storage
    • Information about quarantined objects
    • The list of computers with the Endpoint Agent component
    • Inventory of device
    • Labels assigned to devices
    • List of user accounts registered in the operating systems of the devices
    • List of executable files on devices
    • Address spaces of devices
    • Information about the location of devices on the network interactions map
    • General reports and report templates
    • NDR reports and report templates
    • User account data
    • Network session data
    • Topology map
    • Notifications

    Default

    Distributed solution and multitenancy mode.

    All deployment methods.

    Configuration files.

    Yes

    All modes.

    All deployment methods.

    Backup

    Custom

    All modes.

    Non-high-availability version.

    Sandbox artifacts.

    Custom

    All modes.

    Non-high-availability version.

    Files from alerts generated during a rescan.

    Custom

    All modes.

    Non-high-availability version.

    Events database.

    None.

    All modes.

    All deployment methods.

Files that are in the scan queue when the backup copy of the application is created are not exported.