Viewing IOC scanning task results

August 12, 2022

ID 236247

To view the IOC Scan task results:

  1. Open the Kaspersky Security Center Administration Console.
  2. In the console tree, select the Tasks folder.

    A list of task appears.

  3. Open the settings of the required task in one of the following ways:
    • Double-click the task name.
    • Open the policy context menu and select Properties.
    • Select a task and click Configure task in the right part of the window.
  4. This opens the Properties: <Task name> window.
  5. Select the Results section.
  6. In the Show task results for the device list, select the devices for which you want to view the results of IOC Scan tasks.
  7. To view detailed information for a specific task, double-click to expand it.
  8. To view detailed information about the detected indicator of compromise, click the Show card button.

The IOC detections card contains information about objects that matched the conditions of the IOC file, as well as the text of matched branches or individual conditions of that IOC file.

Viewing the IOC detections card is not available for IOC files that had no indicators of compromise when scanned.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.