Kaspersky Anti Targeted Attack (KATA) Platform

Architecture of the application

April 2, 2024

ID 194604

The application includes the following main components:

  • Sensor. Receives and scans data, can also be used as a proxy server during data exchange between Endpoint Agent and Central Node.
  • Central Node. Receives and scans data, analyzes the behavior of objects, and publishes analysis results in the web interface of the application.
  • Sandbox. Starts virtual images of operating systems. Starts files in these operating systems and tracks the behavior of files in each operating system to detect malicious activity and signs of targeted attacks to the corporate IT infrastructure.
  • Endpoint Agent. Installed on workstations and servers in the IT infrastructure of the organization. Continuously monitors processes running on those computers, active network connections, and files that are modified.

In this Help section

Sensor component

Central Node component

Sandbox component

Endpoint Agent component

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.