for Windows, macOS and Linux
The File Threat Protection component lets you prevent infection of the file system of the computer. By default, the File Threat Protection component resides permanently in the computer's RAM and scans all files that are opened, saved, or run in real time. The component scans files on all computer drives, including connected drives. The component provides computer protection with the help of anti-virus databases, the Kaspersky Security Network cloud service, and heuristic analysis.
The component scans the files accessed by the user or application. If a malicious file is detected, Kaspersky Endpoint Security blocks the file operation. The application then disinfects or deletes the malicious file, depending on the settings of the File Threat Protection component.
When attempting to access a file whose contents reside in OneDrive cloud storage, Kaspersky Endpoint Security downloads and scans the file contents.
File Threat Protection settings for Pro View
| Parameter | OS | Description | 
|---|---|---|
| Scan exclusions | 
 
 
 | A scan exclusion is a set of conditions that must be fulfilled so that Kaspersky Endpoint Security will not scan a particular object for viruses and other threats. Scan exclusions make it possible to safely use legitimate software that can be exploited by criminals to damage the computer or user data. Although they do not have any malicious functions, such applications can be exploited by intruders. For details on legitimate software that can be used by intruders to damage your computer or personal data, please refer to the Kaspersky IT Encyclopedia website. Kaspersky Endpoint Security supports environment variables and the  | 
| Security level | 
 
 
 | For File Threat Protection, Kaspersky Endpoint Security can apply different groups of settings. These groups of settings that are stored in the application are called security levels: 
 | 
| File types | 
 
 
 | The value of this parameter depends on the selected security level. All files. If this setting is enabled, Kaspersky Endpoint Security checks all files without exception (all formats and extensions). Files scanned by extension. If this setting is enabled, the application scans infectable files only. Before scanning a file for malicious code, the internal header of the file is analyzed to determine the format of the file (for example, .txt, .doc, or .exe). The scan also looks for files with particular file extensions. Files scanned by format. If this setting is enabled, the application scans infectable files only. The file format is then determined based on the file's extension. | 
| Protection scope | 
 
 
 | Contains objects that are scanned by the File Threat Protection component. All hard drives and removable drives are scanned. It is not possible to change the protection scope. | 
| Scan of compound files | 
 
 
 | The value of this parameter depends on the selected security level. A common technique of concealing viruses and other malware is to implant them in compound files, such as archives or databases. To detect viruses and other malware that are hidden in this way, the compound file must be unpacked, which may slow down scanning. 
 | 
| Network Drives Scan | 
 
 | Scanning network drives by Kaspersky Endpoint Security. The scan can place a significant load on the CPU. It is more convenient to perform indirect scanning on file servers. | 
| Background Scan | 
 | Background Scan is a scan mode of Kaspersky Endpoint Security that does not display notifications for the user. Background scan requires less computer resources than other types of scans (such as a full scan). In this mode, Kaspersky Endpoint Security scans startup objects, the boot sector, system memory, and the system partition. |