Data in alerts

Alerts may contain user data. Information about alerts is stored on the server with the Central Node component in the directory /data/var/lib/kaspersky/storage/pgsql/10/data/ and is rotated as disk space is filled. Files whose scan results generated an alert are accumulated on the server hosting the Central Node component and rotated as disk space is filled up.

Kaspersky Anti Targeted Attack Platform resources provide no capability to restrict the rights of the users of servers and operating systems to which the Central Node component is installed. The administrator is advised to use any system resources at their own discretion to control how the users of servers and operating systems with the program installed may be granted access to the personal data of other users.

The following information is stored in all alerts:

If a file is detected in network traffic or mail traffic, the following information may be stored on the server:

If an email message was detected, the following information may be stored on the server:

If the alert was generated by URL Reputation technology, the following information may be stored on the server:

If the alert was generated by Intrusion Detection System technology, the following information may be stored on the server:

If the alert was generated using YARA rules, the following information can be stored on the server:

If the alert was generated using the Sandbox component, the following information may be stored on the server:

If the alert was generated by IOC or TAA (IOA) user rules, the following information can be stored on the server:

See also

Data of the Central Node and Sensor components

Traffic data of the Sensor component

Data in events

Data in reports

Data on objects in Storage and Quarantine

Data on program settings

Page top