Kaspersky Anti Targeted Attack Platform

About widgets and layouts

You can use widgets to monitor program operation.

The layout is the appearance of the workspace of the program web interface window in the Dashboard section. You can add, delete, and move widgets on the layout, and configure the scale of widgets.

If you are using the

and mode, the section displays data on the organization that you chose.

By default, this section displays information only on alerts that were not processed by users. To also display information on processed alerts, turn on the Processed switch in the upper-right corner of the window.

The Dashboard section displays the following widgets:

  • Alerts:
    • Alerts by status. Displays the alert status depending on the Kaspersky Anti Targeted Attack Platform user processing the alert and on whether or not this alert has been processed.
    • Alerts by technology. Displays the names of the program modules or components that generated the alert.
    • Alerts by attack vector. Displays detected objects based on the vector of the attack.
    • VIP alerts by importance. Displays the importance of alerts with VIP status depending on the impact that these alerts may have on the security of computers or the corporate LAN based on Kaspersky experience.
    • Alerts by importance. Displays the importance of alerts for users of the Kaspersky Anti Targeted Attack Platform depending on the impact that these alerts may have on the security of computers or the corporate LAN based on Kaspersky experience.

    The left part of each widget displays attack vectors, alert importance levels, alert states, and technologies that generated the alerts. The right part of each widget displays the number of times that the program detected them during the selected period of data display on widgets.

    To go to the Alerts section of the program web interface and view related alerts, click the link with the name of the attack vector, alert importance level, and technology that generated the alert. Alerts will be filtered based on the selected element.

  • Top 10:
    • Domains. 10 domains most frequently seen in alerts.
    • IP addresses. 10 IP addresses most frequently seen in alerts.
    • Email senders. 10 email senders most frequently seen in alerts.
    • Email recipients. 10 email recipients most frequently seen in alerts.
    • TAA hosts. 10 hosts that occur most frequently in events and alerts generated by the Targeted Attack Analyzer (TAA) technology.
    • TAA rules. 10 TAA (IOA) rules that occur most frequently in events and alerts generated by the Targeted Attack Analyzer (TAA) technology.

    The left part of each widget lists the domains, addresses of recipients, IP addresses, and addresses of message senders, host names, and TAA (IOA) rule names. The right part of each widget displays the number of times that the program detected them during the selected period of data display on widgets.

    By clicking the link with the name of each domain, recipient address, IP address, message sender address, host name, and TAA (IOA) rule name, you can go to the Alerts section of the program web interface and view related alerts. Alerts will be filtered based on the selected element.

See also

Monitoring program operation

Adding a widget to the current layout

Moving a widget in the current layout

Removing a widget from the current layout

Saving a layout to PDF

Configuring the period for displaying data in widgets

Configuring the widget display scale

Main principles of working with "Alerts" widgets

Viewing the working condition of modules and components of the program