Managing NDR reports

You can use Kaspersky Anti Targeted Attack Platform to get reports with various information saved by the application. Kaspersky Anti Targeted Attack Platform generates reports as PDF files. The application can send report files to email addresses.

You can view information about generated reports and export them to files in the Reports section, Reports (NDR) subsection, Generated reports tab.

The following types of NDR report templates are possible:

Information in reports is presented as separate information blocks. Each Kaspersky Anti Targeted Attack Platform report includes a fixed set of information blocks, which are arranged in a fixed order. Information blocks used in reports and their descriptions are listed in the table below.

Using information blocks in reports

Name of the information block

Inventory report

System security report

Executive summary

Full report

Device categories

Check mark meaning the item is present.

Dash meaning the item is not present.

Check mark meaning the item is present.

Check mark meaning the item is present.

Device vendors

Check mark meaning the item is present.

Dash meaning the item is not present.

Check mark meaning the item is present.

Check mark meaning the item is present.

Device operating systems

Check mark meaning the item is present.

Dash meaning the item is not present.

Check mark meaning the item is present.

Check mark meaning the item is present.

Devices with the greatest number of risks.

Check mark meaning the item is present.

Check mark meaning the item is present.

Dash meaning the item is not present.

Check mark meaning the item is present.

Situational awareness

Dash meaning the item is not present.

Check mark meaning the item is present.

Check mark meaning the item is present.

Check mark meaning the item is present.

New devices in the network

Check mark meaning the item is present.

Dash meaning the item is not present.

Dash meaning the item is not present.

Check mark meaning the item is present.

Protocols with the most traffic

Check mark meaning the item is present.

Dash meaning the item is not present.

Dash meaning the item is not present.

Check mark meaning the item is present.

Devices with the most connections to other nodes

Check mark meaning the item is present.

Dash meaning the item is not present.

Dash meaning the item is not present.

Check mark meaning the item is present.

Network traffic volume

Check mark meaning the item is present.

Dash meaning the item is not present.

Check mark meaning the item is present.

Check mark meaning the item is present.

Common protocols

Check mark meaning the item is present.

Dash meaning the item is not present.

Check mark meaning the item is present.

Check mark meaning the item is present.

Device security status

Dash meaning the item is not present.

Check mark meaning the item is present.

Check mark meaning the item is present.

Check mark meaning the item is present.

Distribution of devices by status

Dash meaning the item is not present.

Check mark meaning the item is present.

Dash meaning the item is not present.

Check mark meaning the item is present.

Statistics on events

Dash meaning the item is not present.

Check mark meaning the item is present.

Dash meaning the item is not present.

Check mark meaning the item is present.

Distribution of events by detection technologies

Dash meaning the item is not present.

Check mark meaning the item is present.

Dash meaning the item is not present.

Check mark meaning the item is present.

Devices with the most events

Dash meaning the item is not present.

Check mark meaning the item is present.

Dash meaning the item is not present.

Check mark meaning the item is present.

Most critical events

Dash meaning the item is not present.

Check mark meaning the item is present.

Dash meaning the item is not present.

Check mark meaning the item is present.

Most frequently triggered malicious activity detection rules

Dash meaning the item is not present.

Check mark meaning the item is present.

Dash meaning the item is not present.

Check mark meaning the item is present.

Devices with signs of access to public resources

Dash meaning the item is not present.

Check mark meaning the item is present.

Dash meaning the item is not present.

Check mark meaning the item is present.

Connections via remote control protocols

Dash meaning the item is not present.

Check mark meaning the item is present.

Dash meaning the item is not present.

Check mark meaning the item is present.

Active risks

Dash meaning the item is not present.

Check mark meaning the item is present.

Check mark meaning the item is present.

Check mark meaning the item is present.

In this section

Viewing the table of NDR report templates

Viewing NDR report template details

Viewing the table of NDR reports

Manually generating an NDR report based on a template

Duplicating an NDR report template

Editing an NDR report template

Exporting an NDR report to a file

Deleting an NDR report template

Deleting an NDR report

Canceling NDR report generation

Managing the settings for storing report files

Page top