Central Node. Receives and scans data, analyzes the behavior of objects, and publishes analysis results in the web interface of the application.
Sandbox. Starts virtual images of operating systems. Starts files in these operating systems and tracks the behavior of files in each operating system to detect malicious activity and signs of targeted attacks to the corporate IT infrastructure.
Endpoint Agent. Installed on workstations and servers in the IT infrastructure of the organization. Sends information to the Central Node about NDR events and about devices and protocols involved in the connection between the devices. Can be used to automatically send files to Kaspersky Anti Targeted Attack Platform for scanning in Sandbox.