Kaspersky Anti Targeted Attack Platform resources provide no capability to restrict the rights of the users of servers and operating systems to which the Central Node component is installed. The administrator is advised to use any system resources at their own discretion to control how the users of servers and operating systems with the application installed may be granted access to the personal data of other users.
Information about the service data of Kaspersky Anti Targeted Attack Platform is provided in the table below
Service data of Kaspersky Anti Targeted Attack Platform
Data type |
Location and duration of storage |
|---|---|
User account information
|
The information is stored indefinitely on the Central Node server in the
|
Information about МDR, KSN, KPSN integration. |
|
OSMP integration settings:
|
|
Information about applied license keys or activation codes. |
|
Endpoint Agent settings. |
|
Settings of the mail server used for sending notifications:
|
|
Name of the current server. |
|
Addresses of servers connected to the current server and information about certificates used for mutual authentication with them. |
|
Connector settings:
|
|
Information about secrets and user account information of Central Node users. |
|
Address of the monitoring point. |
|
Information about ICAP exclusions. |
|
Settings of Sensor integration with ICAP:
|
|
Settings for sending user-defined intrusion detection rules to KSN. |
|
Information about the state and names of Keytab files used in Kerberos authentication. |
|
Information about KSMG email message scanning priorities. |
|
CPU and RAM load notification settings:
|
|
Information about certificates used for mutual authentication of Sensor and Central Node. |
|
Settings of Sensor integration with POP3:
|
|
Proxy server settings:
|
|
Storage server settings:
|
|
Settings of Sandbox servers:
|
|
Sandbox component settings:
|
|
Security settings:
|
|
Settings of Sensor servers: maximum size of a file that can be sent for scanning. |
|
SIEM settings:
|
|
Settings of Sensor integration with SMTP:
|
|
SNMP connection settings:
|
|
Settings of Sensor integration with SPAN:
|
|
Settings of storage for mirrored traffic from SPAN ports:
|
|
Time zone settings. |
|
Update settings:
|
The information is stored indefinitely on the Central Node server in the |
System event log |
OS log files are stored indefinitely in the |
Log with information about the application operation. |
The log file is stored indefinitely in the /data directory on the server hosting the Central Node component, if the component is installed on a server. When the Central Node component is installed on a cluster, data is stored on storage servers indefinitely. |
File scan queue. |
Files are stored on the server hosting the Central Node component in the /data directory if the component is installed on a server. When the Central Node component is installed on a cluster, data is stored on storage servers. The data is retained until the scan is completed. |
Files received from computers with the Endpoint Agent component. |
Files are stored on the server hosting the Central Node component in the /data directory if the component is installed on a server. When the Central Node component is installed on a cluster, data is stored on storage servers. Data is rotated when disk space becomes full. |
Files with YARA and IDS rules (user-defined and from Kaspersky). |
Files are stored indefinitely in the /data directory on the server hosting the Central Node component, if the component is installed on a server. When the Central Node component is installed on a cluster, data is stored on storage servers indefinitely.
|
Files with data about detections sent to external systems. |
Files are stored indefinitely on the server hosting the Central Node component in the /data directory if the component is installed on a server. When the Central Node component is installed on a cluster, data is stored on storage servers indefinitely.
|
Artifacts of the Sandbox component. |
Files are stored on the server hosting the Central Node component in the /data directory if the component is installed on the server. When the Central Node component is installed on a cluster, data is stored on storage servers. Data is rotated when disk space becomes full. |
Files for which detections were created by the Sandbox component. |
Files are stored on the server hosting the Central Node component in the /data directory if the component is installed on the server. When the Central Node component is installed on a cluster, data is stored on storage servers. Data is rotated when disk space becomes full. |
Certificate files used for the authentication of application components. |
Files are stored indefinitely in the /data directory on the server hosting the Central Node, PCN, SCN, Sensor component or on the computer with the Endpoint Agent component. |
Encryption keys that are transmitted between application components. |
Files are stored indefinitely in the /data directory on the server hosting the Central Node, PCN, SCN, Sensor component or on the computer with the Endpoint Agent component.
|
Copies of mirrored traffic from SPAN ports. |
Files are stored in storage mounted on the server with the Sensor component. Data is deleted as disk space becomes full. |
ICAP exclusion filters. |
Files are stored indefinitely on the server hosting the Central Node component in the /data directory if the component is installed on the server. When the Central Node component is installed on a cluster, data is stored on storage servers indefinitely. |
|
The data is stored on the Central Node server in the /data/storage/volumes/nta_database directory. Data is rotated as disk space becomes filled. |
Information about an email message sent for scanning to Kaspersky Anti Targeted Attack Platform from Kaspersky Secure Mail Gateway:
|
When Central Node is installed on a server (not as a cluster), data is stored on the Central Node server in the /data directory. When Central Node is installed as a cluster, the data is stored in the ceph storage. If an alert is generated as a result of scanning a message, the data is rotated when the number of alerts created as a result of scanning by a specific technology reaches 1,000,000. If no alert is generated, the data is rotated after 7 days. |
Passwords for scanning encrypted archives sent for scanning from Kaspersky Secure Mail Gateway. |
Data is stored on the Central Node server in the /data directory if the component is installed on a server. When the Central Node component is deployed as a cluster, data is stored on storage servers. The data is rotated after the encrypted archive is scanned. |
Information about custom widget layouts:
|
Files are stored indefinitely on the server hosting the Central Node component in the /data directory if the component is installed on a server. When the Central Node component is installed on a cluster, data is stored on storage servers indefinitely. |
Information about user accounts:
|
|
Information about Central Node components:
|
|
Information about tenants:
|
|
Information about computers connected to the Central Node with the Endpoint Agent component:
|
|
Data of the scanned object: domain. |
|
Information about custom intrusion detection rules:
|
|
Information about scan exclusions:
|
|
Information about reports and report templates:
|
|
Information about Endpoint Agent component certificates:
|
|
Information about user-defined Sandbox rules:
|
|
Virtual machine configuration information:
|
|
Information about user accounts on devices:
|
The data is stored on the Central Node server in the /data/storage/volumes/nta_database directory. Data is rotated as disk space becomes filled.
|
Network session information:
|
|
Information about devices registered in the application:
|
|
Data saved when integrated with the Endpoint Agent component as part of the NDR functionality:
|
|
Information about network traffic events: IP and MAC addresses of devices. |
|
Information about executable files on Endpoint Agent computers connected as part of the NDR functionality:
|
|
Audit log for user activity related to the NDR functionality. |