This Help provides information related to Kaspersky Endpoint Agent for Windows. This information may be partially or completely inapplicable to Kaspersky Endpoint Agent for Linux. For complete information about Kaspersky Endpoint Agent for Linux, please refer to the Help of the solution that includes the application: Kaspersky Anti Targeted Attack Platform or Kaspersky Managed Detection and Response.
When Kaspersky Sandbox detects a threat, Kaspersky Endpoint Agent automatically creates IOC Scan tasks for all devices (search for MD5 hashes of objects in which the threat was detected).
To configure start of Autonomous IOC Scan tasks:
The IOC scanning settings window opens.
If you select the Start within the specified time interval option, specify the start and end of the period in the Start time (hh:mm) and End time (hh:mm) fields.
All IOC Scan tasks that were automatically created before the beginning of the specified period will start at any time within the specified period.
All IOC Scan tasks that were automatically created within the specified period will start immediately after creation.
All IOC Scan tasks that were automatically created after the end of the specified period will start during the next task execution period.
Example: If you configured the tasks to run during the period from 8:00 p.m. to 7:00 a.m.: Tasks that were automatically created at 7 p.m. are started at any arbitrary time from 8:00 p.m. to 7:00 a.m. Tasks that were automatically created at 9 p.m. are started at 9 p.m. Tasks that were automatically created at 8:00 a.m. are started during the next task execution period, from 8:00 p.m. to 7:00 a.m. |
The IOC scanning settings window closes.
Start of Autonomous IOC Scan tasks is configured.