Configuring Threat Response actions of Kaspersky Endpoint Agent to respond to threats detected by Kaspersky Sandbox

This Help provides information related to Kaspersky Endpoint Agent for Windows. This information may be partially or completely inapplicable to Kaspersky Endpoint Agent for Linux. For complete information about Kaspersky Endpoint Agent for Linux, please refer to the Help of the solution that includes the application: Kaspersky Anti Targeted Attack Platform or Kaspersky Managed Detection and Response.

Kaspersky Endpoint Agent can perform actions in response to threats detected by Kaspersky Sandbox.

You can configure the following types of actions:

Local actions:

Group actions:

To configure group threat response actions, set up the permissions of Kaspersky Security Center users, whose accounts you want use for managing IOC Scan tasks.

When configuring threat response actions, keep in mind that as a result of some actions, the object containing the threat may be deleted from the workstation where it was detected.

To configure Kaspersky Endpoint Agent response actions to threats detected by Kaspersky Sandbox:

  1. Do one of the following:
    • Open the application properties window for an individual device.
    • Open the policy properties window.
  2. In the Kaspersky Sandbox integration section select the Threat Response subsection.
  3. Select the Take response actions on threats detected by Kaspersky Sandbox check box.
  4. In the Selected actions list, select the check boxes for the actions you want to enable.
  5. If you want to use group actions, specify the Administration Server user name and password in the Authentication on Administration Server group of settings.
  6. If you configure the policy settings, in the upper right corner of the group of settings, change the switch from Undefined to Forced.
  7. Click OK.
  8. In the policy properties window, click Save.

See also

Enabling and disabling integration with Kaspersky Sandbox

Configuring trusted connection on Kaspersky Endpoint Agent side

Adding Kaspersky Sandbox servers to Kaspersky Endpoint Agent list

Configuring the response timeout of Kaspersky Sandbox and request queue settings

Enabling detection of legitimate applications that can be used by cybercriminals

Configuring IOC Scan tasks start

Page top