This Help provides information related to Kaspersky Endpoint Agent for Windows. This information may be partially or completely inapplicable to Kaspersky Endpoint Agent for Linux. For complete information about Kaspersky Endpoint Agent for Linux, please refer to the Help of the solution that includes the application: Kaspersky Anti Targeted Attack Platform or Kaspersky Managed Detection and Response.
You can configure EDR telemetry exclusions using Kaspersky Security Center Web Console both in the properties of an individual device and in the policy settings for a group of devices.
In the main Kaspersky Security Center Web Console window select Devices → Policies and profiles.
Select the policy you want to configure.
In the <Policy name> window that opens, select the Application settings tab.
In the EDR telemetry section, select Exclusions.
The window for configuring EDR telemetry exclusion settings opens.
To enable usage of EDR telemetry exclusions, select the Use exclusions check box.
To add a new exclusion:
Click the Add button.
In the Rule properties window that opens, configure the following exclusion criteria:
The criteria are applied using logical AND.
To create a rule, specify the value in the Full path field and select at least one event type in the Use this exclusion for the following event types list.
If the Network events option is selected for the Use this exclusion for the following event types criterion, specify the full path to the file in the Full path field.
The object for which you create an exclusion must be available on the protected device at the time the exclusion settings are applied. For example, if you first configure exclusion for a specific application, and then install that application on the protected device, this exclusion will not be applied.
In the Process information section, specify the values in the following fields:
Full path. Full path to the file, including its name and extension. You can use file masks (using the ? and * characters), as well as system environment variables.
Command line text. Command line to run the object.
Parent folder path. The path to the folder where the file is located.
In the File properties section, specify the values in the following fields:
File description. The value of the FileDescription parameter from the resource of the RT_VERSION type (VersionInfo).
Original file name. The value of the OriginalFilename parameter from the resource of the RT_VERSION type (VersionInfo).
File version. The value of the FileVersion parameter from the resource of the RT_VERSION type (VersionInfo).
In the File checksums section, specify the values in the following fields:
MD5. MD5 hash of the file.
SHA256. SHA256 hash of the file.
In the Use this exclusion for the following event types list, select at least one of the following options:
File modification.
Network events.
Interactive input in the console. This option is selected by default.
Loading the process module.
Changes in the Registry.
Click OK to save the changes and close the Rule properties window.
The new rule is created and displayed in the list of exclusions.
To remove a rule from the list of exclusions, select the check box next to the rule and click Remove.
To open the properties window for an existing rule and to change the specified criteria, select the check box next to the rule and click Edit.
If you are configuring the policy settings, make sure that the switch in the upper right corner of the group of settings is set to Enforce. It is the default position of the switch.
Click OK to save the changes and close the Exclusions window.
EDR telemetry exclusions will be used according to the configured rules.