This Help provides information related to Kaspersky Endpoint Agent for Windows. This information may be partially or completely inapplicable to Kaspersky Endpoint Agent for Linux. For complete information about Kaspersky Endpoint Agent for Linux, please refer to the Help of the solution that includes the application: Kaspersky Anti Targeted Attack Platform or Kaspersky Managed Detection and Response.
You can configure EDR telemetry exclusions using the Administration Console both in the properties of an individual device and in the policy settings for a group of devices.
In the Managed devices folder of the Administration Console tree, select the folder with the name of the administration group, which includes the required device.
In the workspace, select the Devices tab.
Select the device for which you want to configure Kaspersky Endpoint Agent settings.
Select Properties in the device context menu.
The device properties window opens.
Select the Applications section.
A list of Kaspersky applications installed on the device is displayed in the window.
Select Kaspersky Endpoint Agent and open its properties window in one of the following ways:
Double-click the application name.
In the application context menu, select Properties.
Click the Properties button under the list of Kaspersky applications.
Open Kaspersky Security Center Administration Console.
In the console tree, open the Policies folder.
Select Kaspersky Endpoint Agent policy and open its properties window in one of the following ways:
Double-click the policy name.
Select Properties in the policy context menu.
Select the Configure policy settings item in the right part of the window.
Select the EDR telemetry → Exclusions section.
To enable usage of EDR telemetry exclusions, enable the Use exclusions setting in the EDR telemetry section.
To add a new exclusion:
Click the Add button.
In the Rule properties window that opens, configure the following exclusion criteria:
The criteria are applied using logical AND.
To create a rule, specify the value in the Full path field and select at least one event type in the Use this exclusion for the following event types list.
If the Network events option is selected for the Use this exclusion for the following event types criterion, specify the full path to the file in the Full path field.
The object for which you create an exclusion must be available on the protected device at the time the exclusion settings are applied. For example, if you first configure exclusion for a specific application, and then install that application on the protected device, this exclusion will not be applied.
In the Process information section, specify the values in the following fields:
Full path. Full path to the file, including its name and extension. You can use file masks (using the ? and * characters), as well as system environment variables.
Command line text. Command line to run the object.
Parent folder path. The path to the folder where the file is located.
In the File properties section, specify the values in the following fields:
File description. The value of the FileDescription parameter from the resource of the RT_VERSION type (VersionInfo).
Original file name. The value of the OriginalFilename parameter from the resource of the RT_VERSION type (VersionInfo).
File version. The value of the FileVersion parameter from the resource of the RT_VERSION type (VersionInfo).
In the File checksums section, specify the values in the following fields:
MD5. MD5 hash of the file.
SHA256. SHA256 hash of the file.
In the Use this exclusion for the following event types list, select at least one of the following options:
File modification.
Network events.
Interactive input in the console. This option is selected by default.
Loading the process module.
Changes in the Registry.
Click OK to save the changes and close the Rule properties window.
The new rule is created and displayed in the list of exclusions.
To remove a rule from the list of exclusions, select the rule and click Remove.
To open the properties window for an existing rule and to change the specified criteria, select the rule in the list of exclusions and click Edit.
If you are configuring the policy settings, make sure that the switch in the upper right corner of the group of settings is set to Under policy. It is the default position of the switch.
Click OK to save the changes.
EDR telemetry exclusions will be used according to the configured rules.