This section provides information related to Kaspersky Endpoint Agent for Windows. This information may be partially or completely inapplicable to Kaspersky Endpoint Agent for Linux. For complete information about Kaspersky Endpoint Agent for Linux, please refer to the Help of the solution that includes the application: Kaspersky Anti Targeted Attack Platform or Kaspersky Managed Detection and Response.
You can configure exclusions for and optimization of the volume of EDR telemetry about application processes using Kaspersky Security Center Administration Console, in the properties of an individual device or in the policy settings for a group of devices.
Data that Kaspersky Endpoint Agent analyzes on the protected device and sends to the Telemetry collection server. Telemetry is a list of events that occurred on the protected device.
Set of settings joined by a logical AND, which Kaspersky Endpoint Agent uses to not analyze and send EDR telemetry.
Exclusions of sent EDR telemetry about application processes are available when integrating Kaspersky Endpoint Agent with servers on which KATA Central Node or Kaspersky Industrial CyberSecurity for Networks is installed.
Kaspersky Endpoint Agent does not analyze or send data on excluded application processes to the server with KATA Central Node or Kaspersky Industrial CyberSecurity for Networks installed.
Optimization of the amount of sent EDR telemetry about application processes can be managed (enabled/disabled) when Kaspersky Endpoint Agent is integrated with servers with Kaspersky Industrial CyberSecurity for Networks installed.
If optimization of the amount of sent EDR telemetry is enabled, Kaspersky Endpoint Agent does not send events with codes 102 (basic communications) and 8 (the process's network activity) for the Microsoft SMB protocol and Network Agent klnagent.exe about application processes to a server on which Kaspersky Industrial CyberSecurity for Networks is installed.
To enable and configure exclusions for and optimization of the volume of EDR telemetry on application processes:
In the Managed devices folder of the Administration Console tree, select the folder with the name of the administration group, which includes the required device.
In the workspace, select the Devices tab.
Select the device for which you want to configure Kaspersky Endpoint Agent settings.
Select Properties in the device context menu.
The device properties window opens.
Select the Applications section.
A list of Kaspersky applications installed on the device is displayed in the window.
Select Kaspersky Endpoint Agent and open its properties window in one of the following ways:
Double-click the application name.
In the application context menu, select Properties.
Click the Properties button under the list of Kaspersky applications.
Open Kaspersky Security Center Administration Console.
In the console tree, open the Policies folder.
Select Kaspersky Endpoint Agent policy and open its properties window in one of the following ways:
Double-click the policy name.
Select Properties in the policy context menu.
Select the Configure policy settings item in the right part of the window.
Select the EDR telemetry → Excluded processes section.
In the Exclusions settings group, enable the Use exclusions setting to enable use of EDR telemetry exclusions.
Configure optimization of the volume of EDR telemetry:
When integrating Kaspersky Endpoint Agent with servers with KATA Central Node installed, optimization of the amount of sent EDR telemetry should always be enabled.
Disable the Optimize the amount of sent telemetry setting if you want Kaspersky Endpoint Agent to send events with codes 102 (basic communications) and 8 (the process's network activity) for the Microsoft SMB protocol, WinRM service, and the Network Agent process klnagent.exe, as well as extended information about the type of network packets for all types of network protocols.
Enable the Optimize the amount of sent telemetry setting if you want Kaspersky Endpoint Agent to not send events with codes 102 (basic communications) and 8 (the process's network activity) for the Microsoft SMB protocol and the Network Agent process klnagent.exe, as well as extended information about the type of network packets for all types of network protocols.
If the Use exclusions setting is disabled, Kaspersky Endpoint Agent does not send events with codes 102 (basic communications) and 8 (the process's network activity) for the Microsoft SMB protocol and the Network Agent process klnagent.exe, as well as extended information about the type of network packets for all types of network protocols, regardless of the value of the Optimize the amount of sent telemetry setting.
Exclusion settings are applied using a logical AND.
The executable file of the process for which you create an exclusion must be available on the protected device at the time the exclusion settings are applied. If you first configure an exclusion for a process and then install an application associated with that process on the protected computer, then the exclusion will not be applied.
Specify the parameters of the executable file of the process for which Kaspersky Endpoint Agent will apply the exclusion rule:
Click on the Fill based on file properties button if you want the parameters of the process's executable file to be filled in automatically.
Unavailable in Kaspersky Security Center Web Console and Kaspersky Security Center Cloud Console
In 64-bit operating systems, the parameters of the 64-bit version of the process's executable file in the \windows\system32 folder must be entered manually, since when you click the Fill based on file properties button the plugin fills in the parameters of the process's executable file from the properties of the 32-bit version of the same executable file located in the \windows\syswow64 folder. For example, if you select the \windows\system32\cmd.exe file, the plugin displays the settings of the \windows\syswow64\cmd.exe file. This situation is related to operating system behavior.
Specify process parameters manually:
In the Information about the process section, specify the values in the following fields:
Full path. Full path to the file, including its name and extension. You can use file masks (using the ? and * characters), as well as system environment variables.
Command line text. Command line to run the object.
Parent path. The path to the folder where the file is located.
In the File properties section, specify the values in the following fields:
Description. The value of the FileDescription parameter from the resource of the RT_VERSION type (VersionInfo).
Original file name. The value of the OriginalFilename parameter from the resource of the RT_VERSION type (VersionInfo).
Version. The value of the FileVersion parameter from the resource of the RT_VERSION type (VersionInfo).
In the File checksums section, specify the values in the following fields:
MD5. MD5 hash of the file.
SHA256. SHA256 hash of the file.
In the Use this exclusion for the following types of events list, select at least one value:
File modification.
Network events.
If this value is selected, specify the full path to the file in the Full path field.
Interactive console input.
This event type is selected by default.
Process module load.
Registry modification.
Click OK to save the changes and close the Rule properties window.
The new exclusion is created and displayed in the list of exclusions.
If you need to export the exclusion list to an XML file, click the Export button.
If you need to import the exclusion list from an XML file, click the Import button.
If you need to modify an exclusion, click the Modify button.
If you need to delete an exclusion from the list, select the exclusion and click the Delete button.
If you are configuring the policy settings, make sure that the switch in the upper right corner of the group of settings is turned on.