To create an IOC Scan task from the incident card:
The default settings of the IOC Scan tasks created from the incident card are described in the following table. You can change these values in the settings of the created task.
Default settings of the IOC Scan task created from the incident card
Parameter |
Default value |
Description |
---|---|---|
Settings on the Schedule tab |
||
Run by schedule |
Selected. |
The task is started according to the schedule, with the specified settings. |
Frequency |
At the specified time |
The task is started once, at the specified date and time. |
Start time |
15 minutes after the task's creation. |
The task is started at the specified time. |
Start date |
Task creation date. |
The task is started at the specified date. |
Quit task, running longer than |
Selected. The default value is one hour. |
The application quits the task once the specified time elapses after the task is started, regardless of the task execution progress. |
Cancel schedule |
Not selected. |
Automatic cancellation of the task start schedule is not used. |
Run missed tasks |
Selected. |
The application restarts a task that was not started by the schedule for some reason. For example, if Kaspersky Endpoint Agent was not running at the scheduled task start time. |
Randomize the task start time within the interval |
Selected. The default value is 10 minutes. |
The task will start at an arbitrary time within the specified interval, with the interval beginning at the time specified in the Start time field. |
Settings in the Advanced section |
||
Select IOC documents for which data is collected
|
When analyzing data on files (FileItem), the Analyze file data (FileItem) option is selected. In the additional settings of the IOC document, in the Search for indicators of compromise in the following areas group of settings, the Critical areas on device option is selected. |
The application checks critical areas on the device, as well as the folder where the dangerous object was initially detected. The following areas are considered critical:
|
When analyzing data in the Windows registry (RegistryItem), the Analyze Windows registry (RegistryItem) option is selected. |
The application checks the paths of user-defined registry keys. |
By default, Kaspersky Endpoint Agent 3.9 uses the settings specified in the Integration with Kaspersky Sandbox section, in the Threat response group of settings, for IOC Scan tasks created from the incident card. For detailed information refer to Kaspersky Sandbox Help.
Page top