Enabling Anomaly Detection using Sigma Rules
To enable Anomaly Detection using Sigma rules:
- Do one of the following:
- for a group of protected devices, open the application policy properties window.
- In the main Kaspersky Security Center Web Console window select Devices → Policies and profiles.
- Select the policy you want to configure.
- In the <Policy name> window that opens, select the Application settings tab.
- for an individual protected device, open the application settings for the device.
- In the main Kaspersky Security Center Web Console window select Devices → Managed devices.
- Select the device for which you want to configure application settings.
- In the <Device name> window that opens, select the Applications tab.
- Select Kaspersky Endpoint Agent.
- In the Kaspersky Endpoint Agent window that opens, select the Application settings tab.
- In the Anomaly Detection using Sigma rules section, select the Enable Anomaly Detection using Sigma rules check box.
- Add one or more collections of Sigma rules.
- Click the Save button.
Kaspersky Endpoint Agent will search for anomalies using the enabled collections of Sigma rules.
Page top