By default, the Behavior Detection component starts when Kaspersky Endpoint Security starts and monitors the malicious activity of the applications in the operating system. When malicious activity is detected, Kaspersky Endpoint Security can terminate the process of the application that performs malicious activity.
This feature is not supported in the KESL container.
Behavior Detection component settings
Setting |
Description |
---|---|
Enable Behavior Detection |
This check box enables or disables the Behavior Detection component. The check box is selected by default. |
Behavior Detection component operating mode |
The action to be performed by Kaspersky Endpoint Security upon detecting malicious activity in the operating system:
|
Use exclusions by process |
This check box enables or disables exclusions by process in the operation of the Behavior Detection component. This check box is cleared by default. The Configure button opens the Exclusions by process window. In this window, you can exclude the activity of processes. |