Configuring Anti-Cryptor in the Web Console

In the Web Console, you can configure Anti-Cryptor settings in the policy properties (Application settings Advanced Threat Protection Anti-Cryptor).

Anti-Cryptor component settings

Setting

Description

Anti-Cryptor protection enabled / disabled

This toggle switch enables or disables the protection of files in the local directories with network access by SMB/NFS protocols from remote malicious encrypting.

The toggle button is switched off by default.

Protection scopes

Clicking the Configure protection scope link opens the Protection scopes window.

Action on encryption detection

The action to be performed by Kaspersky Endpoint Security upon detecting malicious encryption:

  • Inform user. Kaspersky Endpoint Security does not block the device performing encryption; it only records in the event log an event about the detection of malicious encryption.
  • Block the device performing encryption (default value).

Block untrusted host for (min.)

In this field you can specify the untrusted device blocking duration in minutes.

If a compromised host is blocked and you change this setting value, the blocking time for this host will not change. The blocking time is not a dynamic value, and it is calculated at the moment of blocking.

Available values: integer from 1 to 4294967295.

Default value: 30.

Exclusions

Clicking the Configure exclusions link opens the Exclusion scopes window.

Exclusions by mask

Clicking the Configure exclusions by mask link opens the Exclusions by mask window.

Page top