Kaspersky Endpoint Detection and Response (KATA) is a component of the Kaspersky Anti Targeted Attack Platform solution. Integration with the Kaspersky Endpoint Detection and Response (KATA) component is facilitated by a Kaspersky Endpoint Security component: Endpoint Detection and Response (KATA) (EDR (KATA)).
Kaspersky Endpoint Security is compatible with the Kaspersky Anti Targeted Attack Platform solution, which is designed to protect the IT infrastructure of organizations and promptly detect threats, such as zero-day attacks, targeted attacks, and advanced persistent threats (APT). To read more, check out the Kaspersky Anti Targeted Attack Platform Help.
This feature is not supported in the KESL container.
When interacting with Kaspersky Endpoint Detection and Response (KATA), Kaspersky Endpoint Security can:
For integration with Kaspersky Endpoint Detection and Response (KATA), the Behavior Detection component must be enabled.
Integration of the Kaspersky Endpoint Security application with Kaspersky Endpoint Security and Response (KATA) is possible only if the Behavior Detection component is enabled. Otherwise, the required telemetry data cannot be transmitted.
Kaspersky Endpoint Detection and Response (KATA) can additionally use data received from the following components:
When integrated with Kaspersky Endpoint Detection and Response (KATA), devices with Kaspersky Endpoint Security establish secure connections to the KATA server via the HTTPS protocol. To ensure a secure connection, the following certificates issued by the KATA server are used:
Certificates for securing the connection to the KATA server are provided by the Kaspersky Anti Targeted Attack Platform administrator.
A proxy server is used to connect to the KATA server if use of a proxy server is configured in the general application settings of Kaspersky Endpoint Security.
By default, the Kaspersky Endpoint Detection and Response (KATA) Integration is disabled. You can enable or disable the integration, and configure the following integration settings via the command line, Web Console, and Administration Console:
If integration between Kaspersky Endpoint Security and Kaspersky Managed Detection and Response is enabled, process exclusions are not applied when sending telemetry.
Managing Kaspersky Endpoint Detection and Response (KATA) Integration settings in Kaspersky Security Center Cloud Console is not supported.