Configuring EDR (KATA) execution prevention for objects.
If integration with the Kaspersky Endpoint Detection and Response Expert (on-premise) solution or the Kaspersky Endpoint Detection and Response (KATA) component is enabled, you can enable or disable execution prevention for objects in the policy properties (Application settings → Detection and Response → Endpoint Detection and Response (KATA)).
The Execution prevention toggle switch under Execution prevention enables or disables execution prevention rules of the EDR (KATA) component.
Configuring EDR Optimum execution prevention for objects.
If integration with Kaspersky Endpoint Detection and Response Optimum is enabled, you can enable or disable object execution prevention and configure object execution prevention rules of the EDR Optimum component:
Object execution prevention cannot be enabled or disabled in the device properties if a policy is applied to the device.
Settings of EDR Optimum execution prevention for objects.
|
Setting |
Description |
|---|---|
|
Execution prevention for objects is enabled/disabled |
Enables or disables EDR Optimum rules for execution prevention for objects. By default, rules are not applied. |
|
Action when starting or opening an object |
You can select the mode of object execution prevention:
|
|
List of object execution prevention rules. |
The Add link opens a window in which you can configure an object execution prevention rule of the EDR Optimum component. If necessary, you can remove a rule from the list by clicking the Delete button. |
To add a rule to the list of object execution prevention rules of the EDR Optimum component:
You can enable or disable the created rule at any time.
If you select the wrong object type, the application will be unable to block the file or script.
To specify a path to an object, select Use path and enter the path to the object.
To specify an object checksum, select the SHA256 or MD5 option and enter the object checksum.
The created rule is added to the list of rules in the Execution prevention for objects settings block.