for Linux
For full functionality, the application, needs to intercept system events, namely file operations and process starts. If the application is not using system event interception, real-time file scanning is not performed, and the protection level of the device is diminished.
The settings are applied only on devices with operating systems that support the fanotify technology and where the application is being used in standard mode.
System Integrity settings
|
Settings |
OS |
Description |
|---|---|---|
|
Interception mechanism |
|
The system event interception mechanism that the application uses:
|
|
If the updatable kernel module fails to start |
|
Action that the application performs if the updatable kernel module fails to start:
This setting is available if the Updatable kernel module interception mechanism is selected. |
|
Telemetry source |
|
The source Kaspersky Endpoint Security uses for telemetry collection:
|
|
Operating mode for auditd |
|
In this mode, the auditd service records audit events for subsequent transmission to Detection and Response solutions:
|