Kaspersky Endpoint Security supports integration with the Kaspersky Endpoint Detection and Response component as part of the Kaspersky Anti Targeted Attack Platform solution. This solution is designed to promptly detect advanced threats, such as targeted attacks, advanced persistent threats, zero-day attacks, and others. For detailed information about how the solution works, please refer to the Kaspersky Anti Targeted Attack Platform Help.
When integration with Endpoint Detection and Response (KATA) is configured, the KATA server receives information about events that occur in the operation of Kaspersky Endpoint Security, threats discovered by the application, as well as information about processing these threats. To react to detected threats, Kaspersky Endpoint Security may then perform tasks started in the Kaspersky Anti Targeted Attack Platform web interface.
Endpoint Detection and Response (KATA) has the following additional requirements:
Kaspersky Anti Targeted Attack Platform 6.0 or later.
Kaspersky Security Center 14.2 or later.
Integration with Endpoint Detection and Response (KATA) can be configured in the Kaspersky Security Center Administration Console (MMC), Web Console, or Cloud Console.
Integration with Kaspersky Endpoint Detection and Response (KATA)
Integration with Kaspersky Endpoint Detection and Response (KATA) consists of the following steps:
Installing the Endpoint Detection and Response component
You can select the Endpoint Detection and Response component during installation of Kaspersky Endpoint Security.
Activating Endpoint Detection and Response
If the Endpoint Detection and Response component is not supported by your current license, you need to activate Kaspersky Endpoint Detection and Response separately.
You can check whether the Endpoint Detection and Response functionality is supported by the current license in the License window.
Connecting to a KATA server
Kaspersky Anti Targeted Attack Platform requires establishing a trusted connection between Kaspersky Endpoint Security and a KATA server. To configure a trusted connection, you need to use a TLS certificate. You can download a TLS certificate in the Kaspersky Anti Targeted Attack Platform web interface. For detailed information about downloading a certificate, please refer to the Kaspersky Anti Targeted Attack Platform Help.
By default, Kaspersky Endpoint Security checks the TLS certificate of only the KATA server. To make the connection more secure, you can enable two-way verification. To enable two-way verification, you need to use a password-protected crypto-container. For detailed information about downloading a crypto-container, please refer to the Kaspersky Anti Targeted Attack Platform Help.
Maximize the Administration Server<Server name> node.
In the console tree, click Managed devices.
In the workspace, select the Policies tab.
Right-click the policy you want to configure and choose Properties.
In the Properties window, select Detection and Response > Endpoint Detection and Response (KATA).
Select the Endpoint Detection and Response (KATA) checkbox.
Click Server connection settings.
In the Server connection settings window that opens, configure the following settings:
Click Add TLS certificate to select a TLS certificate that will be used to establish a trusted connection with a KATA server.
If you want to change the KATA server response timeout, specify the timeout in the Timeout (s) field. When the timeout runs out, Kaspersky Endpoint Security tries to connect to a different KATA server.
If you want to use two-way verification, select the Use two-way verification checkbox. Click Load crypto-container to select a crypto-container file and enter the password in the Crypto-container password field.
Click Save.
To add a KATA server, click Add.
In the KATA server window that opens, specify the server address and port and click Save.
In the main window of the Web Console, select Devices > Policies and profiles.
Click the name of the Kaspersky Endpoint Security for Mac policy.
The policy properties window opens.
Select the Application settings tab.
Select Detection and Response > Endpoint Detection and Response (KATA).
Turn on the Endpoint Detection and Response (KATA) toggle switch.
Click Server connection settings.
In the Server connection settings dialog that opens, configure the following settings:
Click Add TLS certificate to select a TLS certificate that will be used to establish a trusted connection with a KATA server.
If you want to change the KATA server response timeout, specify the timeout in the Timeout (s) field. When the timeout runs out, Kaspersky Endpoint Security tries to connect to a different KATA server.
If you want to use two-way verification, select the Use two-way verification checkbox. Click Load crypto-container to select a crypto-container file and enter the password in the Crypto-container password field.
Click OK.
To add a KATA server, click Add.
In the dialog that opens, specify the server address and port and click OK.
Save your changes.
As a result, computers will appear in the Kaspersky Anti Targeted Attack Platform web interface.