Critical

Expand all | Collapse all

License expired

License has almost expired

Databases are missing or corrupted

Databases are extremely out of date

Application autorun is disabled

Activation error

Active threat detected. Advanced Disinfection should be started

KSN servers unavailable

Not enough space in Quarantine storage

Object not restored from Quarantine

Object not deleted from Quarantine

The application established a connection to a website with an untrusted certificate

Failed to verify an encrypted connection. The domain is added to the list of exclusions

Malicious object detected (local bases)

Malicious object detected (KSN)

Disinfection impossible

Cannot be deleted

Processing error

Process terminated

Unable to terminate process

Dangerous link blocked

Dangerous link opened

Previously opened dangerous link detected

Process action blocked

Keyboard not authorized

AMSI request was blocked

Network activity blocked

Network attack detected

Application startup prohibited

Prohibited process was started before Kaspersky Endpoint Security startup

Access denied (local bases)

Access denied (KSN)

Operation with the device prohibited

Network connection blocked

Error updating component

Error distributing component updates

Local update error

Network update error

Cannot start two tasks at the same time

Error verifying application databases and modules

Error in interaction with Kaspersky Security Center

Not all components were updated

Update completed successfully, update distribution failed

Internal task error

Patch installation failed

Patch rollback failed

Error applying file encryption / decryption rules

File encryption / decryption error

File access blocked

Error enabling portable mode

Error disabling portable mode

Error creating encrypted package

Error encrypting / decrypting device

Could not load encryption module

The task for managing Authentication Agent accounts ended with an error

Policy cannot be applied

FDE upgrade failed

FDE upgrade rollback failed (for more information, please refer to the Kaspersky Endpoint Security for Windows Online Help)

Kaspersky Anti Targeted Attack Platform server unavailable

Failed to delete object

Object not quarantined (Sandbox)

An internal error occurred

Invalid Sandbox server certificate

The Sandbox node is unavailable

Failed to process the object in Sandbox

Maximum load to Sandbox is exceeded

IOC found

Sandbox license verification failed

Failed to submit the scan task to Sandbox by a user

Error creating Sandbox task

Object startup blocked

Process startup blocked

Script execution blocked

Object not quarantined (Endpoint Detection and Response)

Process startup is not blocked

Object is not blocked

Script execution is not blocked

Error changing application components

There are patterns of a possible brute-force attack in the system

There are patterns of a possible Windows Event Log abuse

Atypical actions detected on behalf of a new service installed

Atypical logon that uses explicit credentials detected

There are patterns of a possible Kerberos forged PAC (MS14-068) attack in the system

Suspicious changes detected in the privileged built-in Administrators group

There is an atypical activity detected during a network logon session

Log Inspection rule triggered

Atypical event occurs too often. Event aggregation started

Report on an atypical event for the aggregation period

Error connecting to the Kaspersky Anti Targeted Attack Platform server

Invalid certificate of the Kaspersky Anti Targeted Attack Platform server

Invalid certificate of the agent on the Kaspersky Anti Targeted Attack Platform server

Your device is connected to an untrusted Administration Server. Contact the administrator

File or folder change was detected

Object changes too often. Event aggregation started

Report on object modification for the aggregation period

Monitoring scope includes incorrect objects

Registry change was detected

Device connection / disconnection is detected

Monitoring scope includes incorrect objects

Attempts to perform the restricted operations with the object is too many. Event aggregation started

An operation with the files of the monitoring scope was blocked

Registry modification blocked

Processing error

System Integrity Monitoring: rule triggering disabled for user accounts without matching security identifier (SID)

Application Control: rule triggering disabled for user accounts without matching security identifier (SID)

Device Control: rule triggering disabled for user accounts without matching security identifier (SID)

Web Control: rule triggering disabled for user accounts without matching security identifier (SID)

Adaptive Anomaly Control: rule triggering disabled for user accounts without matching security identifier (SID)

Log Inspection: rule triggering disabled for user accounts without matching security identifier (SID)

Unable to connect to the Integration Server for more than 6 hours. Check Integration Server status and network settings

SVM is unavailable

Malicious object detected. Advanced Disinfection should be started on a virtual machine template

Page top