Kaspersky Sandbox
- Kaspersky Sandbox Online Help
- About the Kaspersky Sandbox solution
- About the Kaspersky Sandbox application
- What's New
- Distribution kit
- Hardware and software requirements
- Limitations of the current version
- Application licensing
- About the license
- About the End User License Agreement
- About the license certificate
- About the subscription
- About the key
- About the key file
- About the activation code
- Viewing license information in the web interface
- Viewing the text of the End User License Agreement and the Privacy Policy in the web interface
- Activating the application using the web interface
- Activating the application using Kaspersky Security Center Web Console
- Application modes based on the license
- About data provision
- Installing and performing initial configuration of the solution
- Preparing the IT infrastructure for Kaspersky Sandbox installation
- Setting up Kaspersky Sandbox for virtual infrastructure
- Installing and configuring applications of the solution when using EPP applications with built-in Kaspersky Sandbox support
- Installing and configuring applications of the solution when using EPP applications without built-in Kaspersky Sandbox support
- Installing the Kaspersky Sandbox application
- Verifying the digital signature
- Step 1. Starting installation of the Kaspersky Sandbox application and selecting the language for viewing End User License Agreements
- Step 2. Viewing the Kaspersky Sandbox End User License Agreement and the Privacy Policy
- Step 3. Viewing the Microsoft End User License Agreement
- Step 4. Viewing the Adobe End User License Agreement
- Step 5. Basic setup of Kaspersky Sandbox
- Step 6. Completing the installation of Kaspersky Sandbox.
- Scaling Kaspersky Sandbox
- Getting started with Kaspersky Sandbox
- Managing the Kaspersky Sandbox application using the web interface
- Initial configuration of the application
- Monitoring of application operation
- Information about self diagnostics of the application in Kaspersky Sandbox web interface
- Information about database update state in Kaspersky Sandbox web interface
- Information about the application activation state and the license validity period in the Kaspersky Sandbox web interface
- Configuring the data display period on the widget in the Kaspersky Sandbox web interface
- Monitoring the processing of objects received from Kaspersky Endpoint Security in the Kaspersky Sandbox web interface
- Database update
- Configuring network interfaces
- Configuring integration with Kaspersky Security Center
- Creating a TLS certificate of Kaspersky Sandbox web interface
- Setting the date and time
- Installing and configuring images of operating systems and software required for the operation of Kaspersky Sandbox
- Managing the cluster
- Creating a new cluster
- Limitations that apply when adding servers to the cluster
- Viewing the server table of the cluster
- Monitoring the status of servers in the cluster
- Adding a server to the cluster
- Removing a server from a cluster
- Deleting the cluster
- Modifying the IP address of a server that is part of a cluster
- Downloading Kaspersky Sandbox system log to the hard drive
- Restarting Kaspersky Sandbox server
- Shutdown of Kaspersky Sandbox server
- Changing Kaspersky Sandbox administrator account password
- Managing Kaspersky Sandbox using Kaspersky Security Center Web Console
- Installing the Kaspersky Sandbox management web plug-in
- Configuring Kaspersky Sandbox device status display
- Kaspersky Sandbox event configuration
- Getting started with Kaspersky Sandbox in Kaspersky Security Center Web Console
- Viewing information about Kaspersky Sandbox and the database update status
- Going to the Kaspersky Sandbox web interface
- Viewing Kaspersky Sandbox license information
- Displaying information about the Kaspersky Sandbox management web plug-in
- Viewing the threat report
- Monitoring the processing of objects received from Kaspersky Endpoint Security
- Managing Kaspersky Endpoint Security for Windows
- Getting started with Kaspersky Endpoint Security
- Configuring the proxy server connection
- Configuring the integration of Kaspersky Endpoint Security with Kaspersky Sandbox
- Managing stand-alone IOC scanning tasks
- Configuring Threat Response actions of Kaspersky Endpoint Security to respond to threats detected by Kaspersky Sandbox
- Configuring Quarantine settings
- Configuring data synchronization with the Administration Server
- Monitoring the results of sending objects for scanning by Kaspersky Sandbox and running IOC scanning tasks
- Managing Kaspersky Endpoint Agent for Windows
- Getting started with Kaspersky Endpoint Agent
- Configuring Kaspersky Endpoint Agent security settings
- Configuring the proxy server connection
- Configuring the usage of Kaspersky Security Network
- Configuring the integration of Kaspersky Endpoint Agent with Kaspersky Sandbox
- Configuring Threat Response actions of Kaspersky Endpoint Agent to respond to threats detected by Kaspersky Sandbox
- Enabling and disabling Threat Response actions for threats detected by Kaspersky Sandbox
- Adding Threat Response actions to the action list of the current policy
- Authentication for Threat Response group tasks at the Administration Server
- Enabling detection of legitimate applications that can be used by cybercriminals
- Configuring the running of IOC scanning tasks
- Configuring Quarantine settings and restoration of objects from Quarantine
- Configuring data synchronization with the Administration Server
- Managing Kaspersky Endpoint Agent tasks
- Interaction with external systems using the API
- Multitenancy
- Contacting the Technical Support Service
- Glossary
- Basic concepts of Kaspersky Security Center relevant to managing the solution using KSC
- Information about third-party code
- Trademark notices
Configuring an autonomous IOC scanning task
To configure the IOC scanning task:
- In the main window of Web Console, select the Devices → Tasks folder.
- This opens a list of tasks; in this list, select the IOC scanning task.
- Modify the following task settings:
- Task name.
- On the General tab, in the Task name field, enter the name of the task.
- Click Save.
- Storage duration of task results on the Administration Server.
- Go to the Settings tab.
- In the Notifications field, click Settings.
- In the Store in the Administration Server database for (days) field, enter the number of days during which the Administration Server must store the results of the task.
- Click Save.
- IOC scanning settings.
- Go to the Application settings tab.
- Select the IOC scan settings section.
- Select the Take response actions after an IOC is found.
- Select one or more Threat Response actions applied to IOC detections:
- Move copy to Quarantine, delete object. If this option is selected, Kaspersky Endpoint Security deletes the malicious object found on the computer. Before deleting the object, Kaspersky Endpoint Security creates a backup copy in case the object needs to be restored later. Kaspersky Endpoint Security moves the backup copy to Quarantine.
- Run scan of critical areas. If this option is selected, Kaspersky Endpoint Security runs the Critical Areas Scan task. By default, Kaspersky Endpoint Security scans the kernel memory, running processes, and disk boot sectors.
- Click Save.
- IOC scanning task schedule.
- Go to the Schedule tab.
- In the Run on a schedule list, select one of the following option for running the task on a schedule:
- Once.
The task is run once at the specified date and time.
- Every N minutes.
The task is run regularly with the specified interval in minutes, starting with the specified time on the day when the task is created.
By default, the task is run every 30 minutes starting from the current system time.
- Every N hours.
The task is run regularly with the specified interval in hours, starting with the specified date and time.
By default, the task is run every six hours starting from the current system date and time.
- Every N days.
The task is run regularly with the specified interval in days. You can also specify the date and time when the task must be run for the first time.
By default, the task is run every day starting from the current system date and time.
- Weekly.
The task is run weekly on the specified day of the week and at the specified time.
- Monthly.
The task is run regularly, on specified days of each month, at the specified time.
By default, days of the month are not selected, and the default start time is 18:00:00.
- Once.
- If you want to modify advanced settings of the schedule, in the Advanced task properties section, you can select the following check boxes:
- If you want the application to run missed database update tasks at the earliest opportunity, select the Run missed tasks check box.
- If you want to prevent many workstations connecting to the Administration Server at the same time by running tasks randomly within a certain time frame rather than on a schedule, select the Use automatically randomized delay for task starts check box.
- If you want to prevent many workstations connecting to the Administration Server at the same time by running tasks randomly within a certain time frame rather than on a schedule:
- Select the Use random task start delay in the interval (min) check box.
- Enter the value of the interval.
- Click Save.
- Viewing IOC scanning task results.
- Go to the Application settings tab.
- Select the IOC scanning results section.
This opens the IOC scanning results table.
- Kaspersky Security Center user account that you want to use to run the task.
- Go to the Settings tab.
- In the Account field, click Settings.
- Select an account for running the task.
You can select the default account or create an account:
- If you select the default account, the task is run under the same account that was used to install and run the application that runs the task.
- If you choose to create an account, enter the credentials of the account to use for running the task. The account must have sufficient permissions to run the task.
- Click Save.
- Excluding host groups from task scope.
- Go to the Settings tab.
- In the Exclusions from task scope field, click Settings.
- Select device groups to which the task will not be applied.
You can only exclude groups that are subgroups of the administration group to which the task is applied.
- Task name.
- Save all changes.
The IOC scanning task is configured.
See also About autonomous IOC scanning tasks |