Viewing the table of objects quarantined on computers with the Kaspersky Endpoint Agent component
The table of objects quarantined on computers with the Endpoint Agent component can be found in the Storage section, Quarantine subsection of the application web interface.
The Kaspersky Anti Targeted Attack Platform server stores metadata of objects quarantined on computers with the Endpoint Agent component. The objects themselves are kept in special storage on each computer where the threatening object was detected.
The table of objects quarantined on computers with the Endpoint Agent component contains the following information:
Object—Information about the object. For example, the file name or file path.
Source—IP address or host name of the computers with the Endpoint Agent component where the object is quarantined.
Time stored—Date and time when the object was quarantined.
State—State of the object.
The right part of the object information row contains buttons:
You can click to delete the metadata of the object on the Kaspersky Anti Targeted Attack Platform server.
You can click to restore the object from Quarantine on a computer the Endpoint Agent component.
You can click to copy the object from Quarantine on the computer with the Endpoint Agent component to the Kaspersky Anti Targeted Attack Platform server.
Clicking the link with the file name or file path opens a list in which you can select one of the following actions:
Filter by this value.
Exclude from filter.
Download.
Send file for scanning.
Find events:
File path
MD5
SHA256
Find alerts:
File path
MD5
SHA256
Copy value to clipboard.
Clicking the link with the host name opens a list in which you can select one of the following actions: