Limitations

Known limitations of Kaspersky Anti Targeted Attack Platform

Kaspersky Anti Targeted Attack Platform 7.1.1 and 7.1.2 has the following known limitations:

  1. Sigma rules relying on data sources other than System Monitor (Sysmon) and Windows Event Log are not supported.
  2. Correlation Sigma rules are not supported.
  3. As part of integration with the NDR functional block, up to 2000 Endpoint Agent components can be connected to a single Central Node component.
  4. In a file alert created based on the results of scanning a copy of web traffic, the User name field is empty if the user is authenticated on the proxy server with basic authentication.
  5. If the date on the Central Node server is over 30 days behind the current date, Kaspersky Anti Targeted Attack Platform cannot work. We recommend making sure that the current date is set on the server on which you want to install the application component.
  6. For the solution to work correctly, the minimum value of payload size per packet (maximum transmission unit, MTU) for the link between the Central Node and Sensor servers, as well as the PCN and SCN, must be 1500. If you know that your ISP limits the MTU on the links between the solution components, you need to configure the MTU so that its size does not exceed the value allowed by your ISP.
  7. When checking the reputation of a file in Kaspersky Security Network, information about the vendor of the trusted signature is not recorded in the log.
  8. Kaspersky Anti Targeted Attack Platform correctly processes ERSPAN traffic received through the virtual interface at a rate of up to 2 Gbps. A higher rate of ERSPAN traffic results in data loss.

Kaspersky Anti Targeted Attack Platform 7.1 has the following known limitations:

  1. Sigma rules relying on data sources other than System Monitor (Sysmon) and Windows Event Log are not supported.
  2. Correlation Sigma rules are not supported.
  3. As part of integration with the NDR functional block, up to 2000 Endpoint Agent components can be connected to a single Central Node component.
  4. In a file alert created based on the results of scanning a copy of web traffic, the User name field is empty if the user is authenticated on the proxy server with basic authentication.
  5. If the date on the Central Node server is over 30 days behind the current date, Kaspersky Anti Targeted Attack Platform cannot work. We recommend making sure that the current date is set on the server on which you want to install the application component.
  6. For the solution to work correctly, the minimum value of payload size per packet (maximum transmission unit, MTU) for the link between the Central Node and Sensor servers, as well as the PCN and SCN, must be 1500. If you know that your ISP limits the MTU on the links between the solution components, you need to configure the MTU so that its size does not exceed the value allowed by your ISP.
  7. When checking the reputation of a file in Kaspersky Security Network, information about the vendor of the trusted signature is not recorded in the log.
  8. Kaspersky Anti Targeted Attack Platform correctly processes ERSPAN traffic received through the virtual interface at a rate of up to 2 Gbps. A higher rate of ERSPAN traffic results in data loss.
  9. Upgrading the Central Node installed on a server may fail with the "Upgrade task "(MoveVolumesDataTask)" completed with an error" error if a disk of 2 TB or larger is allocated for the Targeted Attack Analyzer component database.

    Resolving the "Upgrade task "(MoveVolumesDataTask)" completed with an error" error

  10. For the Central Node component installed on an Astra Linux server to work correctly, more free disk space is required compared to version 7.0.3 of the application. If there is not enough free space on the Central Node server, the upgrade fails. The application, however, remains operational.

    You can free up disk space. For details, see the Upgrading Central Node installed on a server section.

Limitations of Kaspersky Endpoint Security 12.9 for Windows

You can view the list of limitations of Kaspersky Endpoint Security 12.9 for Windows in the Kaspersky Endpoint Security for Windows Online Help.

Limitations of Kaspersky Endpoint Security 12.2 for Linux

You can view the list of limitations of Kaspersky Endpoint Security 12.2 for Linux in the Kaspersky Endpoint Security for Linux Release Notes.

Limitations of Kaspersky Endpoint Security 12.1 for Mac

You can view the list of limitations of Kaspersky Endpoint Security 12.1 for Mac in the Kaspersky Endpoint Security for Mac Online Help.

See also

About Kaspersky Anti Targeted Attack Platform

What's new

Using Kaspersky Threat Intelligence Portal

Distribution kit

Hardware and software requirements

Page top