In the Kaspersky Security Center Administration Console tree, select the Policies folder.
Select the necessary policy and double-click to open the policy properties.
In the policy properties window, select Real-Time Computer Protection.
In the Behavior Detection section, click Settings.
Select or clear the Behavior Detection check box to enable or disable the component.
Go to the General tab.
Use the Enable protection of local folders against external encryption check box to enable or disable the option. If this check box is selected, Kaspersky Embedded Systems Security responds to malicious activity with the action specified below.
Select the relevant action in the Action on malware activity detection block:
Delete. If this item is selected, on detecting malicious activity Kaspersky Embedded Systems Security deletes the executable file of the malicious application and creates a backup copy of the file in Backup.
Block. If this item is selected, on detecting malicious activity Kaspersky Embedded Systems Security terminates this application.
Inform. If this item is selected and malware activity of an application is detected, Kaspersky Embedded Systems Security adds information about the malware activity of the application to the list of active threats.
Save your changes. To apply the policy on computers, close the locks .
In the main window of the Web Console, select Assets (Devices) → Policies & profiles.
Click the name of the Kaspersky Embedded Systems Security policy.
The policy properties window opens.
Select the Application settings tab.
Go to Real-Time Computer Protection → Behavior Detection and click the Configure button.
The Behavior Detection window opens.
Use the Enable Behavior Detection check box to enable or disable the component.
Go to the General tab.
Use the Enable protection of local folders against external encryption check box to enable or disable the option. If this check box is selected, Kaspersky Embedded Systems Security responds to malicious activity with the action specified below.
Select the relevant action in the Upon detection of external encryption of shared folders block:
Delete. If this item is selected, on detecting malicious activity Kaspersky Embedded Systems Security deletes the executable file of the malicious application and creates a backup copy of the file in Backup.
Block. If this item is selected, on detecting malicious activity Kaspersky Embedded Systems Security terminates this application.
Inform. If this item is selected and malware activity of an application is detected, Kaspersky Embedded Systems Security adds information about the malware activity of the application to the list of active threats.
Save your changes. To apply the policy on computers, close the locks .
In the Kaspersky Embedded Systems Security Console tree, select Real-Time Computer Protection → Behavior Detection.
In the results pane of the Behavior Detection node, click Properties.
This opens the Properties:Behavior Detection window.
Select the Behavior Detection check box.
Go to the General tab.
Use the Enable protection of local folders against external encryption check box to enable or disable the option. If this check box is selected, Kaspersky Embedded Systems Security responds to malicious activity with the action specified below.
Select the relevant action in the Upon detection of external encryption of shared folders block:
Delete. If this item is selected, on detecting malicious activity Kaspersky Embedded Systems Security deletes the executable file of the malicious application and creates a backup copy of the file in Backup.
Block. If this item is selected, on detecting malicious activity Kaspersky Embedded Systems Security terminates this application.
Inform. If this item is selected and malware activity of an application is detected, Kaspersky Embedded Systems Security adds information about the malware activity of the application to the list of active threats.