Extended telemetry for IOC Scan

We recommend enabling extended telemetry on the computer for retrospective IOC scanning. Extended telemetry improves the accuracy of IOC detection, but uses more resources of the computer.

Extended telemetry includes the support of the following additional terms:

If extended telemetry is disabled, Kaspersky Endpoint Security may rotate the information about detected indicators of compromise.

To enable extended telemetry:

  1. In the main window of the Web Console, select Assets (Devices)Policies & profiles.
  2. Click the name of the Kaspersky Endpoint Security policy.

    The policy properties window opens.

  3. Select the Application settings tab.
  4. Go to Built-in Agents ConfigurationEndpoint Detection and Response.
  5. Select the Enable advanced system activity logging check box.
  6. Save your changes.
Page top