Working with incident card
September 13, 2022
ID 200109
This Help provides information related to Kaspersky Endpoint Agent for Windows. This information may be partially or completely inapplicable to Kaspersky Endpoint Agent for Linux. For complete information about Kaspersky Endpoint Agent for Linux, please refer to the Help of the solution that includes the application: Kaspersky Anti Targeted Attack Platform or Kaspersky Managed Detection and Response.
The incident card is deleted automatically one month after it was created.
The incident card provides information required to analyze the incident, as well as perform actions in response to the incident.
The following information is displayed in the incident card:
- General incident information.
- Information about the protected device on which the incident occurred.
- Information about the object detected during the incident.
You can perform the following actions on the incident card:
- Isolate the device on which the incident occurred.
- Quarantine file.
- Prevent execution of file detected during the incident.
- Create an IOC Scan task.
You can also use the functionality for working with untrusted objects available in Endpoint Protection Platform applications. For example, can also use the standard Kaspersky Security Center Web Console tools to add a file to Kaspersky Endpoint Security for Windows Application Launch Control allow list or to send a file to Kaspersky experts for analysis. For details, refer to Kaspersky Endpoint Security for Windows Help.