Kaspersky Endpoint Agent

Adding Threat Response actions to the action list of the current policy

November 17, 2023

ID 193081

Expand all | Collapse all

To add Threat Response actions to the list of actions of the current policy:

  1. Open Kaspersky Security Center Administration Console.
  2. In the console tree, open the Policies folder.
  3. Select Kaspersky Endpoint Agent policy and open its properties window in one of the following ways:
    • Double-click the policy name.
    • Select Properties in the policy context menu.
    • Select the Configure policy settings item in the right part of the window.
  4. In the Kaspersky Sandbox integration section select the Threat Response subsection.
  5. In the Actions group of settings, select the Take response actions on threats detected by Kaspersky Sandbox check box, if it has not already been selected.
  6. Click Add and select one of the following actions in the drop-down list:
    • Quarantine and delete
    • Notify device user
    • Run Endpoint Protection Platform scan of critical areas on the device
    • Run IOC Scan on a managed group of devices
    • Quarantine and delete when IOC is found
    • Run Endpoint Protection Platform scan of critical areas on the device when IOC is found

    The action has been added to the Selected actions list.

    When configuring threat response actions, keep in mind that as a result of some actions, the object containing the threat may be deleted from the workstation where it was detected.

  7. To remove an action, select it in the table and click Remove.
  8. In the upper right corner of the settings group, change the switch from Policy not enforced to Under policy.
  9. Click Apply and OK.

See also

Enabling and disabling Threat Response actions

Configuring authentication on the Administration Server for Autonomous IOC Scan tasks

Device protection from legitimate applications that can be used by cybercriminals

Configuring start of Autonomous IOC Scan tasks

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.