Kaspersky Endpoint Agent

Configuring Threat Response actions of Kaspersky Endpoint Agent to respond to threats detected by Kaspersky Sandbox

November 17, 2023

ID 200590

Expand all | Collapse all

Kaspersky Endpoint Agent can perform actions in response to threats detected by Kaspersky Sandbox.

You can configure the following types of actions:

  • Local actions
  • Group actions

When configuring threat response actions, keep in mind that as a result of some actions, the object containing the threat may be deleted from the workstation where it was detected.

If you want Kaspersky Endpoint Agent to create Autonomous IOC Scan tasks when responding to threats, configure authentication on the Administration Server.

The application uses a special Administration Server user account, which has limited permissions and is only intended for creating Autonomous IOC Scan tasks.

The special account can only be created in the Threat Response window in Kaspersky Endpoint Agent policy properties or in the application properties of an individual device. The special account must be created on the Administration Server only once and its password must be used to configure Threat Response settings in the properties of other devices or other policies of the same Administration Server.

It is not possible to change the password of the special account created for Autonomous IOC Scan tasks. If you forget the password of this account, delete it using standard Kaspersky Security Center tools and create it again in the Threat Response window.

To configure Kaspersky Endpoint Agent's actions in response to threats detected by Kaspersky Sandbox:

  1. Do one of the following:
    • Open the application properties window for an individual device.
    • Open the policy properties window.
  2. In the Kaspersky Sandbox integration section select the Threat Response subsection.
  3. Select the Take response actions on threats detected by Kaspersky Sandbox check box.
  4. In the Selected actions list, select the check boxes for the actions you want to enable.
  5. If you select the Run IOC Scan on a managed group of devices action, perform the following actions in the Authentication on Administration Server group of settings:
    1. Click the Create the Administration Server special user button.

      The unavailability of the Create the Administration Server special user button indicates that a special account for the Autonomous IOC Scan tasks has already been created. Go to the step "d" of the instruction.

    2. In the window that opens, in the Administration Server password field, specify a password with a length of 8–16 characters and click the Create the user button.
    3. Click OK.

      A special Administration Server account for Autonomous IOC Scan tasks will be created.

    4. In the Administration Server password field, enter the password for the special account created for Autonomous IOC Scan tasks.
  6. If you configure the policy settings, in the upper right corner of the group of settings, change the switch from Undefined to Enforce.
  7. Click OK.
  8. In the policy properties window, click Save.

Kaspersky Endpoint Agent's actions in response to threats detected by Kaspersky Sandbox are now configured and ready to be applied on devices.

See also

Enabling and disabling integration with Kaspersky Sandbox

Configuring trusted connection on Kaspersky Endpoint Agent side

Adding Kaspersky Sandbox servers to Kaspersky Endpoint Agent list

Configuring the response timeout of Kaspersky Sandbox and request queue settings

Enabling detection of legitimate applications that can be used by cybercriminals

Configuring IOC Scan tasks start

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.