Searching for indicators of compromise in the command line

You can scan for indicators of compromise using the IOC Scan task on the command line only when integrated with Kaspersky Endpoint Detection and Response Optimum. When integrated with Kaspersky Endpoint Detection and Response (KATA), the IOC scan is performed in the Kaspersky Endpoint Detection and Response (KATA) solution.

To create, configure, and run an IOC Scan task from the command line, run the following command:

kesl-control [-T] --scan-ioc --path <path to directory or file> [--process on|off] [--hint <regular expression>] [--arpentry on|off] [--ports on|off] [--system on|off] [--files on|off] [--drives all|system|critical|custom] [--excludes <list of exclusions>] [--scope <list of directories>] [--action Skip|QuarantineFile|IsolateHost|ScanCriticalAreas]

where:

Page top