Configuring KATA integration

Endpoint Detection and Response (KSC) and Endpoint Detection and Response Expert (on-premise) components are not compatible with each other.

The following conditions must be satisfied for integration of the Kaspersky Industrial CyberSecurity for Nodes built-in agent with KATA:

To integrate the Endpoint Agent configuration with KATA in the corporate IT infrastructure, the following must be deployed:

Setting up KATA Integration involves the following steps:

  1. Installing the Endpoint Detection and Response Expert (on-premise) component

    In installation package settings or in the Setup Wizard, or by changing the set of application components in the Windows Control Panel, at the step when you must select application components for installation, select the following:

    • Full functionalityEndpoint AgentEndpoint Detection and Response Expert (on-premise) for the built-in agent
    • Endpoint AgentEndpoint Detection and Response Expert (on-premise) for the Endpoint Agent configuration

    To finish changing the set of application components, you must restart the computer.

  2. Endpoint Detection and Response Expert (on-premise) activation

    You need to purchase a separate license for KATA (for example, Kaspersky Endpoint Detection and Response (KATA) Add-on).

    Licensing of the stand-alone Endpoint Detection and Response Expert (on-premise) functionality is the same as the licensing of Kaspersky Industrial CyberSecurity for Nodes. The feature becomes available after you add a separate key for Kaspersky Endpoint Detection and Response (KATA). As a result, two keys will be added on the computer: a key for Kaspersky Industrial CyberSecurity for Nodes and a key for Endpoint Detection and Response Expert (on-premise).

    Make sure that the Endpoint Detection and Response Expert (on-premise) functionality is included in the license.

  3. Connecting to Central Node

    For Kaspersky Anti Targeted Attack Platform, you can establish a trusted connection between Kaspersky Industrial CyberSecurity for Nodes and the Central Node component. To configure a trusted connection, you must use a TLS certificate. You can get a TLS certificate in the Kaspersky Anti Targeted Attack Platform console (see instructions in the Kaspersky Anti Targeted Attack Platform Help). Then you must add the TLS certificate to Kaspersky Industrial CyberSecurity for Nodes (see instructions below).

    By default, Kaspersky Industrial CyberSecurity for Nodes only checks the TLS certificate of Central Node. To make the connection more secure, you can additionally enable the additional verification of the computer on Central Node. To enable this verification, you must turn on two-way authentication in Central Node and Kaspersky Industrial CyberSecurity for Nodes settings. To use two-way authentication, you will also need a crypto-container. A crypto-container is a PFX archive with a certificate and a private key. You can get a crypto-container in the Kaspersky Anti Targeted Attack Platform console (see instructions in the Kaspersky Anti Targeted Attack Platform Help).

    How to connect a Kaspersky Industrial CyberSecurity for Nodes computer to Central Node using the Kaspersky Security Center Administration Console

    How to connect a Kaspersky Industrial CyberSecurity for Nodes computer to Central Node using the Application Console

    How to connect a Kaspersky Industrial CyberSecurity for Nodes computer to Central Node using the Kaspersky Security Center Web Console

    As a result, the Kaspersky Industrial CyberSecurity for Nodes computer is added using the Kaspersky Anti Targeted Attack Platform console.

Page top