Configuring Threat Response actions of Kaspersky Endpoint Agent to respond to threats detected by Kaspersky Sandbox

Kaspersky Endpoint Agent can perform actions in response to threats detected by Kaspersky Sandbox.

You can configure the following types of actions:

Local actions:

Group actions:

To configure group threat response actions, set up the permissions of Kaspersky Security Center users, whose accounts you want use for managing IOC Scan tasks.

When configuring threat response actions, keep in mind that as a result of some actions, the object containing the threat may be deleted from the workstation where it was detected.

See also

Configuring Kaspersky Endpoint Agent security settings

Configuring Kaspersky Endpoint Agent connection settings to a proxy server

Configuring Kaspersky Security Center as a proxy server for Kaspersky Endpoint Agent activation

Configuring KSN and KMP usage in Kaspersky Endpoint Agent

Configuring the integration of Kaspersky Endpoint Agent with Kaspersky Sandbox

Configuring integration between Kaspersky Endpoint Agent and KATA Central Node

Configure network isolation settings

Configuring quarantine settings in Kaspersky Endpoint Agent

In this Help section

Enabling and disabling Threat Response actions

Adding Threat Response actions to the action list of the current policy

Authentication for Threat Response group tasks on the Administration Server

Device protection from legitimate applications that can be used by cybercriminals

Configuring start of Autonomous IOC Scan tasks

Page top