After you configure integration between Kaspersky Next XDR Expert and Kaspersky Anti Targeted Attack Platform, you can perform response actions on a device or with a file hash in one of the following ways:
This option is available for the Add prevention rule response action.
You can also configure the response action to run automatically when creating or editing a playbook.
To perform response actions through Kaspersky Anti Targeted Attack Platform, you must have one of the following XDR roles: Main administrator, Tenant administrator, Junior analyst, Tier 1 analyst, Tier 2 analyst.
Performing response actions from alert or incident details
To perform a response action from the alert or incident details:
You can select several devices, if necessary.
If you select this response action for a device on which network isolation is already enabled, the parameters are overwritten with new values.
After you select this response action, you must configure the necessary settings in the window that opens on the right side of the screen.
You can select this response action for devices on which network isolation is enabled.
The executable file is always run on behalf of the system and must be available on the device before you start the response action.
After you select this response action, you must configure the necessary settings in the window that opens on the right side of the screen.
After you select this response action, you must configure the necessary settings in the window that opens on the right side of the screen.
You can select this response action for devices on which the prevention rule was applied.
All of the listed response actions are available on devices that use Kaspersky Endpoint Agent for Windows or Kaspersky Endpoint Security for Windows in the role of the Endpoint Agent component. On devices with Kaspersky Endpoint Agent for Linux and Kaspersky Endpoint Security for Linux, the only available response action is Run executable file.
If the response action is completed successfully, an appropriate message is displayed on the screen. Otherwise, an error message is displayed.
Performing response actions from the device details
To perform a response action from the device details:
If the response action is completed successfully, an appropriate message is displayed on the screen. Otherwise, an error message is displayed.
Performing a response action from the event details
This option is available for the Add prevention rule response action.
To perform a response action from the event details:
You can also go to the Observables tab, select check box next to the file hash that you want to block, and then click the Add prevention rule button.
If the response action is completed successfully, an appropriate message is displayed on the screen. Otherwise, an error message is displayed.
Performing response actions from an investigation graph
This option is available if the investigation graph is built.
To perform a response action from an investigation graph:
The investigation graph opens.
If the response action is completed successfully, an appropriate message is displayed on the screen. Otherwise, an error message is displayed.
If you encounter a failure when running the response actions, you have to make sure that the device name in Kaspersky Next XDR Expert is the same as in Kaspersky Anti Targeted Attack Platform.
Page top