Kaspersky Anti Targeted Attack (KATA) Platform

Supported interpreters and processes

8 November 2023

ID 194900

Kaspersky Endpoint Agent application monitors the execution of scripts by the following interpreters:

  • cmd.exe
  • reg.exe
  • regedit.exe
  • regedt32.exe
  • cscript.exe
  • wscript.exe
  • mmc.exe
  • msiexec.exe
  • mshta.exe
  • rundll32.exe
  • runlegacycplelevated.exe
  • control.exe
  • explorer.exe
  • regsvr32.exe
  • wwahost.exe
  • powershell.exe
  • java.exe and javaw.exe (only if started with the –jar option)
  • InstallUtil.exe
  • msdt.exe
  • python.exe
  • ruby.exe
  • rubyw.exe

Information about the processes monitored by Kaspersky Endpoint Agent application is presented in the table below.

Processes and the file extensions that they open

Process

File extensions

winword.exe

rtf

doc

dot

docm

docx

dotx

dotm

docb

excel.exe

xls

xlt

xlm

xlsx

xlsm

xltx

xltm

xlsb

xla

xlam

xll

xlw

powerpnt.exe

ppt

pot

pps

pptx

pptm

potx

potm

ppam

ppsx

ppsm

sldx

sldm

acrord32.exe

pdf

wordpad.exe

docx

pdf

chrome.exe

pdf

MicrosoftEdge.exe

pdf

See also

Selecting a tenant to manage in the Endpoint Agents section

Viewing the table of hosts with the Endpoint Agent component

Viewing information about a host

Filtering and searching hosts with the Endpoint Agent component by host name

Filtering and searching hosts with the Endpoint Agent component that have been isolated from the network

Filtering and searching hosts with the Endpoint Agent component by PCN and SCN server names

Filtering and searching hosts with the Endpoint Agent component by computer IP address

Filtering and searching hosts with the Endpoint Agent component by operating system version on the computer

Filtering and searching hosts with the Endpoint Agent component by component version

Filtering and searching hosts with the Endpoint Agent component by their activity

Quickly creating a filter for hosts with the Endpoint Agent component

Resetting the filter for hosts with the Endpoint Agent component

Removing hosts with the Endpoint Agent component

Configuring activity indicators of the Endpoint Agent component

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.