Kaspersky Anti Targeted Attack (KATA) Platform

Two-server deployment scenario

8 November 2023

ID 247177

When using KATA and KEDR functionality, you can install the Endpoint Agent component on corporate LAN computers. When using KATA functionality, the Endpoint Agent component is not installed.

When using this deployment scenario, the Central Node and Sensor components are installed on the same server or cluster. This server or cluster receives traffic, performs an initial analysis of traffic and a deeper analysis of extracted files. Based on the scan results, components detect signs of targeted attacks on the organization's IT infrastructure.

The Sandbox component is installed on the other server.

The scenario for application operation when deployed on two servers is presented in the figure below.

kata_2servers

Application operating scenario when deployed on two servers

See also

Three-server deployment scenario

Scenario of deployment on four or more servers

Scenario for deploying KEDR functionality with a Sandbox component

Scenario for deploying KEDR functionality without a Sandbox component

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.