Kaspersky Anti Targeted Attack (KATA) Platform

Creating an NTFS metafile retrieval task

8 November 2023

ID 247373

You can retrieve NTFS metafiles from selected hosts with the Endpoint Agent component. To do so, you must create an NTFS metafile retrieval task.

To create an NTFS metafile retrieval task:

  1. Select the Tasks section in the application web interface window.

    This opens the task table.

  2. Click the Add button and select NTFS metafiles in the Get data drop-down list.

    This opens the task creation window.

  3. Configure the following settings:
    1. Metafiles is the list of metafiles that you can get using the task. Select the relevant metafile by selecting the corresponding check box.

      You can select multiple metafiles.

    2. Volume is the name of the disk from which you want to get metafiles.

      By default, the system disk is specified. You can enter the path to a different disk in the <drive letter>:format.

    3. Description is the task description. This field is optional.
    4. Hostis the name or IP address of the host to which you want to assign the task.

      You can specify only one host.

      If you are using Kaspersky Endpoint Agent in the role of the Endpoint Agent component, the NTFS metafile retrieval task can be assigned only to hosts running Kaspersky Endpoint Agent for Windows version 3.13 and later.

  4. Click Add.

The NTFS metafile creation task is created. The task runs automatically after it is created.

When the task finishes, the application places a ZIP archive containing the selected metafiles in Storage. You can download the archive to your local computer.

If the task results in an error, the archive file contains the description of the error.

If you are using the distributed solution and multitenancy mode, the archive is placed in Storage of the Central Node server to which the host specified in the Host field is connected.

If downloading selected metafiles exhausts Storage capacity, objects in Storage will be rotated. If a metafile is larger than total Storage capacity, it is not downloaded

Users with the Security auditor role cannot create this task. Users with the Security officer role do not have access to tasks.

See also

Managing tasks

Viewing the task table

Viewing information about a task

Creating a get file task

Creating a forensic collection task

Creating a registry key retrieval task

Creating a process memory dump retrieval task

Creating a disk image retrieval task

Creating a RAM dump retrieval task

Creating a process termination task

Creating a task to scan hosts using YARA rules

Creating a service management task

Creating an application execution task

Creating a file deletion task

Creating a file quarantine task

Creating a quarantined file recovery task

Creating a copy of a task

Deleting tasks

Filtering tasks by creation time

Filtering tasks by type

Filtering tasks by name

Filtering tasks by file name and path

Filtering tasks by description

Filtering tasks by server name

Filtering tasks based on the name of the user that created the task

Filtering tasks by processing status

Clearing a task filter

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.