Kaspersky Anti Targeted Attack (KATA) Platform

Creating a service management task

8 November 2023

ID 247378

You can remotely start, stop, pause, or resume a service, as well as remove a service or change its start type on selected hosts with the Endpoint Agent component. To do so, you must create a service management task.

To create a service management task:

  1. Select the Tasks section in the application web interface window.

    This opens the task table.

  2. Click Add and select Service management.

    This opens the task creation window.

  3. Configure the following settings:
    1. In the Service name field, enter the name of the service.
    2. In the MD5/SHA256 field, enter the MD5 or SHA256 hash of the service. This field is optional.

      If you enter the hash of a service that is loaded from a DLL, Kaspersky Anti Targeted Attack Platform simultaneously compares the specified hash with the hash of the service DLL and the hash of the svchost process.

    3. In the Action field, select the operation that you want to perform on the service.

      The application supports the following operations with services:

      • Start.
      • Stop.
      • Pause.
      • Resume.
      • Delete.
      • Modify startup type.

      When you remove a service, processes that the service has started keep running until the system is restarted or the process is terminated.

    4. If you selected Modify startup type, in the Startup type, select the start type for the service.
    5. Description is the task description. This field is optional.
    6. Task for—Task scope:
      • If you want to run the task on all hosts of all servers, select the All hosts option.
      • If you want to run the task on selected servers, select the Specified servers option and on the right of the Servers parameter name select the check boxes next to the names of the servers on which you want to run the task.

        This option is available only when distributed solution and multitenancy mode is enabled.

      • If you want to run the task on selected hosts, select the Specified hosts option and list these hosts in the Hosts field.

      If you are using Kaspersky Endpoint Agent as the Endpoint Agent component, the task can be assigned only to hosts running Kaspersky Endpoint Agent for Windows version 3.12 and later. Host with earlier versions of Kaspersky Endpoint Agent for Windows and Kaspersky Endpoint Agent for Linux hosts are displayed in the list of hosts but cannot be selected.

  4. Click Add.

The service management task is created. The task runs automatically after it is created.

Stopping, pausing, deleting services or changing the start type of services that affect the functioning on the host is strongly discouraged.

List of services for which management is not recommended

Users with the Security auditor role cannot create service management tasks.

Users with the Security officer role do not have access to tasks.

See also

Managing tasks

Viewing the task table

Viewing information about a task

Creating a get file task

Creating a forensic collection task

Creating a registry key retrieval task

Creating an NTFS metafile retrieval task

Creating a process memory dump retrieval task

Creating a disk image retrieval task

Creating a RAM dump retrieval task

Creating a process termination task

Creating a task to scan hosts using YARA rules

Creating an application execution task

Creating a file deletion task

Creating a file quarantine task

Creating a quarantined file recovery task

Creating a copy of a task

Deleting tasks

Filtering tasks by creation time

Filtering tasks by type

Filtering tasks by name

Filtering tasks by file name and path

Filtering tasks by description

Filtering tasks by server name

Filtering tasks based on the name of the user that created the task

Filtering tasks by processing status

Clearing a task filter

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.