Kaspersky Anti Targeted Attack (KATA) Platform

Enabling and disabling the automatic use of an IOC file when scanning hosts

8 November 2023

ID 247426

You can enable or disable the automatic use of an IOC file for searching for indicators of compromise on hosts with the Endpoint Agent component.

To enable or disable the automatic use of an IOC file for searching for indicators of compromise on hosts with the Endpoint Agent component:

  1. In the window of the program web interface, select the Custom rules section, IOC subsection.

    This opens the table of IOC files.

  2. In the row containing the IOC file whose use you want to enable or disable, in the State column, set the toggle switch to one of the following positions:
    • Enabled
    • Disabled

Automatic use of an IOC file for searching for indicators of compromise on hosts with the Endpoint Agent component is enabled or disabled.

Users with the Security auditor and Security officer roles cannot enable or disable automatic application of an IOC file.

See also

Managing user-defined IOC rules

Viewing the table of IOC files

Viewing information about an IOC file

Uploading an IOC file

Downloading an IOC file to a computer

Deleting an IOC file

Searching for alerts in IOC scan results

Searching for events using an IOC file

Filtering and searching IOC files

Clearing an IOC file filter

Configuring an IOC scan schedule

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.