Kaspersky Anti Targeted Attack (KATA) Platform

Creating a prevention rule

8 November 2023

ID 247689

To create a prevention rule:

  1. Select the Prevention section in the application web interface window.

    This opens the prevention rule table

  2. Click Add.
  3. Select Create rule.

    This opens the prevention rule creation window.

  4. Configure the following settings:
    1. State is the state of the prevention rule:
      • If you want to enable the prevention rule, set the toggle switch to On.
      • If you want to disable the prevention rule, set the toggle switch to Off.
    2. MD5/SHA256—MD5- or SHA256 hash of the file or data stream that you want to prevent from starting.
    3. Name is the name of the prevention rule.
    4. If you want the application to display a notification about prevention rule triggering to the user of the computer on which the prevention is applied, select the Notify user about blocking file execution check box.

      If you selected the Notify user about blocking file execution check box and an attempt is made to execute a file prevented from running, the user is notified that an execution prevention rule was triggered by this file.

    5. Prevent on is the prevention rule scope:
      • If you want to apply the prevention rule on all hosts of all servers, select All hosts.
      • If you want to apply the prevention rule on selected servers, select the Specified servers option and on the right of the Servers parameter name select the check boxes next to the names of the servers on which you want to apply the prevention rule.

        This option is available only when distributed solution and multitenancy mode is enabled.

      • If you want to apply the prevention rule on selected hosts, select the Specified hosts option and list these hosts in the Hosts field.

      If you are using Kaspersky Endpoint Agent for Linux or Kaspersky Endpoint Security for Linux in the role of the Endpoint Agent component, the prevention rule creation functionality is not available. When creating a prevention rule, if you select a host with Kaspersky Endpoint Agent for Linux, Kaspersky Endpoint Security for Linux or all hosts as the scope of the rule, the rule is not applied or is only applied to hosts with Kaspersky Endpoint Agent for Windows and Kaspersky Endpoint Security for Windows.

  5. Click Add.

The file startup prevention will be created.

You can also import prevention rules.

Users with the Security auditor role cannot create file launch prevention rules.

Users with the Security officer role cannot access prevention rules.

See also

Managing policies (prevention rules)

Viewing the prevention rule table

Configuring prevention rule table display

Viewing a prevention rule

Importing prevention rules

Enabling and disabling a prevention rule

Enabling and disabling presets

Deleting prevention rules

Filtering prevention rules by name

Filtering prevention rules by type

Filtering prevention rules by file hash

Filtering prevention rules by server name

Clearing a prevention rule filter

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.