Kaspersky Anti Targeted Attack (KATA) Platform

Event information

8 November 2023

ID 247889

If you are using the distributed solution and multitenancy mode, when managing the application using the web interface, you can view event information for those tenants to whose data you have access.

Event information displays local timestamps of the Endpoint Agent computer that detected the event. The application administrator must make sure the time on computers with the Endpoint Agent component is current.

To enable the display of events for all tenants:

  1. Select the Threat Hunting section in the application web interface window.
  2. Turn on the Search in all tenants toggle switch.

The table of events displays events for all tenants.

In this section

Recommendations for processing events

Information about events in the tree of events

Viewing the table of events

Configuring the event table display

Viewing information about an event

Information about the "Process started" event

Information about the "Process terminated" event

Information about the "Module loaded" event

Information about the "Remote connection" event

Information about the "Prevention rule" event

Information about the "Document blocked" event

Information about the "File modified" event

Information about the "System event log" event

Information about the "Changes in the registry" event

Information about the "Port listened" event

Information about the "Driver loaded" event

Information about the "Alert" event

Information about the "Alert processing result" event

Information about the "Interpreted file run" event

Information about the "AMSI scan" event

Information about the "Interactive command input at the console" event

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.