[[Template blog/front/browse/indexGridEntry is throwing an error. This theme may be out of date. Run the support tool in the AdminCP to restore the default theme.]]
[[Template blog/front/browse/indexGridEntry is throwing an error. This theme may be out of date. Run the support tool in the AdminCP to restore the default theme.]]
Problem
When user is added to a lot of AD groups, he may be unable to login to web interface of KATA via SSO.
Step-by-step guide
Modify /etc/opt/kaspersky/apt-swarm/swarm_config.json like this (set buffer_size to 65535 under uwsgi section - it's on bottom of the file)
2. Execute via SSH
apt-settings-manager get /configuration/web_backend | python -m json.tool > /tmp/web_backend
Problem Description, Symptoms & Impact
When downloading large collects (sandbox-debug-report) exceeding 1Gb in size, download suddenly fails above 1Gb (at ~1 05x xxx KB).
Diagnostics
Reproducible in all browsers, is not bound to download speed, dowloaded part size is roughly 1Gb
Workaround & Solution
Workaround: download sandbox-debug-report using SCP and CLI, see https://forum.kaspersky.com/topic/how-to-gather-sandbox-debug-report-from-terminal-katakedre-36851/
Issue
"Databases and modules update task" is configured for hosts with LENA 3.12 installed.
Task is executed via KSC.
Diagnostics
"Activate KEA" task is configured for the hosts with LENA or has been configured and deleted in the past.
An update is executed locally, using lenactl works.
KLNagent successfully synchronizes with the server. Other installed applications (e.g. KESL) display no synchronization issues.
Workaround
To fix the issue:
[[Template blog/front/browse/indexGridEntry is throwing an error. This theme may be out of date. Run the support tool in the AdminCP to restore the default theme.]]
[[Template blog/front/browse/indexGridEntry is throwing an error. This theme may be out of date. Run the support tool in the AdminCP to restore the default theme.]]
When creating an IoC scan task, only the following registry branches are scanned.
<field name="predefined_keypaths" type="wstring" multi-valued="yes" default-value=
'{
LR"(HKEY_CLASSES_ROOT\htafile)",
LR"(HKEY_CLASSES_ROOT\batfile)",
LR"(HKEY_CLASSES_ROOT\exefile)",
LR"(HKEY_CLASSES_ROOT\comfile)",
LR"(HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa)",
[[Template blog/front/browse/indexGridEntry is throwing an error. This theme may be out of date. Run the support tool in the AdminCP to restore the default theme.]]
[[Template blog/front/browse/indexGridEntry is throwing an error. This theme may be out of date. Run the support tool in the AdminCP to restore the default theme.]]
In EDR Security officer can create a hash-based prevention rule for workstation. Here's the list of activities to which prevention rules apply:
Agent should control and prevent read access of the following file formats by the following apps:
App:
winword.exe
wordpad.exe
excel.exe
[[Template blog/front/browse/indexGridEntry is throwing an error. This theme may be out of date. Run the support tool in the AdminCP to restore the default theme.]]
Problem
After "Nessus" vulnerability scanning on Central node 4.0 servers, you may see the following:
Ports: 22-tcp
Description: The remote SSH server is configured to allow key exchange algorithms which are considered weak. This is based on the IETF draft document Key Exchange (KEX) Method Updates and Recommendations for Secure Shell (SSH) draft-ietf-curdle-ss
What is the default synchronization period between KEA and CN?
Sync period (which is every X minutes) for KEA is configurable in KEA policy. Default synchronization period is 300 sec (5 min). The same period applies to LENA.
What is the isolation workflow?
In KATA CN creates task for host isolation.
KEA receives an 'isolate' command from the Central Node during synchronization .
An agent turns on host isolation with exclusions configured in KEA policy.
At the
[[Template blog/front/browse/indexGridEntry is throwing an error. This theme may be out of date. Run the support tool in the AdminCP to restore the default theme.]]
KATA 4.0/4.1 is compatible with KSMG 2.0, KSMG 1 and KLMS 8.0.3.
Second thing to notice is that KSMG integration has a few bugs on KATA side. Thankfully, all known issues are fixed in a PF, which is recommended for all who integrate KSMG/KLMS and KATA4.
KATA4.0
Step-by-step guide
Download container with fix.
file_name : kata_scanner_35f8753e6d.tar.gz
md5 : 2adb09c0bd13dfc03c6a5c8980dde4ff
container_name: kata_scanner
container_version: kata_scanner:35f8753e6
[[Template blog/front/browse/indexGridEntry is throwing an error. This theme may be out of date. Run the support tool in the AdminCP to restore the default theme.]]
[[Template blog/front/browse/indexGridEntry is throwing an error. This theme may be out of date. Run the support tool in the AdminCP to restore the default theme.]]
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.
OS restart will be requested If you upgrading KEA above 3.11 version.
About
This article contains the best way of upgrading KEA 3.9 to the last KEA version avoiding possible known issues.
Procedure
Disable Password-protection and Self-Defense in KEA policy, lock the settings. Ensure that policy is applied on all devices.
Upgrade KEA plug-in on the KSC side. Recreate
[[Template blog/front/browse/indexGridEntry is throwing an error. This theme may be out of date. Run the support tool in the AdminCP to restore the default theme.]]
Problem
KEA writes in its event logs numeric task states.
Solution
Number
Meaning
0
Unknown
1
PreparedToStart
2
Starting
3
Started
4
Stopping
5
Stopped
[[Template blog/front/browse/indexGridEntry is throwing an error. This theme may be out of date. Run the support tool in the AdminCP to restore the default theme.]]
Problem
This error appears when newest MDR Configuration files that are above 1MB in size are uploaded into KATA WebUI following the integration scenario either to establish the integration or to replace the outdated config:
https://support.kaspersky.com/KATA/3.7.2/en-US/201839.htm
Solution
Extend zip-archive file size limit from 1MB to 2MB:
Become root:
[[Template blog/front/browse/indexGridEntry is throwing an error. This theme may be out of date. Run the support tool in the AdminCP to restore the default theme.]]
[[Template blog/front/browse/indexGridEntry is throwing an error. This theme may be out of date. Run the support tool in the AdminCP to restore the default theme.]]