<?xml version="1.0"?>
<rss version="2.0"><channel><title><![CDATA[Advice and solutions for Kaspersky Anti Targeted Attack & EDR Expert Latest Topics]]></title><link>https://forum.kaspersky.com/forum/advice-and-solutions-for-kaspersky-anti-targeted-attack-edr-expert-222/</link><description><![CDATA[Advice and solutions for Kaspersky Anti Targeted Attack & EDR Expert Latest Topics]]></description><language>en</language><item><title>How to change CN network settings from command line without accessing web UI in KATA 5.+ [KATA/KEDRE]</title><link>https://forum.kaspersky.com/topic/how-to-change-cn-network-settings-from-command-line-without-accessing-web-ui-in-kata-5-katakedre-39353/</link><description><![CDATA[<div style="border:1px solid #aab8c6;color:#333333;font-size:14px;padding:10px 10px 10px 36px;">
	<p style="padding:0px;">
		<strong>Versions</strong>
	</p>

	<div style="padding:0px;">
		<p style="padding:0px;">
			Applicable to versions later than 5.0, 5.1, 6.0, 6.0.1, etc.
		</p>
	</div>
</div>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/advice-and-solutions-forum-knowledgebase-disclaimer-read-before-using-materials-36464/" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.</span></a></span>
</h2>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span><span>Problem</span></span>
</h2>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<span><span>There are several cases where the <a href="https://support.kaspersky.com/help/KATA/5.1/en-US/247525.htm" rel="external nofollow" style="color:#265951;">standard method</a><span> </span>of changing interface network settings via the Web UI is not available, e.g. the Web UI is inaccessible.</span></span>
</p>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span><span>Solution</span></span>
</h2>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<span><span>Become root, save the nodes settings:</span></span>
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">sudo su</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">console-settings-updater get /deploy/deployment_api/nodes | python3 -m json.tool &gt; /tmp/nodes</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<span><span>Open the saved file for editing:</span></span>
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">vim /tmp/nodes</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<span><span>Locate the desired<span> </span></span></span><strong>network_settings</strong>,<span> </span><strong>ifaces<span> </span></strong>node, change the values tat you need to change:
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">{</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">    </code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"cc2cx0fltsjmxolid99p5loen"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">: {</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">        </code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"id"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">1</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">,</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">        </code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"hostname"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"1.srv.node1.node.dyn.kata"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">,</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">...</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">        </code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"network_settings"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">: {</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">            </code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"ifaces"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">: [</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">                </code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">{</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">                    </code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"iface_name"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"ens160"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">,</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">                    </code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"configuration_type"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"static"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">,</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">                    </code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"span"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:<span> </span></code><code style="border:0px;color:#336699;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">false</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">,</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">                    </code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"address"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"10.68.56.215"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">,</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">                    </code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"netmask"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"255.255.254.0"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">,</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">                    </code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"gateway"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"10.68.56.1"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">,</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">                    </code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"mac"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"00:50:56:a5:39:f6"</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">                </code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">},</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">                </code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">{</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">                    </code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"iface_name"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"ens192"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">,</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">                    </code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"configuration_type"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"static"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">,</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">                    </code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"address"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"100.100.100.100"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">,</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">                    </code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"netmask"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"255.255.255.0"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">,</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">                    </code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"gateway"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"100.100.100.1"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">,</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">                    </code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"mac"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"00:50:56:a2:5a:f6"</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">                </code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">}</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">            </code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">]</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">        </code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">}</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">    </code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">}</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">}</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<span>Save your changes and exit Vim. Verify that the JSON structure is valid (the command returns no errors):</span>
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">cat /tmp/nodes | python3 -m json.tool</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<span>Import the modified settings back:</span>
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">console-settings-updater set /deploy/deployment_api/nodes @/tmp/nodes</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>
]]></description><guid isPermaLink="false">39353</guid><pubDate>Sat, 24 Feb 2024 11:20:54 +0000</pubDate></item><item><title>How to access apt-history logs on CN without the kata-collect-siem-logs tool [KATA/KEDRE]</title><link>https://forum.kaspersky.com/topic/how-to-access-apt-history-logs-on-cn-without-the-kata-collect-siem-logs-tool-katakedre-39351/</link><description><![CDATA[<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/advice-and-solutions-forum-knowledgebase-disclaimer-read-before-using-materials-36464/" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.</span></a></span>
</h2>

<div style="border:1px solid #aab8c6;color:#333333;padding:10px 10px 10px 36px;">
	<p style="padding:0px;">
		<strong>Versions</strong>
	</p>

	<div style="padding:0px;">
		<p style="padding:0px;">
			Applicable to versions above 5: 5.0, 5.1, 6.0, 6.0.1, etc.
		</p>
	</div>
</div>

<p style="padding:0px;">
	<span>You can fancy access<span> </span><strong>log-history</strong><span> </span>logs (former<span> </span><strong>apt-history</strong>) directly for convenience purposes or if the<span> </span><strong>kata-collect-siem-logs<span> </span></strong>tool is malfunctioning for some reason.</span>
</p>

<p style="padding:0px;">
	These logs are in<span> </span><strong>gzip,</strong><span> </span>sorted by dates, as files with names in format:<span> </span><code><strong>/data/volumes/s3proxy/log-history/YYYY-MM-DD-HH-MM-SS</strong></code>, where<span> </span><code><strong>YYYY-MM-DD-HH-MM-SS</strong></code><span> </span>is the datetime.
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
	<div style="border-bottom:1px solid #cccccc;padding:5px 15px;text-align:left;">
		<b style="color:#333333;">basename -a /data/volumes/s3proxy/log-history/2024*</b>
	</div>

	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">2024</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">01</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">01</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">13</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">55</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">03</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">2024</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">01</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">17</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">12</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">00</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">14</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">2024</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">01</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">17</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">12</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">05</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">14</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="padding:0px;">
	 To access these logs, use the respective<span> </span><span><span><code><strong>zless; zgrep; zcat</strong></code><span> </span>tools. For example:</span></span>
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">zcat /data/volumes/s3proxy/log-history/</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">2024</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">01</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">17</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">12</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">05</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">14</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">2024</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">01</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">17</code><span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">12</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">00</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">59.924639</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">info apt-history: New IDS alert: {id:<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">63</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">, importance: High, hidden: False, rule_id:<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">51310592</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">, excluded rule: False, src:<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">18.156</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">.</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">136.240</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">80</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">, dest:<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">10.63</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">.</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">100.252</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">2198</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">, bases_version:<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">202401170033</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">}</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="padding:0px;">
	<span><span><strong>Bonus</strong>: you can also use these tools to read rotated logs of kataservices in <strong><code>/var/log/kaspersky/services/</code></strong>:</span></span>
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">zgrep<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"FileNotFoundError"</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/var/log/kaspersky/services/web_backend/web_backend.log.</code><code style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;"><font color="#009900">1</font></code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>
]]></description><guid isPermaLink="false">39351</guid><pubDate>Sat, 24 Feb 2024 11:09:20 +0000</pubDate></item><item><title>KEA core patches [Kaspersky Endpoint Agent]</title><link>https://forum.kaspersky.com/topic/kea-core-patches-kaspersky-endpoint-agent-38157/</link><description><![CDATA[<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/advice-and-solutions-forum-knowledgebase-disclaimer-read-before-using-materials-36464/" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.</span></a></span>
</h2>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	Problem
</h2>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	You may encounter issues with KEA that may include:
</p>

<ul style="background-color:#ffffff;color:#172b4d;font-size:14px;">
	<li>
		Excessive resource consumption
	</li>
	<li>
		Freezes, crashes
	</li>
	<li>
		etc.
	</li>
</ul>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	Solution
</h2>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	Install the latest available core patch.
</p>

<div style="border:1px solid #d04437;color:#333333;font-size:14px;padding:10px 10px 10px 36px;">
	<div style="padding:0px;">
		<p style="padding:0px;">
			Adding KEA CF to KEA installation package is not supported and will not work, patches need to be installed separately.
		</p>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	To install patch using KSC or locally use the following keys,<span> </span><strong><code>/qn</code></strong><span> </span>can be added for silent install as usual
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="border-bottom:1px solid #cccccc;padding:5px 15px;text-align:left;">
		<b style="color:#333333;">How to install patch</b>
	</div>

	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">msiexec /p private_critical_fix_99.msp  DISCLAIMER=</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">1</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">EULA=</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">1</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">PRIVACYPOLICY=</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">1</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	When installing on servers it is advisable to use additional<span> </span><strong>SERVERPROFILE=1<span> </span></strong>key for optimized performance (works for core patches starting from CF8 for KEA 3.12 and newer)
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="border-bottom:1px solid #cccccc;padding:5px 15px;text-align:left;">
		<b style="color:#333333;">Additional recommended key for Server installations:</b>
	</div>

	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">msiexec /p private_critical_fix_99.msp  DISCLAIMER=</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">1</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">EULA=</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">1</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">PRIVACYPOLICY=</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">1</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">SERVERPROFILE=</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">1</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	For password-protected installations additional key is needed:
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">UNLOCK_PASSWORD=password</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	For detailed info see article<span> </span><u style="background-color:#fcfcfc;color:#333333;font-size:14px;"><a href="https://forum.kaspersky.com/topic/how-to-install-patches-on-password-protected-kea-kaspersky-endpoint-agent-38148/" rel="" style="color:#265951;">https://forum.kaspersky.com/topic/how-to-install-patches-on-password-protected-kea-kaspersky-endpoint-agent-38148/</a></u>
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	Things to keep in mind:
</p>

<ul style="background-color:#ffffff;color:#172b4d;font-size:14px;">
	<li>
		All Core patches are cumulative; That means all previous fixes are included.
	</li>
	<li>
		Newer KEA versions include fixes done in previous versions.
	</li>
	<li>
		It's not always necessary to keep KEA at latest core, but it's worth starting your troubleshooting with installing the latest one.
	</li>
</ul>
]]></description><guid isPermaLink="false">38157</guid><pubDate>Sat, 23 Dec 2023 20:08:28 +0000</pubDate></item><item><title><![CDATA[KEA 3.9 -> 3.1x: Upgrade procedure [Kaspersky Endpoint Agent]]]></title><link>https://forum.kaspersky.com/topic/kea-39-31x-upgrade-procedure-kaspersky-endpoint-agent-38155/</link><description><![CDATA[<p>
	<strong><span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/advice-and-solutions-forum-knowledgebase-disclaimer-read-before-using-materials-36464/" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.</span></a></span></strong>
</p>

<div style="border:1px solid #d04437;color:#333333;font-size:14px;padding:10px 10px 10px 36px;">
	<div style="padding:0px;">
		<p style="padding:0px;">
			OS restart will be requested If you upgrading KEA above 3.11 version.
		</p>
	</div>
</div>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	About
</h2>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	This article contains the best way of upgrading KEA 3.9 to the last KEA version avoiding possible known issues.
</p>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	Procedure
</h2>

<ul style="background-color:#ffffff;color:#172b4d;font-size:14px;">
	<li>
		Disable<span> </span><strong>Password-protection</strong><span> </span>and<span> </span><strong>Self-Defense</strong><span> </span>in KEA policy, lock the settings. Ensure that policy is applied on all devices.
	</li>
	<li>
		Upgrade KEA plug-in on the KSC side. Recreate KEA policy.
	</li>
	<li>
		Prepare installation package:<br />
		 - copy KEA distributive to KSC;<br />
		 - copy KEA Core-patch into the same folder;<br />
		 - copy <a href="https://box.kaspersky.com/f/a999b72e91cf405cbcfb/?dl=1" rel="external nofollow">KEA3.9_upgrade_script.zip</a><span> </span>into the same folder;<br />
		<img class="ipsImage ipsImage_thumbnailed" data-fileid="15636" data-ratio="72.66" width="278" alt="image.png.3f46a5d949b495fb25196c256c98f26d.png" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.3f46a5d949b495fb25196c256c98f26d.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /><br />
		 - modify the last part of the script specifying the correct patch name (optional). Uncomment the last string if you want to install the patch right after KEA installation:<br />
		<img class="ipsImage ipsImage_thumbnailed" data-fileid="15637" data-ratio="13.65" width="425" alt="image.png.3b210bb6c23f4944dc59ef3dfa35b9ab.png" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.3b210bb6c23f4944dc59ef3dfa35b9ab.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" />
	</li>
	<li style="text-align:left;">
		Create an installation package on KSC<br />
		 <img class="ipsImage ipsImage_thumbnailed" data-fileid="15638" data-ratio="65.42" width="483" alt="image.png.f0ed935f4814ef1f4316ed67b930cf34.png" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.f0ed935f4814ef1f4316ed67b930cf34.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /><span> </span>→<span>  </span><img class="ipsImage ipsImage_thumbnailed" data-fileid="15639" data-ratio="113.94" width="416" alt="image.png.40b866df11d9a31ff3d0bc0ad1cf059e.png" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.40b866df11d9a31ff3d0bc0ad1cf059e.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" />→<span> </span><img class="ipsImage ipsImage_thumbnailed" data-fileid="15640" data-ratio="86.77" width="378" alt="image.png.38131884001f0fd311abd151df094c42.png" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.38131884001f0fd311abd151df094c42.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" />
	</li>
	<li>
		Create and start "Install Application Remotely" task from KSC;
	</li>
	<li>
		Wait for successful completion;
	</li>
	<li>
		Enable Password-protection and Self-Defense in KEA policy after the upgrade is done.
	</li>
</ul>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	Upgrade Script:<span><a href="https://box.kaspersky.com/f/a999b72e91cf405cbcfb/?dl=1" rel="external nofollow">KEA3.9_upgrade_script.zip</a></span>
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	This scenario helps to avoid possible known issues with KEA 3.9 upgrade.
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	Rarely, even the script doesn't work.<br />
	The cause of it - KEA 3.9 Self-Defense. The files and services are marked for deletion but can't be deleted.<br />
	So, if the script doesn't help you - the only possible way to complete the upgrade, unfortunately, is the<span> </span><strong>reboot</strong>.
</p>
]]></description><guid isPermaLink="false">38155</guid><pubDate>Sat, 23 Dec 2023 19:32:19 +0000</pubDate></item><item><title>How to perform Yara-scan using KEA [Kaspersky Endpoint Agent]</title><link>https://forum.kaspersky.com/topic/how-to-perform-yara-scan-using-kea-kaspersky-endpoint-agent-38154/</link><description><![CDATA[<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/advice-and-solutions-forum-knowledgebase-disclaimer-read-before-using-materials-36464/" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.</span></a></span>
</h2>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	The scenario is applicable for KEA version 3.10 and above.
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	There is no built-in feature to perform Yara-scan using KATA/EDR Expert 3.7.2. But if necessary, it's possible to perform it using KEA 3.10 and above.
</p>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	Yara-scan using the Command line
</h2>

<h3 style="background-color:#ffffff;color:#000000;font-size:16px;padding:0px;">
	Requirements:
</h3>

<ul style="background-color:#ffffff;color:#172b4d;font-size:14px;">
	<li>
		KEA 3.10 (and above) installed
	</li>
	<li>
		Files with Yara-rules (<code><strong>*.yara</strong></code>;<span> </span><code><strong>*.yar</strong></code>)
	</li>
</ul>

<h3 style="background-color:#ffffff;color:#000000;font-size:16px;padding:0px;">
	Scenario:
</h3>

<ol style="background-color:#ffffff;color:#172b4d;font-size:14px;">
	<li>
		Ensure that KEA is installed and running;
	</li>
	<li>
		<p style="padding:0px;">
			Run the Yara-scan
		</p>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"C:\Program Files (x86)\Kaspersky Lab\Endpoint Agent\agent.exe"</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">--scan-yara --path c:\rules --folder c:\files --scan-files yes</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>

		<div style="border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="background-color:#f7f7f7;border-bottom:1px solid #7eff33;padding:10px;">
				<b>Syntax</b>
			</div>

			<div style="padding:10px;">
				<p style="padding:0px;">
					<code><strong>--path [PATH]</strong></code><span> </span>- the location of yara-files<br />
					<code><strong>--folder [PATH]</strong></code><span> </span>- the scope of scanning (e.g.<span> </span><strong><code>C:\</code></strong><span> </span>to scan all files on the C drive and subfolders)
				</p>
			</div>
		</div>
	</li>
	<li>
		Results will be listed on the CLI
	</li>
</ol>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<a class="ipsAttachLink ipsAttachLink_image" data-fileext="png" data-fileid="15633" href="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.afcbcef45a23625392ab398e689c4b7e.png" rel=""><img alt="image.thumb.png.89c2d63a3872e52a9ebd38b5842ce255.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15633" data-ratio="25.43" style="height:auto;" width="700" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.thumb.png.89c2d63a3872e52a9ebd38b5842ce255.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
</p>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	Yara-scan using KATA/EDR Web-UI
</h2>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	Alternatively you can perform the commend using "Run program" EDR task from Central Node.
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<img alt="image.png.b6c75b5365482b65196f96040061175e.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15634" data-ratio="38.73" style="height:auto;" width="457" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.b6c75b5365482b65196f96040061175e.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" />
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<img alt="image.png.fb4f56b30a0fb7df0f7bf3b53b73a4c6.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15635" data-ratio="42.77" style="height:auto;" width="657" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.fb4f56b30a0fb7df0f7bf3b53b73a4c6.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" />
</p>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	Yara-scan using KSC
</h2>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	If KEA is installed and managed from KSC server, you can start the command by<span> </span><code><strong>*.bat</strong></code><span> </span>file using Remote installation task.
</p>

<h3 style="background-color:#ffffff;color:#000000;font-size:16px;padding:0px;">
	Requirements:
</h3>

<ul style="background-color:#ffffff;color:#172b4d;font-size:14px;">
	<li>
		KEA 3.10 (and above) installed
	</li>
	<li>
		Files with Yara-rules (*.yara; *.yar)
	</li>
	<li>
		Shared folder with READ ALL access
	</li>
	<li>
		Shared folder with WRITE ALL access
	</li>
</ul>

<h3 style="background-color:#ffffff;color:#000000;font-size:16px;padding:0px;">
	Follow these steps:
</h3>

<ol style="background-color:#ffffff;color:#172b4d;font-size:14px;">
	<li>
		Prepare the batch file
	</li>
	<li>
		Prepare Shared folders: one with READ and one with WRITE access for everyone
	</li>
	<li>
		Create installation package on KSC using<span> </span><code><strong>*.bat<span> </span></strong></code>file (see example below)
	</li>
	<li>
		Create and start "Install application remotely" task
	</li>
</ol>

<h3 style="background-color:#ffffff;color:#000000;font-size:16px;padding:0px;">
	Example:
</h3>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="border-bottom:1px solid #cccccc;padding:5px 15px;text-align:left;">
		<b style="color:#333333;">*.bat file example</b>
	</div>

	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#808080;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">@echo</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">off</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"C:\Program Files (x86)\Kaspersky Lab\Endpoint Agent\agent.exe"</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">--scan-yara --path \\SHARE\YaraRules\ --folder C:\ --scan-files yes &gt;&gt; C:\Windows\Temp\yara-scan-results.txt</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">copy C:\Windows\Temp\yara-scan-results.txt \\SHARE\YaraScanRusults\%computername%_results.txt</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	The script will start Yara scanning using KEA: all files at<span> </span><code><strong>C:\</strong></code><span> </span>will be scanned using all rules from<span> </span><code><strong>\\SHARE\YaraRules\</strong></code>, results will be saved into<span> </span><code><strong>\\SHARE\YaraScanRusults\</strong><span> </span></code>folder.<br />
	<br />
	<span><code><strong>\\SHARE\YaraRules\</strong></code><span> </span>folder should be available for READ<br />
	<code><strong>\\SHARE\YaraScanRusults\</strong></code><span> </span>folder should be available for WRITE</span>
</p>
]]></description><guid isPermaLink="false">38154</guid><pubDate>Sat, 23 Dec 2023 19:21:02 +0000</pubDate></item><item><title>How to integrate KATA with KPSN reputation database [KATA/KEDRE]</title><link>https://forum.kaspersky.com/topic/how-to-integrate-kata-with-kpsn-reputation-database-katakedre-38151/</link><description><![CDATA[<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/advice-and-solutions-forum-knowledgebase-disclaimer-read-before-using-materials-36464/" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.</span></a></span>
</h2>

<h3 style="background-color:#ffffff;color:#000000;font-size:16px;padding:0px;">
	<strong>Scenario:</strong>
</h3>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	KATA/EDR CN is integrated with the KPSN server, and you want to enrich the KPSN reputation database with the detections from the sandbox server. You can integrate a KATA Platform Central node with the KPSN reputation database and automatically populate it with information about the files that the sandbox technology finds to be dangerous and highly important.
</p>

<h3 style="background-color:#ffffff;color:#000000;font-size:16px;padding:0px;">
	<strong>Pre-requisites:</strong>
</h3>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	To configure sending checksums of the files detected by the sandbox technology to KPSN, you will need a certificate of a KPSN user account entitled to use KPSN API.
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	Download the certificate (both parts, public and private) of a KPSN user who has permission to use KPSN API from the user’s profile in the KPSN web console. The KPSN administrator has the required permissions, but a pair of encryption keys of any user allowed to access the KPSN API will do as well. and key from the user’s profile from the KPSN web interface.
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	You can provide the API access to the required user from KPSN Web UI → Users → and the API option should be enabled under permissions.
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	To send the sandbox detections to KPSN:
</p>

<ul style="background-color:#ffffff;color:#172b4d;font-size:14px;">
	<li>
		In the central node administrator’s console, open<span> </span><strong>Settings | KPSN reputation database</strong><span> </span>and specify:

		<ul>
			<li>
				HOST – IP address of the KPSN server where the local KPSN reputation database is stored;
			</li>
			<li>
				TLS Certificate – a certificate for the user authentication in KPSN;
			</li>
			<li>
				TLS encryption key – private encryption key;
			</li>
		</ul>
	</li>
</ul>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	There are two or more servers with different roles in a typical KPSN installation. A KPSN server can have several roles. Specify the IP address of the KPSN server that has the <strong>Monitoring Service</strong><span> </span>role.
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<a class="ipsAttachLink ipsAttachLink_image" data-fileext="png" data-fileid="15627" href="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.235c08425c4470487f9fec9e3b8a1957.png" rel=""><img alt="image.thumb.png.717f8d1a30604b04868c13a6e7ba9ec3.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15627" data-ratio="54.29" style="height:auto;" width="700" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.thumb.png.717f8d1a30604b04868c13a6e7ba9ec3.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	In the Central node console of a senior security office, open<span> </span><strong>Settings | KPSN reputation database</strong><span> </span>and select the checkbox to<span> </span><strong>Assign the ‘Untrusted’ status to objects</strong>.
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<a class="ipsAttachLink ipsAttachLink_image" data-fileext="png" data-fileid="15628" href="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.300abcc7a5f5b8af5c5284522fa7f38f.png" rel=""><img alt="image.thumb.png.7ce86bb705a0253638cdaf4e6302192c.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15628" data-ratio="34.29" style="height:auto;" width="700" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.thumb.png.7ce86bb705a0253638cdaf4e6302192c.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	You can upload the test file to the KATA Central node for scanning, once the file is detected by Sandbox component, the checksum of the detected file will be published in the KPSN local reputation database.
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	The KPSN administrator can manually create records in the KPSN reputation database. A record added by KATA/EDR has the KATA tag in the description. You cannot delete the KATA records, but you can disable them.
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	Below screenshot display the samples hashes added in the KPSN Reputation database from the KATA server.
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<a class="ipsAttachLink ipsAttachLink_image" data-fileext="png" data-fileid="15629" href="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.a4f750849146af49826e640288ffcf59.png" rel=""><img alt="image.thumb.png.ff001792be537b44c992e737b5d99347.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15629" data-ratio="54.14" style="height:auto;" width="700" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.thumb.png.ff001792be537b44c992e737b5d99347.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
</p>
]]></description><guid isPermaLink="false">38151</guid><pubDate>Sat, 23 Dec 2023 16:51:21 +0000</pubDate></item><item><title>How to collect LENA troubleshooting information [Kaspersky Endpoint Agent for Linux]</title><link>https://forum.kaspersky.com/topic/how-to-collect-lena-troubleshooting-information-kaspersky-endpoint-agent-for-linux-38150/</link><description><![CDATA[<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/advice-and-solutions-forum-knowledgebase-disclaimer-read-before-using-materials-36464/" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.</span></a></span>
</h2>

<p style="padding:0px;">
	<span style="color:#003366;">This article applies to<span> </span><strong>Endpoint Agent for Linux</strong>. To collect LENA debug or ANY traces, please follow this guide.</span>
</p>

<p style="padding:0px;">
	Default traces location is<code><span> </span>'/var/log/kaspersky/epagent/'</code>.
</p>

<p style="padding:0px;">
	Default dumps location is<span> </span><code>'/tmp/agentdumps'</code>
</p>

<p style="padding:0px;">
	Public<span> </span><strong><a href="https://support.kaspersky.com/collect" rel="external nofollow" style="color:#265951;">collect.sh script</a></strong><span> </span>was updated to collect LENA-related information and gather these folder as well.
</p>

<h2 style="border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	How to: enable LENA ANY traces
</h2>

<p style="padding:0px;">
	For KATA-EDR (on-premises) customers to tune LENA performance by exclusions, ANY level logs are required. To enable ANY logging:
</p>

<ol>
	<li>
		<p style="padding:0px;">
			Become root
		</p>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">sudo su -</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>
	</li>
	<li>
		<p style="padding:0px;">
			Use one-liner to enable ANY tracing level: 
		</p>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">sed -i<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">'s/LENA_TRACE_LEVEL=none/LENA_TRACE_LEVEL=any/g'</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/etc/opt/kaspersky/epagent/service.conf &amp;&amp; systemctl restart epagent</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>

		<div style="padding:0px;">
			<div style="padding:0px;">
				<ol>
					<li>
						<p style="padding:0px;">
							Modify the config file<strong><span> </span><code><span style="color:#242424;">/etc/opt/kaspersky/epagent/service.conf</span></code></strong>
						</p>

						<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
							<div style="border-bottom:1px solid #cccccc;padding:5px 15px;text-align:left;">
								<b style="color:#333333;">/etc/opt/kaspersky/epagent/service.conf</b>
							</div>

							<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
								<div style="padding:0px;">
									<div style="background-color:#ffffff;font-size:1em;padding:0px;">
										<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
											<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
												<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
													<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
														<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
															<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
																<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">KESL_FIFO_PATH=/run/log/kesl-messages</code>
															</div>

															<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
																<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">AUDIT_FIFO_PATH=/run/log/audit-messages</code>
															</div>

															<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
																<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">LENA_TRACE_LEVEL=none &lt;-- set any here instead of none</code>
															</div>

															<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
																<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">LENA_DUMPS=yes</code>
															</div>
														</div>
													</td>
												</tr>
											</tbody>
										</table>
									</div>
								</div>
							</div>
						</div>
					</li>
					<li>
						<p style="padding:0px;">
							<span>Save the modided value.</span>
						</p>

						<div style="border:1px solid #aab8c6;color:#333333;padding:10px 10px 10px 36px;">
							<p style="padding:0px;">
								Careful, CaSe sensitive values!
							</p>

							<div style="padding:0px;">
								<p style="padding:0px;">
									LENA_TRACE_LEVEL=any  ←<span> </span><u>correct</u>
								</p>

								<p style="padding:0px;">
									LENA_TRACE_LEVEL=none  ←<span> </span><u>correct</u>
								</p>

								<p style="padding:0px;">
									LENA_TRACE_LEVEL=ANY ←<span> </span><strong>wrong</strong>
								</p>

								<p style="padding:0px;">
									LENA_TRACE_LEVEL=None   ←<span> </span><strong>wrong</strong>
								</p>
							</div>
						</div>
					</li>
					<li>
						<p style="padding:0px;">
							<span>To apply changes, restart<span> </span><code>epagent</code><span> </span>service</span>
						</p>

						<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
							<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
								<div style="padding:0px;">
									<div style="background-color:#ffffff;font-size:1em;padding:0px;">
										<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
											<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
												<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
													<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
														<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
															<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
																<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">systemctl restart epagent</code>
															</div>
														</div>
													</td>
												</tr>
											</tbody>
										</table>
									</div>
								</div>
							</div>
						</div>
					</li>
				</ol>
			</div>
		</div>
	</li>
	<li>
		<span>Wait until the problematic behavior is reproduced;</span>
	</li>
	<li>
		<p style="padding:0px;">
			<span>Stop traces</span>
		</p>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/opt/kaspersky/epagent/sbin/lenactl --traces --off</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>
	</li>
	<li>
		<p style="padding:0px;">
			Double-check that produced traces indeed contain ANY-level information use this<span> </span><span>command</span>:
		</p>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">grep -q ANY /var/log/kaspersky/epagent/lena*;<span> </span></code><code style="border:0px;color:#336699;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">if</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">[[ $? ==<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">]]; then echo<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"ANY logs"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">;<span> </span></code><code style="border:0px;color:#336699;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">else</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">echo<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"Not ANY :("</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">; fi</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>
	</li>
	<li>
		<p style="padding:0px;">
			As an addition you can check for how long ANY traces were gathered like 
		</p>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">grep -h ANY /var/log/kaspersky/epagent/lena* | awk<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">'{print $1}'</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">| cut -d<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">'.'</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-f<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">1</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">| uniq</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>
	</li>
	<li>
		<p style="padding:0px;">
			And as final accord you can check whether you gathered enough ANY traces to be analyzed and sneak-peek what processes are producing excess load
		</p>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">grep -ha<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"from auditd"</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/var/log/kaspersky/epagent/lena* | grep -oE<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"\"exe\"\:\[\"[^\"]+\""</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">| sort | uniq -c | sort -nr | sed -e<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">'s/$/\]/'</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">| grep -E<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"[0-9]{3,}\s+\""</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>
	</li>
	<li>
		Collect the produced logs and system information in one go using<span> </span><strong><a href="https://support.kaspersky.com/collect" rel="external nofollow" style="color:#265951;">collect.sh script</a></strong>
	</li>
</ol>

<h2 style="border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	How to: enable LENA debug traces
</h2>

<p style="padding:0px;">
	Debug traces take less space and are suitable for troubleshooting issues<span> </span><strong>not-related to Performance or 3rd party compatibility</strong>.
</p>

<ol>
	<li>
		<p style="padding:0px;">
			Enable<span> </span><strong>debug<span> </span></strong>traces:
		</p>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/opt/kaspersky/epagent/sbin/lenactl --traces --on</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>

		<div style="border:1px solid #d04437;color:#333333;padding:10px 10px 10px 36px;">
			<div style="padding:0px;">
				<p style="padding:0px;">
					This method is not suitable for ANY traces and will override ANY traces level set previously by DEBUG value
				</p>
			</div>
		</div>
	</li>
	<li>
		<span>Wait for a while until the problematic behavior is reproduced;</span>
	</li>
	<li>
		<p style="padding:0px;">
			Disable traces:
		</p>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/opt/kaspersky/epagent/sbin/lenactl --traces --off</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>
	</li>
	<li>
		Collect the produced logs and system information in one go using<span> </span><strong><a href="https://support.kaspersky.com/collect" rel="external nofollow" style="color:#265951;">collect.sh script</a></strong>
	</li>
</ol>

<h2 style="border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	How to: enable LENA log rotation
</h2>

<ol>
	<li>
		<p style="padding:0px;">
			To add log rotation,<span> </span><span>add to<span> </span></span><code><span><strong>/etc/opt/kaspersky/epagent/service.conf</strong></span></code><span><span> </span>following strings:</span>
		</p>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="border-bottom:1px solid #cccccc;padding:5px 15px;text-align:left;">
				<b style="color:#333333;">/etc/opt/kaspersky/epagent/service.conf</b>
			</div>

			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">LENA_ROTATION_COUNT=</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">10</code>        <span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">&lt;--  set max number of log files</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">LENA_ROTATION_FILE_SIZE=100m    &lt;--  set the size of each file</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>
	</li>
	<li>
		<p style="padding:0px;">
			<span><span>To apply changes, restart<span> </span><code>epagent</code><span> </span>service</span></span>
		</p>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">systemctl restart epagent</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>
	</li>
</ol>
]]></description><guid isPermaLink="false">38150</guid><pubDate>Sat, 23 Dec 2023 16:43:41 +0000</pubDate></item><item><title>How to remotely uninstall KEA Core Patches through KSC [Kaspersky Endpoint Agent]</title><link>https://forum.kaspersky.com/topic/how-to-remotely-uninstall-kea-core-patches-through-ksc-kaspersky-endpoint-agent-38149/</link><description><![CDATA[<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/advice-and-solutions-forum-knowledgebase-disclaimer-read-before-using-materials-36464/" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.</span></a></span>
</h2>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	Most of the time KEA core patches are cumulative and it is sufficient to install the newer one on top of the previous in order to fix new issues.
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	However, sometimes, for troubleshooting purposes or otherwise, you would need to remove an existing patch. This is how it's done.
</p>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	Step-by-step guide
</h2>

<ol style="background-color:#ffffff;color:#172b4d;font-size:14px;">
	<li>
		In the Administration Console, go to<span> </span><strong>Advanced → Remote installation → Installation packages;</strong>
	</li>
	<li>
		In the right frame, click<span> </span><strong>Create installation package</strong>;
	</li>
	<li>
		Select<span> </span><strong>Create installation package for specified executable file</strong>;
	</li>
	<li>
		Enter the name for the package and click<span> </span><strong>Next</strong>;
	</li>
	<li>
		Click<span> </span><strong>Select</strong><span> </span>and specify the path to the MSP file with the patch. The file must be located in the folder with MSP and MSI files of the major application version;
	</li>
	<li>
		<p style="padding:0px;">
			In the Executable file command line field enter the following:  
		</p>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/i &lt;GUID KEA&gt; MSIPATCHREMOVE={GUID of Core} /qn</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>

		<p style="padding:0px;">
			<span>Example of the path to uninstall KEA 3.9 Core 11:</span>
		</p>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/i {B310DC3B-8C5A-4C9D-A054-DFEEF8549B9B} MSIPATCHREMOVE={3891229E-A660-</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">4416</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-B662-F5ED41B7B771} /qn</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>

		<p style="padding:0px;">
			<span>GUIDs of KEA msi and Core msp files can be found into properties of these files under<span> </span><strong>Details</strong> tab in the<span> </span><strong>Revision</strong><span> </span><strong>Number</strong><span> </span>line</span>
		</p>
	</li>
	<li>
		Click<span> </span><strong>Next→ Finish</strong>;
	</li>
	<li>
		Create a remote installation task with this installation package for a device or a group of devices;
	</li>
	<li>
		Run the task to remove the patch.
	</li>
</ol>
]]></description><guid isPermaLink="false">38149</guid><pubDate>Sat, 23 Dec 2023 16:36:54 +0000</pubDate></item><item><title>How to install patches on password-protected KEA [Kaspersky Endpoint Agent]</title><link>https://forum.kaspersky.com/topic/how-to-install-patches-on-password-protected-kea-kaspersky-endpoint-agent-38148/</link><description><![CDATA[<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/advice-and-solutions-forum-knowledgebase-disclaimer-read-before-using-materials-36464/" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.</span></a></span>
</h2>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	As the first step of troubleshooting of KEA, we recommend installing the latest core patch.
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	However, sometimes such installation will fail. There are two popular causes of this:
</p>

<ol style="background-color:#ffffff;color:#172b4d;font-size:14px;">
	<li>
		EULA is not accepted;
	</li>
	<li>
		KEA installation is protected with a password.
	</li>
</ol>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	This guide addresses both of these issues.
</p>

<div style="border:1px solid #d04437;color:#333333;font-size:14px;padding:10px 10px 10px 36px;">
	<p style="padding:0px;">
		# in Password Symbol
	</p>

	<div style="padding:0px;">
		<p style="padding:0px;">
			Due to limitations in KSC, when creating a custom package for remote deployment in KSC, or editing package configuration file (.kpd) directly, if password contains "#"  symbol, it won't work. Examination of saved package shows everything afterwards and including # is lost from command line. This is because in (.kpd) configuration files # is a sign of a single string comment. Thus # is invalid symbol and cannot be used in command line. Behavior is expected from KSC side and cannot be changed. We recommend not to use # in password.
		</p>
	</div>
</div>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	Step-by-step guide
</h2>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	The following options need to be provided to the installer:
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">disclaimer=</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">1</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	This instructs the installer to accept the EULA. 
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">UNLOCK_PASSWORD=password</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	This is required if the installation of KEA is protected with a password. Replace "<em>password</em>" with the actual value of the password.
</p>

<h3 style="background-color:#ffffff;color:#000000;font-size:16px;padding:0px;">
	Local installation
</h3>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	The resulting line for local installation may look like this:
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">msiexec /p critical_fix_core9(</code><code style="border:0px;color:#336699;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">private</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">).msp disclaimer=</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">1</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">UNLOCK_PASSWORD=password</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<h3 style="background-color:#ffffff;color:#000000;font-size:16px;padding:0px;">
	Remote installation
</h3>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	The same options can be used when deploying remotely via KSC. Specify them as follows:
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<a class="ipsAttachLink ipsAttachLink_image" data-fileext="png" data-fileid="15626" href="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.649dfb5b5bc95e2ca78466c3290e4516.png" rel=""><img alt="image.thumb.png.53e2b05b7962872f13a47fd01eb92974.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15626" data-ratio="102.34" style="height:auto;" width="684" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.thumb.png.53e2b05b7962872f13a47fd01eb92974.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
</p>
]]></description><guid isPermaLink="false">38148</guid><pubDate>Sat, 23 Dec 2023 16:27:42 +0000</pubDate></item><item><title>How to upgrade password protected KEA with KSC task [Kaspersky Endpoint Agent]</title><link>https://forum.kaspersky.com/topic/how-to-upgrade-password-protected-kea-with-ksc-task-kaspersky-endpoint-agent-38147/</link><description><![CDATA[<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/advice-and-solutions-forum-knowledgebase-disclaimer-read-before-using-materials-36464/" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.</span></a></span>
</h2>

<p style="padding:0px;">
	How to upgrade previously installed password protected KEA using KSC remote installation task.
</p>

<h2 style="border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	Step-by-step guide
</h2>

<ol>
	<li>
		Edit attached file <code><a href="https://box.kaspersky.com/f/d31c731547be4811a24a/?dl=1" rel="external nofollow">install_props.json</a></code>, put there your password for already installed KEA;
	</li>
	<li>
		Put this file to folder on KSC containing files for creation of remote installation package for new KEA version as per screenshots below;
	</li>
	<li>
		Create on KSC package for remote installation;
	</li>
	<li>
		<p style="padding:0px;">
			Start remote installation task on KSC.
		</p>

		<div style="padding:0px;">
			<div style="padding:0px;">
				<p style="padding:0px;">
					<a class="ipsAttachLink ipsAttachLink_image" data-fileext="png" data-fileid="15624" href="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.4c8708d22c8d95458feb435cf66a17b0.png" rel=""><img alt="image.thumb.png.27b449aa7b97e8cbb958b6db9cd5fba2.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15624" data-ratio="31.00" style="height:auto;" width="700" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.thumb.png.27b449aa7b97e8cbb958b6db9cd5fba2.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
				</p>

				<p style="padding:0px;">
					 
				</p>

				<p style="padding:0px;">
					<a class="ipsAttachLink ipsAttachLink_image" data-fileext="png" data-fileid="15625" href="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.99b24e863b7c821cb2485a445707bb25.png" rel=""><img alt="image.thumb.png.8a21b0c4f6fab306189fbe4979a2c2ff.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15625" data-ratio="23.29" style="height:auto;" width="700" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.thumb.png.8a21b0c4f6fab306189fbe4979a2c2ff.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
				</p>
			</div>
		</div>
	</li>
</ol>
]]></description><guid isPermaLink="false">38147</guid><pubDate>Sat, 23 Dec 2023 16:19:08 +0000</pubDate></item><item><title>How to change installed components for built-in KEA [Kaspersky Endpoint Agent]</title><link>https://forum.kaspersky.com/topic/how-to-change-installed-components-for-built-in-kea-kaspersky-endpoint-agent-38146/</link><description><![CDATA[<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/advice-and-solutions-forum-knowledgebase-disclaimer-read-before-using-materials-36464/" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.</span></a></span>
</h2>

<h1 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:24px;padding:0px;">
	Problem
</h1>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	If you install standalone Kaspersky Endpoint Agent, both KSC installation package and local installer provide option to choose, which KEA components to install:
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<a class="ipsAttachLink ipsAttachLink_image" data-fileext="png" data-fileid="15622" href="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.0c78759af66b103609e8183f520b0c15.png" rel=""><img alt="image.thumb.png.08bf107794f645e55cd73c99bee632fb.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15622" data-ratio="77.29" style="height:auto;" width="700" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.thumb.png.08bf107794f645e55cd73c99bee632fb.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a><a class="ipsAttachLink ipsAttachLink_image" data-fileext="png" data-fileid="15623" href="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.ac56d239ed52169acfe8357f0260f8eb.png" rel=""><img alt="image.thumb.png.df12c96ef310fdcd1cd0322e92e6ce9c.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15623" data-ratio="94.14" style="height:auto;" width="700" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.thumb.png.df12c96ef310fdcd1cd0322e92e6ce9c.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	However, when KEA is installed in built-in scenario, bundled with KES or KSWS, you don't get to choose and KEA is installed in default configuration, with all the components.
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	There's a way to select installed KEA components even for built-in scenarios.
</p>

<h1 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:24px;padding:0px;">
	Using install_props.json for changing installed components
</h1>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	As<span> </span><u><a href="https://support.kaspersky.com/KATA/3.7/en-US/195714.htm" rel="external nofollow" style="color:#265951;">KEA section of Online Help</a></u><span> </span>states, it is possible to configure installation options via<span> </span><code><strong>install_props.json</strong></code>. EDR Optimum help even describes<span> </span><u><a href="https://support.kaspersky.com/KEDR_Optimum/1.0/en-US/195561.htm" rel="external nofollow" style="color:#265951;">how to use it for built-in scenario</a></u>. However, installer options for components selection are not covered by Online Help.
</p>

<h4 style="background-color:#ffffff;color:#000000;font-size:14px;padding:0px;">
	Directives and values
</h4>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<code>ADDLOCAL</code><span> </span>directive defines, which components of KEA will be installed.
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<code>REMOVE</code><span> </span>directive defines which components will not be installed.
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	There are<span> </span><span>five</span> possible values for directives in KEA now:
</p>

<div style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<table style="border-collapse:collapse;padding:0px;">
		<colgroup>
			<col />
			<col />
		</colgroup>
		<thead>
			<tr>
				<th scope="col" style="border:1px solid #c1c7d0;color:#000000;padding:0px;text-align:left;vertical-align:top;">
					<div style="color:#000000;padding:0px;">
						Name
					</div>
				</th>
				<th scope="col" style="border:1px solid #c1c7d0;color:#000000;padding:0px;text-align:left;vertical-align:top;">
					<div style="color:#000000;padding:0px;">
						Feature
					</div>
				</th>
			</tr>
		</thead>
		<tbody>
			<tr>
				<td style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					ALL
				</td>
				<td style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					Default value. Installs all available features, can only be used this way: ADDLOCAL=ALL
				</td>
			</tr>
			<tr>
				<td style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					Core
				</td>
				<td style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					Core functionality of Endpoint Agent. Must be installed.
				</td>
			</tr>
			<tr>
				<td style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					KATA
				</td>
				<td style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					KATA/EDR Expert and other message brokers integration.
				</td>
			</tr>
			<tr>
				<td style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					SB
				</td>
				<td style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					Kaspersky Sandbox integration
				</td>
			</tr>
			<tr>
				<td style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					EDR
				</td>
				<td style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					EDR Optimum
				</td>
			</tr>
		</tbody>
	</table>
</div>

<h4 style="background-color:#ffffff;color:#000000;font-size:14px;padding:0px;">
	Example
</h4>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	This example will install Endpoint Agent with KATA integration, but without Kaspersky Sandbox integration:
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">[Setup]</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										 
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">ADDLOCAL=Core,KATA</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										 
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">REMOVE=SB</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<h4 style="background-color:#ffffff;color:#000000;font-size:14px;padding:0px;">
	How to use the file
</h4>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	File <a href="https://box.kaspersky.com/f/30b09cb54e4e458fa9d9/?dl=1" rel="external nofollow">(example)</a> with options should be placed next to the Kaspersky Endpoint Agent installer,<span> </span><code>endpointagent.msi</code>.
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	For the remote installation via KSC, location should be similar to
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">C:\ProgramData\KasperskyLab\adminkit\</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">1093</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">\.working\share\Packages\KES_&lt;version&gt;\exec\agent</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>
]]></description><guid isPermaLink="false">38146</guid><pubDate>Sat, 23 Dec 2023 16:10:27 +0000</pubDate></item><item><title>How to configure KEA exclusions required for KEA on AD controllers [Kaspersky Endpoint Agent]</title><link>https://forum.kaspersky.com/topic/how-to-configure-kea-exclusions-required-for-kea-on-ad-controllers-kaspersky-endpoint-agent-38145/</link><description><![CDATA[<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/advice-and-solutions-forum-knowledgebase-disclaimer-read-before-using-materials-36464/" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.</span></a></span>
</h2>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	Problem
</h2>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	How to configure KEA exclusions required for KEA installed on AD controllers to prevent its slowdown and high hardware resources consumption.
</p>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	Step-by-step guide
</h2>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	Add the following registry key to affected AD controller registry:
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<code>[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\KasperskyLab\SOYUZ\4.0\Environment]</code><br />
	<code>"EnablePorts"=dword:00000001</code><br />
	<code>"EnableSignatureLevel"=dword:00000001</code><br />
	<code>"ServerProfile"=dword:0000000a</code>
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	This operation should be done as<span> </span><strong>Local System</strong><span> </span>account (either locally via psexec or via<span> </span><code>.bat</code><span> </span><a href="https://box.kaspersky.com/f/f25bec72a9e14c1eb58a/?dl=1" rel="external nofollow">script (attached)</a><span> </span>deployed via KSC and Network Agent).
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	Please restart<span> </span><strong>Endpoint Agent</strong><span> </span>service after this change.
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<span>This option will make KEA exclude the ports:</span>
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">Exclusions WinRM</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">Exclution DHCP</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">Exclude DNS</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">Exclude SSDP</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">Exclude mDNS</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">Exclude LLMNR</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">Exclusions RPC/NetBios</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">Exclude LDAP</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">Exclude Kerberos</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">Networking and RabbitMQ</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">Exclude     Delivery Optimization<span> </span></code><code style="border:0px;color:#336699;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">for</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">Windows<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">10</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">[</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">244</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">]</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">Exclusions Microsoft SQL Server database management system (MSSQL) server</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">Exclusions In Windows Server<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">2008</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">(and Windows Vista), the dynamic port range is<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">49152</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">65535</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">,<span> </span></code><code style="border:0px;color:#336699;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">for</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">both TCP and UDP.</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>
]]></description><guid isPermaLink="false">38145</guid><pubDate>Sat, 23 Dec 2023 15:57:40 +0000</pubDate></item><item><title>How to enable KEA traces and dumps: all the options [Kaspersky Endpoint Agent]</title><link>https://forum.kaspersky.com/topic/how-to-enable-kea-traces-and-dumps-all-the-options-kaspersky-endpoint-agent-38144/</link><description><![CDATA[<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/advice-and-solutions-forum-knowledgebase-disclaimer-read-before-using-materials-36464/" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.</span></a></span>
</h2>

<div style="color:rgb(23,43,77);font-size:14px;padding:0px;">
	<p style="background-color:rgb(255,255,255);padding:0px;">
		Kaspersky Endpoint Agent, as many other products, has a few different ways of enabling traces.
	</p>

	<div style="background-color:rgb(255,255,255);border:1px solid rgb(208,68,55);color:rgb(51,51,51);padding:10px 10px 10px 36px;">
		<p style="padding:0px;">
			Traces folder
		</p>

		<div style="padding:0px;">
			<p style="padding:0px;">
				NB! The folder specified for traces must exist and be writable. KEA will neither create folder nor display any error if it doesn't exist.
			</p>
		</div>
	</div>

	<p style="background-color:rgb(255,255,255);padding:0px;">
		One may choose which is best suitable for their needs:
	</p>

	<h2 style="background-color:rgb(255,255,255);border-bottom-color:rgb(126,255,51);color:rgb(0,0,0);font-size:20px;padding:0px;">
		Traces with restart
	</h2>

	<p style="background-color:rgb(255,255,255);padding:0px;">
		In 99% cases, information that is written only during initialization, that is, after KEA restart, is critical for investigation. Unless specified otherwise, always perform KEA restart when collecting traces (after traces are enabled), either by restarting KEA service , via<span> </span><code>services.msc</code>
	</p>

	<p style="background-color:rgb(255,255,255);padding:0px;">
		In some cases, Kaspersky Support Engineer may ask to perform the restart after the reproduction, in that case, restart KEA not after starting traces, but 2 minutes before stopping traces.
	</p>

	<p style="background-color:rgb(255,255,255);padding:0px;">
		<a class="ipsAttachLink ipsAttachLink_image" data-fileext="png" data-fileid="15617" href="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.3407a595650214167626be79e05ae1cd.png" rel=""><img alt="image.thumb.png.cb6addf8b5e4002336ce28d7872c9e7a.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15617" data-ratio="39.14" style="height:auto;" width="700" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.thumb.png.cb6addf8b5e4002336ce28d7872c9e7a.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
	</p>

	<p style="background-color:rgb(255,255,255);padding:0px;">
		or using CLI:
	</p>

	<div style="background-color:rgb(255,255,255);border:1px solid rgb(223,225,229);color:rgb(51,51,51);padding:0px;">
		<div style="border-bottom:1px solid #cccccc;padding:5px 15px;text-align:left;">
			<b style="color:#333333;">Elevated cmd (as Admin)</b>
		</div>

		<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
			<div style="padding:0px;">
				<div style="background-color:#ffffff;font-size:1em;padding:0px;">
					<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
									<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
										<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
											<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">sc restart soyuz</code>
										</div>
									</div>
								</td>
							</tr>
						</tbody>
					</table>
				</div>
			</div>
		</div>
	</div>

	<p style="background-color:rgb(255,255,255);padding:0px;">
		Verification: traces with restart will always contain the lines with the below text:
	</p>

	<div style="background-color:rgb(255,255,255);border:1px solid rgb(223,225,229);color:rgb(51,51,51);padding:0px;">
		<div style="border-bottom:1px solid #cccccc;padding:5px 15px;text-align:left;">
			<b style="color:#333333;">Traces with restart</b>
		</div>

		<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
			<div style="padding:0px;">
				<div style="background-color:#ffffff;font-size:1em;padding:0px;">
					<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
									<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
										<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
											<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">kata.</code>
										</div>

										<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
											<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">codeinjection.rule</code>
										</div>
									</div>
								</td>
							</tr>
						</tbody>
					</table>
				</div>
			</div>
		</div>
	</div>

	<p style="background-color:rgb(255,255,255);padding:0px;">
		If the text is nowhere to be found, traces are collected without restart and are of zero to no use, such traces need to be recollected following the procedure.
	</p>

	<h2 style="background-color:rgb(255,255,255);border-bottom-color:rgb(126,255,51);color:rgb(0,0,0);font-size:20px;padding:0px;">
		Using the agent.exe utility
	</h2>

	<p style="background-color:rgb(255,255,255);padding:0px;">
		<span>When working with KEA on local host, use<span> </span></span><code><span>cmd</span></code><span><span> </span>or<span> </span></span><code><span>Powershell</span></code><span>, started as Administrator, however i<span>n some cases KEA installation folder is restricted and requires Local System account to be accessed (one can use Windows Scheduler or, if approved, psexec tool to execute command under Local System).</span></span>
	</p>

	<p style="background-color:rgb(255,255,255);padding:0px;">
		<span>To enable KEA traces:</span>
	</p>

	<div style="background-color:rgb(255,255,255);border:1px solid rgb(223,225,229);color:rgb(51,51,51);padding:0px;">
		<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
			<div style="padding:0px;">
				<div style="background-color:#ffffff;font-size:1em;padding:0px;">
					<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
									<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
										<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
											<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">C:\Program Files (x86)\Kaspersky Lab\Endpoint Agent&gt;agent.exe --trace enable --folder C:\path\to\folder</code>
										</div>
									</div>
								</td>
							</tr>
						</tbody>
					</table>
				</div>
			</div>
		</div>
	</div>

	<p style="background-color:rgb(255,255,255);padding:0px;">
		To disable traces:
	</p>

	<div style="background-color:rgb(255,255,255);border:1px solid rgb(223,225,229);color:rgb(51,51,51);padding:0px;">
		<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
			<div style="padding:0px;">
				<div style="background-color:#ffffff;font-size:1em;padding:0px;">
					<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
									<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
										<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
											<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">C:\Program Files (x86)\Kaspersky Lab\Endpoint Agent&gt;agent.exe --trace disable</code>
										</div>
									</div>
								</td>
							</tr>
						</tbody>
					</table>
				</div>
			</div>
		</div>
	</div>

	<h2 style="border-bottom-color:rgb(126,255,51);color:rgb(0,0,0);font-size:20px;padding:0px;">
		Modifying registry key
	</h2>

	<h3 style="background-color:rgb(255,255,255);color:rgb(0,0,0);font-size:16px;padding:0px;">
		Traces
	</h3>

	<p style="background-color:rgb(255,255,255);padding:0px;">
		This option is specifically useful when you have troubles starting KEA service. Modify the registry key:
	</p>

	<div style="background-color:rgb(255,255,255);border:1px solid rgb(223,225,229);color:rgb(51,51,51);padding:0px;">
		<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
			<div style="padding:0px;">
				<div style="background-color:#ffffff;font-size:1em;padding:0px;">
					<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
									<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
										<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
											<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\KasperskyLab\SOYUZ\</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">4.0</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">\Trace\Configuration</code>
										</div>
									</div>
								</td>
							</tr>
						</tbody>
					</table>
				</div>
			</div>
		</div>
	</div>

	<p style="background-color:rgb(255,255,255);padding:0px;">
		For your convenience, there's also a registry key with example of Debug configuration next to this one:
	</p>

	<div style="background-color:rgb(255,255,255);border:1px solid rgb(223,225,229);color:rgb(51,51,51);padding:0px;">
		<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
			<div style="padding:0px;">
				<div style="background-color:#ffffff;font-size:1em;padding:0px;">
					<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
									<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
										<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
											<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\KasperskyLab\SOYUZ\</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">4.0</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">\Trace\Configuration(Example)</code>
										</div>

										<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
											<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">logging=on;layout=basic;sub-system=*;sink=folder(c:\traces\);level=debug;roll=</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">51200</code>
										</div>
									</div>
								</td>
							</tr>
						</tbody>
					</table>
				</div>
			</div>
		</div>
	</div>

	<p style="background-color:rgb(255,255,255);padding:0px;">
		Notice that in this example traces folder is configured to be<span> </span><code><strong>c:\traces\</strong></code>. As previously mentioned, the folder specified for traces must exist and be writable so if you decide to use this configuration "as is" you need to create<span> </span><code><strong>c:\traces<span> </span></strong></code>folder manually.
	</p>

	<p style="background-color:rgb(255,255,255);padding:0px;">
		To disable traces, restore original content of the registry key (<code>logging=off</code><span class="ipsEmoji">😞</span>
	</p>

	<div style="background-color:rgb(255,255,255);border:1px solid rgb(223,225,229);color:rgb(51,51,51);padding:0px;">
		<div style="border-bottom:1px solid #cccccc;padding:5px 15px;text-align:left;">
			<b style="color:#333333;">Disable traces</b>
		</div>

		<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
			<div style="padding:0px;">
				<div style="background-color:#ffffff;font-size:1em;padding:0px;">
					<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
									<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
										<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
											<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\KasperskyLab\SOYUZ\</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">4.0</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">\Trace\Configuration</code>
										</div>

										<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
											<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">logging=off</code>
										</div>
									</div>
								</td>
							</tr>
						</tbody>
					</table>
				</div>
			</div>
		</div>
	</div>

	<h3 style="background-color:rgb(255,255,255);color:rgb(0,0,0);font-size:16px;padding:0px;">
		Dumps
	</h3>

	<div style="background-color:rgb(255,255,255);border:1px solid rgb(223,225,229);color:rgb(51,51,51);padding:0px;">
		<div style="border-bottom:1px solid #cccccc;padding:5px 15px;text-align:left;">
			<b style="color:#333333;">Enable dumps</b>
		</div>

		<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
			<div style="padding:0px;">
				<div style="background-color:#ffffff;font-size:1em;padding:0px;">
					<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
									<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
										<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
											<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\KasperskyLab\SOYUZ\</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">4.0</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">\CrashDump</code>
										</div>

										<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
											 
										</div>

										<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
											<code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"Enable"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">=dword:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">00000001</code>
										</div>

										<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
											<code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"Folder"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">=</code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"c:\\traces\\"</code>
										</div>

										<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
											<code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"Enable(Example)"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">=dword:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">00000001</code>
										</div>

										<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
											<code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"Folder(Example)"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">=</code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"c:\\traces\\"</code>
										</div>
									</div>
								</td>
							</tr>
						</tbody>
					</table>
				</div>
			</div>
		</div>
	</div>

	<p style="background-color:rgb(255,255,255);padding:0px;">
		Notice that in this example dump folder is configured to be<span> </span><code><strong>c:\traces\</strong></code>. This folder must exist and be writable so if you decide to use this configuration "as is" you need to create<span> </span><code><strong>c:\traces<span> </span></strong></code>folder manually.
	</p>

	<p style="background-color:rgb(255,255,255);padding:0px;">
		To disable traces, restore original content of the registry key:
	</p>

	<div style="background-color:rgb(255,255,255);border:1px solid rgb(223,225,229);color:rgb(51,51,51);padding:0px;">
		<div style="border-bottom:1px solid #cccccc;padding:5px 15px;text-align:left;">
			<b style="color:#333333;">Disable dumps</b>
		</div>

		<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
			<div style="padding:0px;">
				<div style="background-color:#ffffff;font-size:1em;padding:0px;">
					<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
									<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
										<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
											<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\KasperskyLab\SOYUZ\</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">4.0</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">\CrashDump</code>
										</div>

										<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
											 
										</div>

										<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
											<code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"Enable"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">=dword:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">00000000</code>
										</div>
									</div>
								</td>
							</tr>
						</tbody>
					</table>
				</div>
			</div>
		</div>
	</div>

	<p style="background-color:rgb(255,255,255);padding:0px;">
		 
	</p>

	<h2 style="background-color:rgb(255,255,255);border-bottom-color:rgb(126,255,51);color:rgb(0,0,0);font-size:20px;padding:0px;">
		<span style="color:#000000;font-size:20px;">Using KSC console</span>
	</h2>

	<h3 style="background-color:rgb(255,255,255);color:rgb(0,0,0);font-size:16px;padding:0px;">
		Enabling traces and dumps
	</h3>

	<p style="background-color:rgb(255,255,255);padding:0px;">
		Execute the following steps:
	</p>

	<ol style="background-color:rgb(255,255,255);">
		<li>
			In the properties of target host in KSC console, locate Endpoint Agent app<br />
			<a class="ipsAttachLink ipsAttachLink_image" data-fileext="png" data-fileid="15619" href="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.b2172f023953d270d6d374689c64ecc8.png" rel=""><img alt="image.thumb.png.e266efba7999cda4bf7b5bc38bcdf41c.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15619" data-ratio="89.29" style="height:auto;" width="700" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.thumb.png.e266efba7999cda4bf7b5bc38bcdf41c.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
		</li>
		<li>
			Open Properties of Endpoint Agent, and navigate to Troubleshooting tab and enable traces and dumps(if needed).<br />
			<strong><span style="color:#ff0000;">NB! It's recommended to write traces to<span> </span></span><code>C:\ProgramData\Kaspersky Lab<span>\</span></code><span><span> </span>folder</span>!</strong><br />
			To be able to retrieve the traces using Remote Diagnostics Utility configure the traces folder to be the same as respective EPP traces folder, e.g.:<br />
			For KES <strong><span> </span>%ProgramData%\Kaspersky Lab\KES\Traces</strong><br />
			<span>For KSWS</span><strong><span> </span>%programfiles(x86)%\Kaspersky Lab\Kaspersky Security for Windows Server\~TraceFiles</strong><br />
			<a class="ipsAttachLink ipsAttachLink_image" data-fileext="png" data-fileid="15618" href="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.b3279ce0a734427239d3f0aa87d948e7.png" rel=""><img alt="image.thumb.png.a0837fc9ddb269f3b4345ca0c1c330bc.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15618" data-ratio="93.14" style="height:auto;" width="700" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.thumb.png.a0837fc9ddb269f3b4345ca0c1c330bc.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
		</li>
	</ol>

	<h3 style="background-color:rgb(255,255,255);color:rgb(0,0,0);font-size:16px;padding:0px;">
		Retrieving traces
	</h3>

	<p style="background-color:rgb(255,255,255);padding:0px;">
		To download files remotely, execute the following steps:
	</p>

	<ol style="background-color:rgb(255,255,255);">
		<li>
			Connect to target host with Remote Diagnostics Utility
		</li>
		<li>
			Navigate to KES Trace files folder:<br />
			<a class="ipsAttachLink ipsAttachLink_image" data-fileext="png" data-fileid="15620" href="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.2363aef92fdb6381aab781d599559b1f.png" rel=""><img alt="image.thumb.png.843369947b953f5868e57747c20eeffb.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15620" data-ratio="48.00" style="height:auto;" width="700" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.thumb.png.843369947b953f5868e57747c20eeffb.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
		</li>
		<li>
			Locate<span> </span><code>soyuz_*.log, proton_*.log, klnagent_*.log</code><span> </span>- these are Endpoint Agent trace files:<br />
			<a class="ipsAttachLink ipsAttachLink_image" data-fileext="png" data-fileid="15621" href="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.038ce3ef4afc5780a8b7ea49d6ee119d.png" rel=""><img alt="image.thumb.png.cb18805b7a442551554a89f18913ed66.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15621" data-ratio="29.14" style="height:auto;" width="700" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.thumb.png.cb18805b7a442551554a89f18913ed66.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
		</li>
		<li>
			Download these files using the 'Download' button.
		</li>
	</ol>

	<h2 style="background-color:rgb(255,255,255);border-bottom-color:rgb(126,255,51);color:rgb(0,0,0);font-size:20px;padding:0px;">
		Enabling traces from installation
	</h2>

	<p style="background-color:rgb(255,255,255);padding:0px;">
		<u style="background-color:#fcfcfc;color:#333333;font-size:14px;"><a href="https://forum.kaspersky.com/topic/how-to-enable-kea-traces-from-installation-kaspersky-endpoint-agent-38143/" rel="" style="color:#265951;">https://forum.kaspersky.com/topic/how-to-enable-kea-traces-from-installation-kaspersky-endpoint-agent-38143/</a></u>
	</p>
</div>
]]></description><guid isPermaLink="false">38144</guid><pubDate>Sat, 23 Dec 2023 15:51:56 +0000</pubDate></item><item><title>How to enable KEA traces from installation [Kaspersky Endpoint Agent]</title><link>https://forum.kaspersky.com/topic/how-to-enable-kea-traces-from-installation-kaspersky-endpoint-agent-38143/</link><description><![CDATA[<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/advice-and-solutions-forum-knowledgebase-disclaimer-read-before-using-materials-36464/" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.</span></a></span>
</h2>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	Sometimes, you may want to have Kaspersky Endpoint Agent traces which start<span> </span><em>from its very cradle.<span> </span></em>This guide is applicable to local installation.
</p>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	Step-by-step guide
</h2>

<ol style="background-color:#ffffff;color:#172b4d;font-size:14px;">
	<li>
		Place the<span> </span><a href="https://box.kaspersky.com/f/3d3f3f5922134309821d/?dl=1" rel="external nofollow">attached JSON</a><span> </span>file next to<span> </span><code>endpointagent.msi</code><span> </span>file. Feel free to modify patch to traces folder inside.
	</li>
	<li>
		<p style="padding:0px;">
			Install Endpoint Agent using GUI or command line:
		</p>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">msiexec /i endpointagent.msi /qn</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>
	</li>
</ol>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	Traces will appear as soon as the services start, even before the installation completes.
</p>
]]></description><guid isPermaLink="false">38143</guid><pubDate>Sat, 23 Dec 2023 15:43:15 +0000</pubDate></item><item><title>How to check KEA bases version [Kaspersky Endpoint Agent]</title><link>https://forum.kaspersky.com/topic/how-to-check-kea-bases-version-kaspersky-endpoint-agent-38142/</link><description><![CDATA[<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/advice-and-solutions-forum-knowledgebase-disclaimer-read-before-using-materials-36464/" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.</span></a></span>
</h2>

<div style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<p style="padding:0px;">
		Configuring<span> </span><a href="https://support.kaspersky.com/KEA/3.13/en-US/193067.htm" rel="external nofollow" style="color:#265951;">KEA update task</a><span> </span>is of crucial importance. Updated KATA telemetry filters, exclusions and performance optimizations are delivered via bases. However, KEA has no transparent means to check bases version locally.
	</p>

	<p style="padding:0px;">
		The solution to this demand is to check bases version locally via CLI.
	</p>

	<h3 style="color:#000000;font-size:16px;padding:0px;">
		KEA for Windows bases date
	</h3>

	<p style="padding:0px;">
		From Elevated Command Prompt, execute:
	</p>

	<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
		<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
			<div style="padding:0px;">
				<div style="background-color:#ffffff;font-size:1em;padding:0px;">
					<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
									<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
										<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
											<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">type<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"C:\ProgramData\Kaspersky Lab\Endpoint Agent\4.0\Bases\Current\aptem.stt"</code>
										</div>
									</div>
								</td>
							</tr>
						</tbody>
					</table>
				</div>
			</div>
		</div>
	</div>

	<p style="padding:0px;">
		The example output is as follows,
	</p>

	<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
		<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
			<div style="padding:0px;">
				<div style="background-color:#ffffff;font-size:1em;padding:0px;">
					<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
									<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
										<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
											<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">;</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">202209190911</code>
										</div>
									</div>
								</td>
							</tr>
						</tbody>
					</table>
				</div>
			</div>
		</div>
	</div>

	<p style="padding:0px;">
		Format is ;<strong>YYYYMMDDHHMM</strong>
	</p>

	<h3 style="color:#000000;font-size:16px;padding:0px;">
		KEA for Linux (LENA) bases date
	</h3>

	<div style="border:1px solid #aab8c6;color:#333333;padding:10px 10px 10px 36px;">
		<p style="padding:0px;">
			Fresh installation
		</p>

		<div style="padding:0px;">
			<p style="padding:0px;">
				For a fresh LENA installation that has never been updated, the bases "aptem.stt" file might be missing.
			</p>
		</div>
	</div>

	<p style="padding:0px;">
		From root or using sudo:
	</p>

	<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
		<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
			<div style="padding:0px;">
				<div style="background-color:#ffffff;font-size:1em;padding:0px;">
					<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
									<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
										<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
											<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">sudo cat /var/opt/kaspersky/epagent/update/bases/aptem.stt</code>
										</div>
									</div>
								</td>
							</tr>
						</tbody>
					</table>
				</div>
			</div>
		</div>
	</div>

	<p style="padding:0px;">
		Output format is the same,  ;<strong>YYYYMMDDHHMM. <span> </span></strong>Using built-in tools, we can easily make it in a proper way:
	</p>

	<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
		<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
			<div style="padding:0px;">
				<div style="background-color:#ffffff;font-size:1em;padding:0px;">
					<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
									<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
										<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
											<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">sudo cat /var/opt/kaspersky/epagent/update/bases/aptem.stt | sed -E<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">'s/\;([0-9]{8})([0-9]{2})([0-9]{2})/\1 \2:\3/g'</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">| xargs -</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">date -d</code>
										</div>
									</div>
								</td>
							</tr>
						</tbody>
					</table>
				</div>
			</div>
		</div>
	</div>

	<h3 style="color:#000000;font-size:16px;padding:0px;">
		Bonus: LENA's Last update date
	</h3>

	<p style="padding:0px;">
		Lena's Last update date is stored in epoch format in /opt/kaspersky/epagent/update/last_update. Using built-in tools, we can make it human-readable: 
	</p>

	<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
		<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
			<div style="padding:0px;">
				<div style="background-color:#ffffff;font-size:1em;padding:0px;">
					<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
									<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
										<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
											<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">sudo cat /var/opt/kaspersky/epagent/update/last_update | xargs -</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-I% date -d \@%</code>
										</div>
									</div>
								</td>
							</tr>
						</tbody>
					</table>
				</div>
			</div>
		</div>
	</div>

	<p style="padding:0px;">
		It is also worth mentioning that "Last update date" is relevant but it is still entirely different value than bases date. In case the bases in repository are outdated, Last Update date may be 5 minutes ago, yet bases will remain old.
	</p>
</div>
]]></description><guid isPermaLink="false">38142</guid><pubDate>Sat, 23 Dec 2023 15:32:27 +0000</pubDate></item><item><title>How to change {admin} password on KATA 5.1 central node [KATA/KEDRE]</title><link>https://forum.kaspersky.com/topic/how-to-change-admin-password-on-kata-51-central-node-katakedre-38138/</link><description><![CDATA[<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/advice-and-solutions-forum-knowledgebase-disclaimer-read-before-using-materials-36464/" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.</span></a></span>
</h2>

<h2 style="border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="color:#339966;">Description and cautions</span>
</h2>

<p style="padding:0px;">
	One may need to change the admin account's password (the account used for SSH login).
</p>

<div style="border:1px solid #d04437;color:#333333;padding:10px 10px 10px 36px;">
	<p style="padding:0px;">
		KATA 5.0
	</p>

	<div style="padding:0px;">
		<p style="padding:0px;">
			For KATA 5.0 this article is not applicable. No option to change Local Administrator/ Cluster Administrator in pseudo-graphic menu available by default in 5.0 See <u style="background-color:#fcfcfc;color:#333333;font-size:14px;"><a href="https://forum.kaspersky.com/topic/how-to-reset-kata-web-administrator-password-in-kata-50-katakedre-36844/" rel="" style="color:#265951;">https://forum.kaspersky.com/topic/how-to-reset-kata-web-administrator-password-in-kata-50-katakedre-36844/</a></u>
		</p>
	</div>
</div>

<h2 style="border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="color:#339966;">Details</span>
</h2>

<p style="padding:0px;">
	<strong>In case of standalone Central node:</strong>
</p>

<ol>
	<li>
		Login to the web-interface of the CN.
	</li>
	<li>
		Enter admin credentials (used for SSH login).
	</li>
	<li>
		Go to admin account &gt; change password as per below
	</li>
</ol>

<p style="padding:0px;">
	<a class="ipsAttachLink ipsAttachLink_image" data-fileext="png" data-fileid="15615" href="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.b261e9ef8a58b120e79c9fe5dcf7668a.png" rel=""><img alt="image.thumb.png.0a055fe396d982944cfd0e57cbb9e9cf.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15615" data-ratio="202.31" style="height:auto;" width="346" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.thumb.png.0a055fe396d982944cfd0e57cbb9e9cf.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
</p>

<p style="padding:0px;">
	<strong>In case of Distributed deployment (PCN and SCN):</strong>
</p>

<ol>
	<li>
		Login to the web-interface of PCN.
	</li>
	<li>
		Enter admin credentials (used for SSH login).
	</li>
	<li>
		Go to admin account -&gt; change password
	</li>
	<li>
		Login to SCN via SSH and change using the pseudographic menu ("Change cluster admin password..." option)
	</li>
</ol>

<p style="padding:0px;">
	<img alt="image.png.f79810fe8335b23a408f2950c6eac98d.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15616" data-ratio="53.37" style="height:auto;" width="682" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.f79810fe8335b23a408f2950c6eac98d.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" />
</p>
]]></description><guid isPermaLink="false">38138</guid><pubDate>Sat, 23 Dec 2023 11:43:17 +0000</pubDate></item><item><title>Certified LENA 3.12 is not updating [Kaspersky Endpoint Agent]</title><link>https://forum.kaspersky.com/topic/certified-lena-312-is-not-updating-kaspersky-endpoint-agent-37989/</link><description><![CDATA[<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/advice-and-solutions-forum-knowledgebase-disclaimer-read-before-using-materials-36464/" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.</span></a></span>
</h2>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="color:#339966;">Issue</span>
</h2>

<ol style="background-color:#ffffff;color:#172b4d;font-size:14px;">
	<li>
		"Databases and modules update task" is configured for hosts with LENA 3.12 installed.
	</li>
	<li>
		Task is executed via KSC.
	</li>
</ol>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="color:#339966;">Diagnostics</span>
</h2>

<ol style="background-color:#ffffff;color:#172b4d;font-size:14px;">
	<li>
		"Activate KEA" task is configured for the hosts with LENA or has been configured and deleted in the past.
	</li>
	<li>
		An update is executed locally, using lenactl works.
	</li>
	<li>
		KLNagent successfully synchronizes with the server. Other installed applications (e.g. KESL) display no synchronization issues.
	</li>
</ol>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="color:#339966;">Workaround</span>
</h2>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	To fix the issue:
</p>

<ol style="background-color:#ffffff;color:#172b4d;font-size:14px;">
	<li>
		Remove the "Activate KEA" task or any other configured KEA tasks except for "Databases and modules update task" for hosts with LENA installed.
	</li>
	<li>
		If necessary, move hosts with LENA to a separate group or configure other desired KEA tasks using a selection for Windows hosts only.
	</li>
	<li>
		Ensure there are no tasks except for "Databases and modules update task" remaining for hosts with LENA installed in KSC.
	</li>
	<li>
		Option A. Reinstall LENA on hosts to get rid of cached activation tasks.
	</li>
	<li>
		Option B. Remove the problematic cached tasks locally:
		<ol>
			<li>
				Stop LENA:<br />
				<code># systemctl stop epagent</code>
			</li>
			<li>
				Remove the cached tasks:<br />
				<code># rm -rf /var/opt/kaspersky/epagent/tasks/*</code>
			</li>
			<li>
				Start LENA<br />
				<code># systemctl start epagent</code>
			</li>
			<li>
				Force synchronization with the host, e.g. by calling klnagchk.<br />
				<code># /opt/kaspersky/klnagent64/bin/klnagchk</code>
			</li>
			<li>
				Ensure one task is recieved.<br />
				<code># ll /var/opt/kaspersky/epagent/tasks/</code>
			</li>
		</ol>
	</li>
	<li>
		Execute "Databases and modules update task" on KSC. Ensure it finishes successfully.
	</li>
	<li>
		Double check locally that the bases are updated.
	</li>
</ol>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="color:#339966;">RCA</span>
</h2>

<ol style="background-color:#ffffff;color:#172b4d;font-size:14px;">
	<li>
		LENA connector that receives the product tasks from KLNagent is only configured to accept valid tasks ant halt synchronization if an invalid task is received.
	</li>
	<li>
		Only "Databases and modules update task" is considered to be valid for certified LENA version.
	</li>
	<li>
		"Activate KEA" task is received or cached first. Connector halts synchronization once it is processed.
	</li>
	<li>
		An update task is never received by the product.
	</li>
</ol>
]]></description><guid isPermaLink="false">37989</guid><pubDate>Sat, 16 Dec 2023 14:43:07 +0000</pubDate></item><item><title>Registry branches that are scanned by the IoC task [Kaspersky Endpoint Agent]</title><link>https://forum.kaspersky.com/topic/registry-branches-that-are-scanned-by-the-ioc-task-kaspersky-endpoint-agent-37988/</link><description><![CDATA[<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/advice-and-solutions-forum-knowledgebase-disclaimer-read-before-using-materials-36464/" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.</span></a></span>
</h2>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<strong>When creating an IoC scan task, only the following registry branches are scanned.</strong>
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<span style="color:#242424;">&lt;field name="predefined_keypaths" type="wstring" multi-valued="yes" default-value=</span><br />
	<span style="color:#242424;"><span>               </span>'{</span><br />
	<span style="color:#242424;"><span>                  </span>LR"(HKEY_CLASSES_ROOT\htafile)",</span><br />
	<span style="color:#242424;"><span>                  </span>LR"(HKEY_CLASSES_ROOT\batfile)",</span><br />
	<span style="color:#242424;"><span>                  </span>LR"(HKEY_CLASSES_ROOT\exefile)",</span><br />
	<span style="color:#242424;"><span>                  </span>LR"(HKEY_CLASSES_ROOT\comfile)",</span><br />
	<span style="color:#242424;"><span>                  </span>LR"(HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa)",</span><br />
	<span style="color:#242424;"><span>                  </span>LR"(HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Monitors)",</span><br />
	<span style="color:#242424;"><span>                  </span>LR"(HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\NetworkProvider)",</span><br />
	<span style="color:#242424;"><span>                  </span>LR"(HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Class)",</span><br />
	<span style="color:#242424;"><span>                  </span>LR"(HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders)",</span><br />
	<span style="color:#242424;"><span>                  </span>LR"(HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Terminal Server)",</span><br />
	<span style="color:#242424;"><span>                  </span>LR"(HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager)",</span><br />
	<span style="color:#242424;"><span>                  </span>LR"(HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services)",</span><br />
	<span style="color:#242424;"><span>                  </span>LR"(HKEY_LOCAL_MACHINE\Software\Classes\piffile)",</span><br />
	<span style="color:#242424;"><span>                  </span>LR"(HKEY_LOCAL_MACHINE\Software\Classes\htafile)",</span><br />
	<span style="color:#242424;"><span>                  </span>LR"(HKEY_LOCAL_MACHINE\Software\Classes\exefile)",</span><br />
	<span style="color:#242424;"><span>                  </span>LR"(HKEY_LOCAL_MACHINE\Software\Classes\comfile)",</span><br />
	<span style="color:#242424;"><span>                  </span>LR"(HKEY_LOCAL_MACHINE\Software\Classes\CLSID)",</span><br />
	<span style="color:#242424;"><span>                  </span>LR"(HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run)",</span><br />
	<span style="color:#242424;"><span>                  </span>LR"(HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad)",</span><br />
	<span style="color:#242424;"><span>                  </span>LR"(HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer)",</span><br />
	<span style="color:#242424;"><span>                  </span>LR"(HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run)",</span><br />
	<span style="color:#242424;"><span>                  </span>LR"((HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components)",</span><br />
	<span style="color:#242424;"><span>                  </span>LR"(HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows)",</span><br />
	<span style="color:#242424;"><span>                  </span>LR"(HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options)",</span><br />
	<span style="color:#242424;"><span>                  </span>LR"(HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Aedebug)",</span><br />
	<span style="color:#242424;"><span>                  </span>LR"(HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon)"</span><br />
	<span style="color:#242424;"><span>                </span>}'</span><br />
	<span style="color:#242424;"><span>             </span>tag-id="2" tag-name="PredefinedKeyPaths"/&gt;</span>
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<strong>IoC tasks that are configured to scan other branches of the registry will not return any results.</strong>
</p>
]]></description><guid isPermaLink="false">37988</guid><pubDate>Sat, 16 Dec 2023 14:36:07 +0000</pubDate></item><item><title>KEA for Linux remote installation fails: Installation error Error in PREIN scriptlet in rpm package epagent [Kaspersky Endpoint Agent for Linux]</title><link>https://forum.kaspersky.com/topic/kea-for-linux-remote-installation-fails-installation-error-error-in-prein-scriptlet-in-rpm-package-epagent-kaspersky-endpoint-agent-for-linux-37987/</link><description><![CDATA[<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/advice-and-solutions-forum-knowledgebase-disclaimer-read-before-using-materials-36464/" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.</span></a></span>
</h2>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	Problem
</h2>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	Some users may face a rather unclear and not self-explanatory error when attempting to remotely install KEA for Linux:
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">Remote installation has been completed with an error on<span> </span></code><code style="border:0px;color:#336699;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">this</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">device: Installation error Error in PREIN scriptlet in rpm<span> </span></code><code style="border:0px;color:#336699;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">package</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">epagent</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										 
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">Error: Transaction failed</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<a class="ipsAttachLink ipsAttachLink_image" data-fileext="png" data-fileid="15373" href="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.fe65f964e49933b30fd0e8e5ad0fa2be.png" rel=""><img alt="image.thumb.png.dba472ebf2f3fcdf77be076e6a11513a.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15373" data-ratio="102.04" style="height:auto;" width="686" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.thumb.png.dba472ebf2f3fcdf77be076e6a11513a.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
</p>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	Solution
</h2>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	This error is specific to<span> </span><strong>RHEL-based</strong><span> </span>distributives which have<span> </span><code>SELinux</code>. KEA for Linux does not support Enforcing<span> </span><code>SELinux</code><span> </span>mode, and thus requires<span> </span><code>SELinux</code><span> </span>to be either disabled, or set to Permissive mode.
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	To set SELinux to permissive mode for current session(until reboot):
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">setenforce Permissive</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	To disable SELinux, in file<span> </span><code>/etc/selinux/config</code><span> </span>set
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">SELINUX=disabled</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>
]]></description><guid isPermaLink="false">37987</guid><pubDate>Sat, 16 Dec 2023 14:30:14 +0000</pubDate></item><item><title>KEA SSL Error: WINHTTP_CALLBACK_STATUS_FLAG_SECURITY_CHANNEL_ERROR [Kaspersky Endpoint Agent]</title><link>https://forum.kaspersky.com/topic/kea-ssl-error-winhttp_callback_status_flag_security_channel_error-kaspersky-endpoint-agent-37986/</link><description><![CDATA[<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/advice-and-solutions-forum-knowledgebase-disclaimer-read-before-using-materials-36464/" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.</span></a></span>
</h2>

<div style="border:1px solid #ffeaae;color:#333333;font-size:14px;padding:10px 10px 10px 36px;">
	<div style="padding:0px;">
		<p style="padding:0px;">
			The article is applicable to<span> </span><strong>KEA 3.x<span> </span></strong>(any cf) as part of [KATA+]EDR solution.
		</p>
	</div>
</div>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span>1.1.<span> </span></span>Problem
</h2>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	Some hosts (usually server, eg. Windows Server 2012 R2) will not appear in CN dashboard after being configured using correct settings, including a valid TLS certificate. In the known case, such Endpoint Agents were configured locally using the command line, not via policy; however, we were able to verify that the same configuration led to successful connection on most hosts.
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	During troubleshooting, you should be able to find the following events in WEL, Schannel errors are present:
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">Log Name:      System</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">Source:        Schannel</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">Event ID:     <span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">36871</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">Level:         Error</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">Description:</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">A fatal error occurred<span> </span></code><code style="border:0px;color:#336699;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">while</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">creating a TLS client credential. The internal error state is<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">10013</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">.</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	In KEA traces  you should be able to find the following lines:
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">SSL Error: WINHTTP_CALLBACK_STATUS_FLAG_SECURITY_CHANNEL_ERROR internal error</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">kata.compression=</code><code style="border:0px;color:#336699;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">true</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">kata.sync_period=</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">300</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">kata.certificate=[...]</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">kata.servers=</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">10.231</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">.</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">132.146</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">;</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">syslog.enable=</code><code style="border:0px;color:#336699;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">false</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">syslog.type=CEF</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">syslog.server=:<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	The connection port is displayed as 0. This persists even though the port used by default is 443 (as it is on non-affected hosts), or if we specify the port in the configuration string like this:
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<em>C:\Program Files (x86)\Kaspersky Lab\Endpoint Agent\agent.exe" --message-broker=enable --type=kata --servers=</em><span style="color:#000000;">&lt;servername&gt;<em><strong>:443</strong></em></span><em><span> </span>--tls=yes --pinned-certificate=”%~dp0kata.crt</em>
</p>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span>1.2.<span> </span></span>Cause
</h2>

<ul style="background-color:#ffffff;color:#172b4d;font-size:14px;">
	<li>
		Most common cause - TLS 1.2 is disabled (usually for Server OSes)
	</li>
	<li>
		Some of the ciphers are missing
	</li>
</ul>

<div style="border:1px solid #d04437;color:#333333;font-size:14px;padding:10px 10px 10px 36px;">
	<p style="padding:0px;">
		Alternative cause
	</p>

	<div style="padding:0px;">
		<p style="padding:0px;">
			Recently it was found out that the problem persists on desktops (Win 10) with all the TLS1.2 keys and ciphers in place, when there is "<strong>CryptoPRO CSP</strong>" software installed, specifically following versions:
		</p>

		<p style="padding:0px;">
			CryptoPRO CSP - 4.0.9944<br />
			CryptoPRO CSP - 4.0.9958
		</p>
	</div>
</div>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span>1.3.<span> </span></span>Solution
</h2>

<ol style="background-color:#ffffff;color:#172b4d;font-size:14px;">
	<li>
		For KEA 3.11 and older - Upgrade KEA to the latest version.
	</li>
	<li>
		Ensure "КриптоПро CSP" is not listed in installed applications
	</li>
	<li>
		For Windows 2012R2  - install<span> </span><a href="https://support.microsoft.com/en-au/topic/update-adds-new-tls-cipher-suites-and-changes-cipher-suite-priorities-in-windows-8-1-and-windows-server-2012-r2-8e395e43-c8ef-27d8-b60c-0fc57d526d94" rel="external nofollow" style="color:#265951;"><strong>KB2919355</strong></a> 
	</li>
	<li>
		<p style="padding:0px;">
			Enable TLS 1.2. Exhaustive article in Russian<span> </span><a href="https://winitpro.ru/index.php/2022/04/19/vklyuchit-protokol-tls-1-2-windows/" rel="external nofollow" style="color:#265951;">https://winitpro.ru/index.php/2022/04/19/vklyuchit-protokol-tls-1-2-windows/</a>
		</p>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="border-bottom:1px none #cccccc;padding:5px 15px;text-align:left;">
				<b style="color:#333333;">Script to enable all the keys from the article</b><span><span style="font-size:0px;text-align:left;vertical-align:text-bottom;"> </span></span>
			</div>

			<div style="border-top:1px solid #cccccc;color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#808080;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">@echo</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">off</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">reg add<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client"</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/v DisabledByDefault /t REG_DWORD /d<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/f</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">reg add<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client"</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/v Enabled /t REG_DWORD /d<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">1</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/f</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">reg add<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Server"</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/v DisabledByDefault /t REG_DWORD /d<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/f</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">reg add<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Server"</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/v Enabled /t REG_DWORD /d<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">1</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/f</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">reg add<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WinHTTP"</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/v DefaultSecureProtocols /t REG_DWORD /d<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">2720</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/REG:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">32</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/f</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												 
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">reg add<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v2.0.50727"</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/v SchUseStrongCrypto /t REG_DWORD /d<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">1</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/f</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">reg add<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v2.0.50727"</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/v SchUseStrongCrypto /t REG_DWORD /d<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">1</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/REG:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">32</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/f</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">reg add<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v2.0.50727"</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/v SystemDefaultTlsVersions /t REG_DWORD /d<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">1</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/f</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">reg add<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v2.0.50727"</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/v SystemDefaultTlsVersions /t REG_DWORD /d<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">1</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/REG:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">32</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/f</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">reg add<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319"</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/v SchUseStrongCrypto /t REG_DWORD /d<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">1</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/f</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">reg add<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319"</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/v SchUseStrongCrypto /t REG_DWORD /d<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">1</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/REG:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">32</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/f</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">reg add<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319"</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/v SystemDefaultTlsVersions /t REG_DWORD /d<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">1</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/f</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">reg add<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319"</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/v SystemDefaultTlsVersions /t REG_DWORD /d<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">1</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/REG:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">32</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/f</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>
	</li>
	<li>
		<p style="padding:0px;">
			Ensure the following registry keys for TLS 1.2 are present (it is possible to check using GSI6 report):
		</p>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">Windows Registry Editor Version<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">5.00</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												 
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">1.2</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">]</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">1.2</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">\Client]</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"DisabledByDefault"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">=dword:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">00000000</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"Enabled"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">=dword:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">00000001</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												 
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">1.2</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">\Server]</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"DisabledByDefault"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">=dword:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">00000000</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"Enabled"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">=dword:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">00000001</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>
	</li>
	<li>
		Ensure the following registry value for WinHttp API:<br />
		32-bit: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttp<br />
		64-bit: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttp<br />
		<strong><code>"DefaultSecureProtocols" = dword:00000AA0</code><br />
		<br />
		0x0000AA0</strong><span> </span>— allow TLS 1.1 and TLS 1.2 in addition to SSL 3.0 and TLS 1.0;
	</li>
	<li>
		<p style="padding:0px;">
			Allow following ciphers on the server in order to match KATA CN (old and outdated are not allowed from security point of view) -
		</p>

		<p style="padding:0px;">
			For Windows 2012 R2 it is necessary to add and enable  <strong><span>TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384</span></strong> <br />
			One can do this via MS documentation like this -<span> </span><a href="https://docs.microsoft.com/en-us/windows/win32/secauthn/tls-cipher-suites-in-windows-server-2022" rel="external nofollow" style="color:#265951;">https://docs.microsoft.com/en-us/windows/win32/secauthn/tls-cipher-suites-in-windows-server-2022</a>:
		</p>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">ECDHE-RSA-AES256-GCM-SHA384</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">ECDHE-ECDSA-AES256-GCM-SHA384</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">ECDHE-RSA-AES256-SHA384</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">ECDHE-ECDSA-AES256-SHA384</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">ECDHE-RSA-AES128-GCM-SHA256</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">ECDHE-ECDSA-AES128-GCM-SHA256</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">ECDHE-RSA-AES128-SHA256</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">ECDHE-ECDSA-AES128-SHA256</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>

		<p style="padding:0px;">
			Ciphers can be enabled using tool called<span> </span><strong>IISCrypto,<span> </span></strong>it can be used to tweak TLS/SSL, cipehrs and Schannel with GUI -<span> </span><a href="https://www.nartac.com/Products/IISCrypto/" rel="external nofollow" style="color:#265951;">https://www.nartac.com/Products/IISCrypto/</a>
		</p>
	</li>
	<li>
		Reboot for the settings to take effect -<span> </span><strong>!Restart required!</strong>
	</li>
</ol>
]]></description><guid isPermaLink="false">37986</guid><pubDate>Sat, 16 Dec 2023 14:23:39 +0000</pubDate></item><item><title>KEA on Exchange servers [Kaspersky Endpoint Agent]</title><link>https://forum.kaspersky.com/topic/kea-on-exchange-servers-kaspersky-endpoint-agent-37985/</link><description><![CDATA[<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/advice-and-solutions-forum-knowledgebase-disclaimer-read-before-using-materials-36464/" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.</span></a></span>
</h2>

<div style="border:1px solid #aab8c6;color:#333333;font-size:14px;padding:10px 10px 10px 36px;">
	<div style="padding:0px;">
		<p style="padding:0px;">
			This article applies to<span> </span><strong>KEA 3.10+</strong>
		</p>
	</div>
</div>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	Problem
</h2>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	You need to install KEA on a host running<span> </span><strong>MS Exhange 2013, 2016, 2019</strong><span> </span>server, and ensure compatibilty.
</p>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	Solution
</h2>

<ol style="background-color:#ffffff;color:#172b4d;font-size:14px;">
	<li>
		<p style="padding:0px;">
			Add the following values into registry (should be done with "Local System" rights):
		</p>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\KasperskyLab\SOYUZ\</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">4.0</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">\Environment]</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"EnablePorts"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">=dword:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">00000001</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"EnableSignatureLevel"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">=dword:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">00000001</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"ServerProfile"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">=dword:0000000a</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>
	</li>
	<li>
		<p style="padding:0px;">
			In KEA policy, add the following telemetry exclusions:
		</p>

		<div style="border:1px solid #d04437;color:#333333;padding:10px 10px 10px 36px;">
			<div style="padding:0px;">
				<p style="padding:0px;">
					<span style="color:#242424;"><span> W</span></span>e highly recommend NOT to exclude UmWorkerProcess.exe.
				</p>
			</div>
		</div>

		<div style="padding:0px;">
			<div style="padding:0px;">
				<p style="padding:0px;">
					C:\Program Files\Microsoft\Exchange Server\V15\Bin\ComplianceAuditService.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\Bin\EdgeTransport.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\FIP-FS\Bin\fms.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\Bin\Search\Ceres\HostController\hostcontrollerservice.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\Bin\Microsoft.Exchange.AntispamUpdateSvc.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\TransportRoles\agents\HygieneMicrosoft.Exchange.ContentFilter.Wrapper.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\Bin\Microsoft.Exchange.Diagnostics.Service.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\Bin\Microsoft.Exchange.Directory.TopologyService.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\Bin\Microsoft.Exchange.EdgeCredentialSvc.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\Bin\Microsoft.Exchange.EdgeSyncSvc.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\FrontEnd\PopImap\Microsoft.Exchange.Imap4.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\ClientAccess\PopImap\Microsoft.Exchange.Imap4service.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\Bin\Microsoft.Exchange.Notifications.Broker.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\FrontEnd\PopImap\Microsoft.Exchange.Pop3.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\ClientAccess\PopImap\Microsoft.Exchange.Pop3service.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\Bin\Microsoft.Exchange.ProtectedServiceHost.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\Bin\Microsoft.Exchange.RPCClientAccess.Service.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\Bin\Microsoft.Exchange.Search.Service.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\Bin\Microsoft.Exchange.Servicehost.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\Bin\Microsoft.Exchange.Store.Service.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\Bin\Microsoft.Exchange.Store.Worker.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\FrontEnd\CallRouter\Microsoft.Exchange.UM.CallRouter.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\Bin\MSExchangeCompliance.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\Bin\MSExchangeDagMgmt.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\Bin\MSExchangeDelivery.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\Bin\MSExchangeFrontendTransport.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\Bin\MSExchangeHMHost.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\Bin\MSExchangeHMWorker.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\Bin\MSExchangeMailboxAssistants.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\Bin\MSExchangeMailboxReplication.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\Bin\MSExchangeRepl.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\Bin\MSExchangeSubmission.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\Bin\MSExchangeTransport.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\Bin\MSExchangeTransportLogSearch.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\Bin\MSExchangeThrottling.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\Bin\Search\Ceres\Runtime\1.0\Noderunner.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\Bin\OleConverter.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\Bin\Search\Ceres\ParserServer\ParserServer.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\FIP-FS\Bin\ScanEngineTest.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\FIP-FS\Bin\ScanningProcess.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\Bin\UmService.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\FIP-FS\Bin\UpdateService.exe<br />
					C:\Program Files\Microsoft\Exchange Server\V15\Bin\wsbexchange.exe
				</p>
			</div>
		</div>
	</li>
</ol>
]]></description><guid isPermaLink="false">37985</guid><pubDate>Sat, 16 Dec 2023 14:13:08 +0000</pubDate></item><item><title>KEA task states [Kaspersky Endpoint Agent]</title><link>https://forum.kaspersky.com/topic/kea-task-states-kaspersky-endpoint-agent-37984/</link><description><![CDATA[<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/advice-and-solutions-forum-knowledgebase-disclaimer-read-before-using-materials-36464/" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.</span></a></span>
</h2>

<h2 style="border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	Problem
</h2>

<p style="padding:0px;">
	KEA writes in its event logs numeric task states.<span> </span>
</p>

<p style="padding:0px;">
	<a class="ipsAttachLink ipsAttachLink_image" data-fileext="png" data-fileid="15372" href="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.2f612ad54b2dd42a96e700a267e9307f.png" rel=""><img alt="image.thumb.png.b01c4cca71197d4a1e448f4e196be616.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15372" data-ratio="26.86" style="height:auto;" width="700" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.thumb.png.b01c4cca71197d4a1e448f4e196be616.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
</p>

<h2 style="border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	Solution
</h2>

<div style="padding:0px;">
	<table style="border-collapse:collapse;padding:0px;">
		<colgroup>
			<col />
			<col />
		</colgroup>
		<thead>
			<tr>
				<th scope="col" style="border:1px solid #c1c7d0;color:#000000;padding:0px;text-align:left;vertical-align:top;">
					<div style="color:#000000;padding:0px;">
						Number
					</div>
				</th>
				<th scope="col" style="border:1px solid #c1c7d0;color:#000000;padding:0px;text-align:left;vertical-align:top;">
					<div style="color:#000000;padding:0px;">
						Meaning
					</div>
				</th>
			</tr>
		</thead>
		<tbody>
			<tr>
				<td style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					0
				</td>
				<td style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					Unknown
				</td>
			</tr>
			<tr>
				<td style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					1
				</td>
				<td style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					<span style="color:#242424;">PreparedToStart</span>
				</td>
			</tr>
			<tr>
				<td style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					2
				</td>
				<td style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					<span style="color:#242424;">Starting</span>
				</td>
			</tr>
			<tr>
				<td colspan="1" style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					3
				</td>
				<td colspan="1" style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					<span style="color:#242424;">Started</span>
				</td>
			</tr>
			<tr>
				<td colspan="1" style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					4
				</td>
				<td colspan="1" style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					<span style="color:#242424;">Stopping</span>
				</td>
			</tr>
			<tr>
				<td colspan="1" style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					5
				</td>
				<td colspan="1" style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					<span style="color:#242424;">Stopped</span>
				</td>
			</tr>
			<tr>
				<td colspan="1" style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					6
				</td>
				<td colspan="1" style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					<span style="color:#242424;">Reloading</span>
				</td>
			</tr>
			<tr>
				<td colspan="1" style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					7
				</td>
				<td colspan="1" style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					<span style="color:#242424;">Recovering</span>
				</td>
			</tr>
			<tr>
				<td colspan="1" style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					8
				</td>
				<td colspan="1" style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					<span style="color:#242424;">Failed</span>
				</td>
			</tr>
			<tr>
				<td colspan="1" style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					9
				</td>
				<td colspan="1" style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					<span style="color:#242424;">Completed</span>
				</td>
			</tr>
		</tbody>
	</table>
</div>

<p style="padding:0px;">
	 
</p>

<p>
	 
</p>
]]></description><guid isPermaLink="false">37984</guid><pubDate>Sat, 16 Dec 2023 14:07:22 +0000</pubDate></item><item><title>Prevented file formats in KEA [Kaspersky Endpoint Agent]</title><link>https://forum.kaspersky.com/topic/prevented-file-formats-in-kea-kaspersky-endpoint-agent-37983/</link><description><![CDATA[<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/advice-and-solutions-forum-knowledgebase-disclaimer-read-before-using-materials-36464/" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.</span></a></span>
</h2>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	In EDR Security officer can create a hash-based prevention rule for workstation. Here's the list of activities to which prevention rules apply:
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<span>Agent should control and<span> </span><span>prevent read access</span><span> </span>of the following file formats by the following apps:</span>
</p>

<div style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<table style="border-collapse:collapse;padding:0px;">
		<colgroup>
			<col />
			<col />
			<col />
			<col />
			<col />
			<col />
		</colgroup>
		<thead>
			<tr>
				<th scope="col" style="border:1px solid #c1c7d0;color:#000000;padding:0px;text-align:left;vertical-align:top;">
					<div style="color:#000000;padding:0px;">
						<p style="padding:0px;">
							<span>App:</span>
						</p>
					</div>
				</th>
				<th scope="col" style="border:1px solid #c1c7d0;color:#000000;padding:0px;text-align:left;vertical-align:top;">
					<div style="color:#000000;padding:0px;">
						<p style="padding:0px;">
							<span>winword.exe</span>
						</p>
					</div>
				</th>
				<th scope="col" style="border:1px solid #c1c7d0;color:#000000;padding:0px;text-align:left;vertical-align:top;">
					<div style="color:#000000;padding:0px;">
						<p style="padding:0px;">
							<span>wordpad.exe</span>
						</p>
					</div>
				</th>
				<th scope="col" style="border:1px solid #c1c7d0;color:#000000;padding:0px;text-align:left;vertical-align:top;">
					<div style="color:#000000;padding:0px;">
						<p style="padding:0px;">
							<span>excel.exe</span>
						</p>
					</div>
				</th>
				<th scope="col" style="border:1px solid #c1c7d0;color:#000000;padding:0px;text-align:left;vertical-align:top;">
					<div style="color:#000000;padding:0px;">
						<p style="padding:0px;">
							<span>powerpnt.exe</span>
						</p>
					</div>
				</th>
				<th scope="col" style="border:1px solid #c1c7d0;color:#000000;padding:0px;text-align:left;vertical-align:top;">
					<div style="color:#000000;padding:0px;">
						<p style="padding:0px;">
							<span>acrord32.exe<br />
							Microsoft Edge<br />
							Google Chrome</span>
						</p>
					</div>
				</th>
			</tr>
		</thead>
		<tbody>
			<tr>
				<td style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					<span><strong>File formats:</strong></span>
				</td>
				<td style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					<span>.rtf<br />
					.doc<br />
					.dot<br />
					.docm<br />
					.docx<br />
					.dotx<br />
					.dotm<br />
					.docb </span>
				</td>
				<td style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					<p style="padding:0px;">
						<span>.docx</span>
					</p>

					<p style="padding:0px;">
						<span>.rtf</span>
					</p>
				</td>
				<td style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					<span>.xls<br />
					.xlt<br />
					.xlm<br />
					.xlsx<br />
					.xlsm<br />
					.xltx<br />
					.xltm<br />
					.xlsb<br />
					.xla<br />
					.xlam<br />
					.xll<br />
					.xlw</span>
				</td>
				<td style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					<span>.ppt<br />
					.pot<br />
					.pps<br />
					.pptx<br />
					.pptm<br />
					.potx<br />
					.potm<br />
					.ppam<br />
					.ppsx<br />
					.ppsm<br />
					.sldx<br />
					.sldm</span>
				</td>
				<td style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					<span>.pdf</span>
				</td>
			</tr>
		</tbody>
	</table>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	 
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	Agent should prevent script started by following interpreters:
</p>

<ul>
	<li style="padding:0px;">
		<span>cmd.exe</span>
	</li>
	<li style="padding:0px;">
		<span>reg.exe</span>
	</li>
	<li style="padding:0px;">
		<span>regedit.exe</span>
	</li>
	<li style="padding:0px;">
		<span>regedt32.exe</span>
	</li>
	<li style="padding:0px;">
		<span>cscript.exe</span>
	</li>
	<li style="padding:0px;">
		<span>wscript.exe</span>
	</li>
	<li style="padding:0px;">
		<span>mmc.exe</span>
	</li>
	<li style="padding:0px;">
		<span>msiexec.exe</span>
	</li>
	<li style="padding:0px;">
		<span>mshta.exe</span>
	</li>
	<li style="padding:0px;">
		<span>rundll32.exe</span>
	</li>
	<li style="padding:0px;">
		<span>runlegacycplelevated.exe</span>
	</li>
	<li style="padding:0px;">
		<span>control.exe</span>
	</li>
	<li style="padding:0px;">
		<span>explorer.exe</span>
	</li>
	<li style="padding:0px;">
		<span>regsvr32.exe</span>
	</li>
	<li style="padding:0px;">
		<span>wwahost.exe</span>
	</li>
	<li style="padding:0px;">
		<span>powershell.exe</span>
	</li>
	<li>
		<span>perl.exe ( * )</span>
	</li>
	<li>
		<span>hh.exe ( * )</span>
	</li>
	<li>
		<span>msbuild.exe ( * )</span>
	</li>
	<li>
		<span>python.exe ( * )</span>
	</li>
	<li>
		<span>InstallUtil.exe</span>
	</li>
	<li>
		<span>RegSvcs.exe</span>
	</li>
	<li>
		<span>RegAsm.exe</span>
	</li>
	<li>
		<span>ruby.exe</span>
	</li>
	<li>
		<span>rubyw.exe</span>
	</li>
	<li>
		<span>autoit.exe</span>
	</li>
	<li>
		<span>AutoHotkey.exe</span>
	</li>
	<li>
		<span>AutoHotkeyU32.exe</span>
	</li>
	<li>
		<span>AutoHotkeyA32.exe</span>
	</li>
	<li>
		<span>AutoHotkeyU64.exe</span>
	</li>
	<li>
		<span>AutoHotkeyA64.exe</span>
	</li>
</ul>
]]></description><guid isPermaLink="false">37983</guid><pubDate>Sat, 16 Dec 2023 13:59:42 +0000</pubDate></item><item><title>How to renew KEA unique identifier on cloned devices [Kaspersky Endpoint Agent]</title><link>https://forum.kaspersky.com/topic/how-to-renew-kea-unique-identifier-on-cloned-devices-kaspersky-endpoint-agent-37982/</link><description><![CDATA[
	<div style="text-align:left;">
		<strong><span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/advice-and-solutions-forum-knowledgebase-disclaimer-read-before-using-materials-36464/" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.</span></a></span></strong>
	</div>

	<div style="text-align:left;">
		 
	</div>

	<div style="text-align:left;">
		<span style="color:rgb(0,0,0);font-size:24px;font-family:Inter, '-apple-system', BlinkMacSystemFont, 'Segoe UI', Roboto, Helvetica, Arial, sans-serif, 'Apple Color Emoji', 'Segoe UI Emoji', 'Segoe UI Symbol';">Problem</span>
	</div>

	<div style="text-align:left;">
		<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
			You may use images with installed KEA that are distributed to multiple devices, or some hardware vendors (ACER) do not comply with<span> </span><a href="https://www.dmtf.org/sites/default/files/standards/documents/DSP0134_2.7.1.pdf" rel="external nofollow" style="color:#265951;">standards<span> </span></a>and sell hardware with non-unique BIOS IDs, etc.
		</p>

		<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
			As a result, a telemetry from different agents may end up merged into a single record.
		</p>

		<h1 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:24px;padding:0px;">
			Symptoms
		</h1>

		<ul style="background-color:#ffffff;color:#172b4d;font-size:14px;">
			<li>
				Certain hostnames are present in KATA alerts, but search returns 0 events. Moreover, such hostnames are not present in the agent list. If looked up by an IP in the database/logs, UUID is found to be non-unique or belonging to other host.
			</li>
			<li>
				The same UUID is found in KEA logs from different machines.
			</li>
			<li>
				There is UUID 03000200-0400-0500-0006-000700080009 in the logs.
			</li>
			<li>
				There is UUID 6ab5b300-538d-1014-9fb5-b0684d007b53 in the logs.
			</li>
			<li>
				There is UUID 0bea76da-28ca-4e13-9715-361a8bbf3bc8 in the logs.
			</li>
		</ul>

		<h1 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:24px;padding:0px;">
			Solution
		</h1>

		<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
			Run<span> </span><a href="https://box.kaspersky.com/f/7753d064cdca4bdebde5/?dl=1" rel="external nofollow">the new script</a><span> </span>on the affected machine to reset the UUID.
		</p>
	</div>

]]></description><guid isPermaLink="false">37982</guid><pubDate>Sat, 16 Dec 2023 13:53:10 +0000</pubDate></item><item><title>How to integrate KATA and KWTS [KATA/KEDRE]</title><link>https://forum.kaspersky.com/topic/how-to-integrate-kata-and-kwts-katakedre-37657/</link><description><![CDATA[<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/advice-and-solutions-forum-knowledgebase-disclaimer-read-before-using-materials-36464/" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.</span></a></span>
</h2>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	You may have purchased both the KATA and KWTS(Kaspersky Web Traffic Security) products. Since KWTS<span> </span><u><a href="https://support.kaspersky.com/KWTS/6.1/en-US/187067.htm" rel="external nofollow" style="color:#265951;">has built-in KATA integration</a></u>, you may want to integrate KATA and KWTS.
</p>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	Problems after integration
</h2>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	Shortly after integration you may notice that on KWTS side, there is an error about sending objects to KATA, and dashboards look similar to this:
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<a class="ipsAttachLink ipsAttachLink_image" data-fileext="png" data-fileid="14918" href="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.dedec5a9b7a98691a357fa141350a1cf.png" rel=""><img alt="image.thumb.png.e3b5a2ae4c4849dcc24f234c83d3ad0a.png" class="ipsImage ipsImage_thumbnailed" data-fileid="14918" data-ratio="29.29" style="height:auto;" width="700" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.thumb.png.e3b5a2ae4c4849dcc24f234c83d3ad0a.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<a class="ipsAttachLink ipsAttachLink_image" data-fileext="png" data-fileid="14919" href="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.2bc41a2dbb3ab87c448e6f9e0d78bf5c.png" rel=""><img alt="image.thumb.png.6a8c3d87953683acc724f99e5bc29295.png" class="ipsImage ipsImage_thumbnailed" data-fileid="14919" data-ratio="31.71" style="height:auto;" width="700" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.thumb.png.6a8c3d87953683acc724f99e5bc29295.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
</p>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	Resolution
</h2>

<div style="border:1px solid #aab8c6;color:#333333;font-size:14px;padding:10px 10px 10px 36px;">
	<div style="padding:0px;">
		Prerequisite for successful integration with KWTS is KATA version 3.6.1.752 or higher.
	</div>
</div>

<h4 style="background-color:#ffffff;color:#000000;font-size:14px;padding:0px;">
	KATA side
</h4>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	To clean tasks, stuck in 'processing' state, do the following:
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	1) Find out KWTS ID:
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">sudo -u kluser psql antiapt -c<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"select id, sensor_type, sensor_name, ip from lms.client;"</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	On KATA4:
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">docker exec -it `docker ps | grep kedr_database| awk<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">'{print $1}'</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">` psql -U kluser antiapt -c<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"select id, sensor_type, sensor_name, ip from lms.client;"</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	Name and IP of KWTS will be the same as in Administrator Web UI, External Systems section.
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<span>Then, clean up tasks that may be stuck in 'processing state':</span>
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">sudo -u kluser psql antiapt -c<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"update lms.task set state = 'error', has_error = True where client_id = &lt;KWTS ID&gt; and state = 'processing' and update_time &lt; now() - interval '1 hour';"</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	On KATA4:
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">docker exec -it `docker ps | grep kedr_database| awk<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">'{print $1}'</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">` psql -U kluser antiapt -c<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"update lms.task set state = 'error', has_error = True where client_id = &lt;KWTS ID&gt; and state = 'processing' and update_time &lt; now() - interval '1 hour';"</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	This command is safe to execute, it will do no harm even if there are no stuck tasks.
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	To view all active tasks from KSMG/KLMS/KWTS/Other external systems without modifying their states, run the command:
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">docker exec -it `docker ps | grep kedr_database| awk<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">'{print $1}'</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">` psql -U kluser antiapt -c<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"select count(*) from lms.task where client_id=&lt;KSMG ID&gt;;"</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<div style="border:1px solid #aab8c6;color:#333333;font-size:14px;padding:10px 10px 10px 36px;">
	<div style="padding:0px;">
		<p style="padding:0px;">
			The two commands above can  be used to remove tasks stuck in processing from other types of external systems as well.
		</p>
	</div>
</div>

<h4 style="background-color:#ffffff;color:#000000;font-size:14px;padding:0px;">
	KWTS side
</h4>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	On KWTS side, it is important to exclude certain type of objects from being scanned in KATA:
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	In file<span> </span><code>/var/opt/kaspersky/kwts/kata-filters.json</code><span> </span>remove the lines, containing keywords:
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">ArchiveGzip</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										 
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">ArchiveCab</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										 
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">ExecutableJs</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	After applying changes, restart kwts service:
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">systemctl restarts kwts</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	After these changes, KWTS and KATA integration is expected to work normally further on.
</p>
]]></description><guid isPermaLink="false">37657</guid><pubDate>Sun, 03 Dec 2023 15:03:50 +0000</pubDate></item></channel></rss>
