<?xml version="1.0"?>
<rss version="2.0"><channel><title>Advice and solutions for Kaspersky EDR Optimum Latest Topics</title><link>https://forum.kaspersky.com/forum/advice-and-solutions-for-kaspersky-edr-optimum-227/</link><description>Advice and solutions for Kaspersky EDR Optimum Latest Topics</description><language>en</language><item><title>Correct integration/installation [EDR Optimum]</title><link>https://forum.kaspersky.com/topic/correct-integrationinstallation-edr-optimum-37770/</link><description><![CDATA[<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/advice-and-solutions-forum-knowledgebase-disclaimer-read-before-using-materials-36464/" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.</span></a></span>
</h2>

<p style="color:#172b4d;font-size:14px;padding:0px;">
	<strong><span>This article will help you to check EDRO component correct installation and integration.<span> </span></span></strong>
</p>

<p style="color:#172b4d;font-size:14px;padding:0px;">
	<em><u><span>What you need to know about EDRO</span></u></em>
</p>

<p style="color:#172b4d;font-size:14px;padding:0px;">
	<em><span>1 EDRO working with KES 11.7+, KSWS 11.0.1 and KSV LA 5.2 (Windows only), so called EPP</span></em>
</p>

<p style="color:#172b4d;font-size:14px;padding:0px;">
	<em><span><a href="https://support.kaspersky.com/KEDR_Optimum/2.3/en-US/216855.htm" rel="external nofollow" style="color:#265951;">https://support.kaspersky.com/KEDR_Optimum/2.3/en-US/216855.htm</a> </span></em>
</p>

<p style="color:#172b4d;font-size:14px;padding:0px;">
	<em>2 You must use NWC for EDRO</em>
</p>

<p style="color:#172b4d;font-size:14px;padding:0px;">
	<em>3 You can't use only KEA for EDRO scenario. It always integrates with EPP.</em>
</p>

<p style="color:#172b4d;font-size:14px;padding:0px;">
	<span style="color:#000000;font-size:20px;">How to check that EDRO component installed correctly</span>
</p>

<p style="color:#172b4d;font-size:14px;padding:0px;">
	<span>First of all you need to check whether KEA component was installed or not. And if it's installed then was it integrated with EPP.<span> </span></span>
</p>

<div style="color:#172b4d;font-size:14px;padding:0px;">
	<div style="padding:0px;">
		<h4 style="color:#000000;font-size:14px;padding:0px;">
			<span style="color:#1abc9c;">KES</span>
		</h4>

		<p style="padding:0px;">
			Starting with KES 11.7 EDRO agent is integrated in the KES.
		</p>

		<h2 style="border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
			<u><span>First of all, check component status in MMC or NWC</span></u>
		</h2>

		<p style="padding:0px;">
			MMC
		</p>

		<p style="padding:0px;">
			<img alt="image.png.e5e9df5fc0828af09e62529f3f46cfbd.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15103" data-ratio="5.37" style="height:auto;" width="484" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.e5e9df5fc0828af09e62529f3f46cfbd.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" />
		</p>

		<p style="padding:0px;">
			NWC
		</p>

		<p style="padding:0px;">
			<a class="ipsAttachLink ipsAttachLink_image" data-fileext="png" data-fileid="15104" href="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.af7acc77a80647eef121448f283d28f1.png" rel=""><img alt="image.thumb.png.896990f6ddec5e855aba757eafbc07f3.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15104" data-ratio="3.14" style="height:auto;" width="700" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.thumb.png.896990f6ddec5e855aba757eafbc07f3.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
		</p>

		<p style="padding:0px;">
			<span style="color:#000000;">If you see Not supported by license, pay attention to the version. If you see 0.0.0.0 or N/A, it means that component is not installed. Not supported by license doesn't mean that there is no license for EDRO, it may mean that component is not installed on the host.</span>
		</p>

		<p style="padding:0px;">
			When component is installed but not activated, you'll see installed component version:
		</p>

		<p style="padding:0px;">
			MMC
		</p>

		<p style="padding:0px;">
			<img alt="image.png.188c94fe5370aba573bd20cf36b7da7d.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15101" data-ratio="4.32" style="height:auto;" width="556" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.188c94fe5370aba573bd20cf36b7da7d.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" />
		</p>

		<p style="padding:0px;">
			NWC
		</p>

		<p style="padding:0px;">
			<a class="ipsAttachLink ipsAttachLink_image" data-fileext="png" data-fileid="15102" href="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.9ff8614d16be6e4a6d583b5da64582c1.png" rel=""><img alt="image.thumb.png.e26a3568687c40a9c1f5867eef43badf.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15102" data-ratio="4.29" style="height:auto;" width="700" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.thumb.png.e26a3568687c40a9c1f5867eef43badf.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
		</p>

		<p style="padding:0px;">
			If component was installed and was not activated, it will look like this in the KES GUI:
		</p>

		<p style="padding:0px;">
			<img alt="image.png.854d694bc32aad8d8976025d5a614eb6.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15105" data-ratio="22.55" style="height:auto;" width="337" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.854d694bc32aad8d8976025d5a614eb6.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" />
		</p>

		<p style="padding:0px;">
			If component is not installed, then there will be no Detection and Response section in the KES GUI (in case MDR is installed, then there will be section Detection and Response, but there will be no Endpoint Detection and Response Optimum like you see above).
		</p>

		<p style="padding:0px;">
			 
		</p>

		<p style="padding:0px;">
			<u style="color:#000000;font-size:20px;">How to check EDRO license in the KES UI</u>
		</p>

		<p style="padding:0px;">
			<span>You can check license components in the KES GUI. If there is no Optimum word, license do not support EDRO. For example:</span>
		</p>

		<p style="padding:0px;">
			<img alt="image.png.8401980f7ea554fb2032bb517c9e300f.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15106" data-ratio="34.00" style="height:auto;" width="647" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.8401980f7ea554fb2032bb517c9e300f.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" />
		</p>

		<p style="padding:0px;">
			And there's an example when license key supports EDRO:
		</p>

		<p style="padding:0px;">
			<img alt="image.png.0a75e388328fc4c8639b0e17133727a4.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15107" data-ratio="33.18" style="height:auto;" width="672" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.0a75e388328fc4c8639b0e17133727a4.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" />
		</p>
	</div>
</div>

<div style="color:#172b4d;font-size:14px;padding:0px;">
	<div style="padding:0px;">
		<h4 style="color:#000000;font-size:14px;padding:0px;">
			<span style="color:#1abc9c;">KSWS</span>
		</h4>

		<p style="padding:0px;">
			During KSWS installation you must enable Endpoint Agent, even if KEA was already installed on the host. KSWS detects it and enables connector with existing KEA (KEA will not be reinstalled).
		</p>

		<p style="padding:0px;">
			<img alt="image.png.40aad8c0550fe6f74cfa0403251bd75f.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15108" data-ratio="77.22" style="height:auto;" width="395" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.40aad8c0550fe6f74cfa0403251bd75f.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" />
		</p>

		<p style="padding:0px;">
			This is how correctly installed KSWS + KES looks like in the MMC:
		</p>

		<p style="padding:0px;">
			<img alt="image.png.680f16370fed24cd4e46e059bca3d615.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15109" data-ratio="64.14" style="height:auto;" width="449" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.680f16370fed24cd4e46e059bca3d615.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" />
		</p>

		<p style="padding:0px;">
			And if it not installed:
		</p>

		<p style="padding:0px;">
			<img alt="image.png.766cdc12ace7734bd80c8aa371848539.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15110" data-ratio="61.67" style="height:auto;" width="420" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.766cdc12ace7734bd80c8aa371848539.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" />
		</p>
	</div>
</div>

<div style="color:#172b4d;font-size:14px;padding:0px;">
	<div style="padding:0px;">
		<h4 style="color:#000000;font-size:14px;padding:0px;">
			KSV LA
		</h4>

		<p style="padding:0px;">
			There is no change components task. You can change them only during the upgrade or installation. Reinstallation requires reboot.
		</p>

		<p style="padding:0px;">
			During installation you need to choose Custom installation and enable integration with KEA
		</p>

		<p style="padding:0px;">
			<img alt="image.png.a5046052d678b4215112ce7a00f08a0c.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15111" data-ratio="44.16" style="height:auto;" width="437" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.a5046052d678b4215112ce7a00f08a0c.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" />
		</p>

		<p style="padding:0px;">
			Remember that you can enable integration in the installation package properties in the KSC.
		</p>
	</div>
</div>

<h2 style="border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	How to check NWC setup for EDRO
</h2>

<p style="color:#172b4d;font-size:14px;padding:0px;">
	What to do if there is no Alerts section in the NWC.
</p>

<div style="color:#172b4d;font-size:14px;padding:0px;">
	<div style="padding:0px;">
		<h2 style="border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
			<u>How it looks If there is no Alerts section in the WEB UI</u>
		</h2>

		<p style="padding:0px;">
			<img alt="image.png.6a6d23db0b2426f2c3290019b87b6778.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15112" data-ratio="108.84" style="height:auto;" width="215" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.6a6d23db0b2426f2c3290019b87b6778.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" />
		</p>

		<p style="padding:0px;">
			Go to the settings:
		</p>

		<p style="padding:0px;">
			<img alt="image.png.acaad8e480c2585831bc2c4b667a1b88.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15113" data-ratio="54.09" style="height:auto;" width="342" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.acaad8e480c2585831bc2c4b667a1b88.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" />
		</p>

		<p style="padding:0px;">
			And enable EDR alerts:
		</p>

		<p style="padding:0px;">
			<img alt="image.png.c8ad0ba0a351db8a5a841d88606edcaf.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15114" data-ratio="79.55" style="height:auto;" width="396" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.c8ad0ba0a351db8a5a841d88606edcaf.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" />
		</p>

		<p style="padding:0px;">
			In the KSC NWC<span> </span><u>there will be EDRO plugin by default</u>. It installs with the console. So the only way to reinstall it - reinstall NWC.
		</p>

		<h2 style="border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
			<u>How detection looks without installed EDRO component </u>
		</h2>

		<p style="padding:0px;">
			If you see detection but without enriched information, you'll see it like this:
		</p>

		<p style="padding:0px;">
			<a class="ipsAttachLink ipsAttachLink_image" data-fileext="png" data-fileid="15115" href="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.4b4719573a410137cb1de1c2a4d969f8.png" rel=""><img alt="image.thumb.png.9ab1962d8a26e308c2c9656314d3c15a.png" class="ipsImage ipsImage_thumbnailed" data-fileid="15115" data-ratio="6.29" style="height:auto;" width="700" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.thumb.png.9ab1962d8a26e308c2c9656314d3c15a.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
		</p>

		<p style="padding:0px;">
			In the<span> </span><u>Enrichment and response</u><span> </span>section you'll see only<span> </span><strong>Basic</strong>. It means where was a detection but no additional information about it was collected. Main reason why this may happen is that there's no EDRO component on the host.
		</p>
	</div>
</div>
]]></description><guid isPermaLink="false">37770</guid><pubDate>Thu, 07 Dec 2023 13:27:55 +0000</pubDate></item><item><title>Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.</title><link>https://forum.kaspersky.com/topic/advice-and-solutions-forum-knowledgebase-disclaimer-read-before-using-materials-37647/</link><description><![CDATA[<p style="background-color:#ffffff;color:#444444;font-size:14px;">
	The materials provided on the Advice and Solutions (Forum Knowledgebase) part of the Forum result from the work of the Kaspersky Customer Support team and Forum community members. They are shared here for ease of use of Kaspersky products, deploying and configuring them.
</p>

<p style="background-color:#ffffff;color:#444444;font-size:14px;">
	Please remember that using commands or recommendations from the articles without a clear understanding of their purpose may result in errors or system inoperability. Please note that some materials presented are not official, so technical support may decline to support a specific unsupported configuration in some instances.
</p>

<p style="background-color:#ffffff;color:#444444;font-size:14px;">
	<b style="color:#000000;font-size:14.6667px;">Please also ensure to use the official documentation, found in this<span style="color:#e67e22;"><span> </span></span><a href="https://support.kaspersky.com/KEDR_Optimum/2.3/en-US/220194.htm" rel="external nofollow">link.</a></b>
</p>
]]></description><guid isPermaLink="false">37647</guid><pubDate>Sat, 02 Dec 2023 17:55:32 +0000</pubDate></item><item><title>Which KES/KSWS detections generate Incident cards [EDR Optimum]</title><link>https://forum.kaspersky.com/topic/which-kesksws-detections-generate-incident-cards-edr-optimum-36947/</link><description><![CDATA[<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/advice-and-solutions-forum-knowledgebase-disclaimer-read-before-using-materials-36464/" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.</span></a></span>
</h2>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	You may wonder which product detection should create incident card, and which should not. Here's the answer.
</p>

<div style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<table style="border-collapse:collapse;padding:0px;">
		<colgroup>
			<col />
			<col />
		</colgroup>
		<thead>
			<tr>
				<th scope="col" style="border:1px solid #c1c7d0;color:#000000;padding:0px;text-align:left;vertical-align:top;">
					<div style="color:#000000;padding:0px;">
						Product
					</div>
				</th>
				<th scope="col" style="border:1px solid #c1c7d0;color:#000000;padding:0px;text-align:left;vertical-align:top;">
					<div style="color:#000000;padding:0px;">
						Component
					</div>
				</th>
			</tr>
		</thead>
		<tbody>
			<tr>
				<td style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					KES
				</td>
				<td style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					<span style="color:#242424;">WebAV, MailAV, OAS/ODS, SystemWatcher, HIPS</span>
				</td>
			</tr>
			<tr>
				<td style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					KSWS
				</td>
				<td style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					<span style="color:#242424;">OAS, ODS, TrafficSecurity</span>
				</td>
			</tr>
			<tr>
				<td style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					KSV LA
				</td>
				<td style="border:1px solid #c1c7d0;padding:7px 10px;text-align:left;vertical-align:top;">
					<span style="color:#242424;">WebAV, MailAV, OAS/ODS, SystemWatcher, HIPS</span>
				</td>
			</tr>
		</tbody>
	</table>
</div>
]]></description><guid isPermaLink="false">36947</guid><pubDate>Mon, 30 Oct 2023 17:56:45 +0000</pubDate></item><item><title>Preparing data to display. Please, wait... [EDR Optimum]</title><link>https://forum.kaspersky.com/topic/preparing-data-to-display-please-wait-edr-optimum-36946/</link><description><![CDATA[<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/advice-and-solutions-forum-knowledgebase-disclaimer-read-before-using-materials-36464/" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.</span></a></span>
</h2>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	Problem
</h2>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	Using EDR, you may encounter an issue where you're unable to view incident card regarding a detection in KSC Web Console. It looks like this:
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<img alt="image.png.8cc6dd0fd60106ec5f2abce26218d6ec.png" class="ipsImage ipsImage_thumbnailed" data-fileid="13720" data-ratio="52.01" style="height:auto;" width="423" data-src="https://forum.kaspersky.com/uploads/monthly_2023_10/image.png.8cc6dd0fd60106ec5f2abce26218d6ec.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" />
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	Here we will discuss known causes of such behavior (several products are involved, so causes may be different).
</p>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	Possible causes and solutions
</h2>

<h3 style="background-color:#ffffff;color:#000000;font-size:16px;padding:0px;">
	MDR
</h3>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	In MDR, incidents are to be viewed using the dedicated MDR Console, and KSC version<span> </span><strong>13 and newer</strong><span> </span>with configured<span> </span><strong>MDR plug-in</strong>.<strong><span> </span>KSC 12.* Web Console</strong><span> </span>will not receive the data; this is expected behavior.
</p>

<h3 style="background-color:#ffffff;color:#000000;font-size:16px;padding:0px;">
	KES+KEA
</h3>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<span style="color:#000000;">If you first install<span> </span><strong>KES without EA component</strong>, and then a<span> </span><strong>standalone KEA package</strong>, </span><span style="color:#000000;">KES EDRO integration will be disabled and killchain will not work.</span>
</p>

<div style="border:1px solid #ffeaae;color:#333333;font-size:14px;padding:10px 10px 10px 36px;">
	<div style="padding:0px;">
		<p style="padding:0px;">
			Here is a quick way to determine if<span> </span><strong>KEA</strong><span> </span>was installed as a component of<span> </span><strong>KES</strong>. Open regedit, then navigate to:
		</p>

		<p style="padding:0px;">
			<strong>[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\KasperskyLab\protected\KES\Installer\features]</strong>
		</p>

		<p style="padding:0px;">
			<code>"AntiAPTFeature" = "1"</code>
		</p>

		<p style="padding:0px;">
			If the value is<span> </span><code>0</code>, proceed to the workaround to enable the component as described below.
		</p>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<span style="color:#000000;">To fix this, we ran<span> </span><strong>Change application components</strong><span> </span>task on the host, enabling Endpoint Agent in KES. </span>
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	If KES/KEA integration is configured correctly, we can find the following in KES traces:
</p>

<div style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<div style="padding:0px;">
		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">12</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">08</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">37.426</code>   <span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0x2a18</code>   <span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">INF    edr_etw    Start processing detect = http:</code><code style="border:0px;color:#008200;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">//www.virusanalyst.com/eicar.zip//eicar/eicar.com, recordId = 6, taskId = 1128, result = 0</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">12</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">08</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">37.426</code>   <span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0x2a18</code>   <span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">INF    edr_etw    Start processing actions = http:</code><code style="border:0px;color:#008200;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">//www.virusanalyst.com/eicar.zip//eicar/eicar.com, action = 4, recordId = 6, taskId = 1128, edrAction = 3489660999, result = 0</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">12</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">08</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">37.442</code>   <span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0x2a18</code>   <span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">INF    edr_etw    Killchain is enabled!</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">12</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">08</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">37.442</code>   <span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0x2a18</code>   <span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">INF    edr_etw    SystemWatcher is running!</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">12</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">08</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">37.442</code>   <span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0x2a18</code>   <span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">INF    edr_etw    product::component::edr::`anonymous-namespace'::IsSystemWatcherDetect begin</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">12</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">08</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">37.442</code>   <span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0x2a18</code>   <span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">INF    edr_etw    product::component::edr::`anonymous-namespace'::IsSystemWatcherDetect end</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">12</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">08</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">37.442</code>   <span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0x2a18</code>   <span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">INF    edr_etw    product::component::edr::`anonymous-namespace'::InvestigateProcessIds begin</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">12</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">08</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">37.442</code>   <span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0x2a18</code>   <span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">INF    edr_etw    product::component::edr::`anonymous-namespace'::InvestigateProcessIds end</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">12</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">08</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">37.442</code>   <span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0x2a18</code>   <span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">INF    edr_etw    Finish processing detect = http:</code><code style="border:0px;color:#008200;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">//www.virusanalyst.com/eicar.zip//eicar/eicar.com threat status = 1, recordId = 6, taskId = 1128,result = 0</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">12</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">08</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">37.458</code>   <span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0x1f18</code>   <span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">INF    edr_etw    Finish processing AV detect result =<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	Searching for ThreatID in KEA traces:
</p>

<div style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<div style="padding:0px;">
		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">12</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">08</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">37.426</code>   <span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0x2a18</code>   <span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">INF    amfcd    ThreatsProcessingEventsLogic::OnTreatActionImpl: ctx:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0x23d68510</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">[TI<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0x1b8dd490</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">: id =<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0x6</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">, : tdid = {7F620459-6C51-9E46-9A5D-689A9B0D0098}, name = http:</code><code style="border:0px;color:#008200;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">//www.virusanalyst.com/eicar.zip//eicar/eicar.com, add info: &lt;none&gt;, 0x0] 0x4 0x0</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>
	</div>
</div>

<h3 style="background-color:#ffffff;color:#000000;font-size:16px;padding:0px;">
	KES+KEA (upgrade from KESB to EDR Optimum)
</h3>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<strong>EDR Optimum</strong><span> </span><u><a href="https://support.kaspersky.com/KEDR_Optimum/1.0/en-US/193103.htm" rel="external nofollow" style="color:#265951;">requires</a></u><span> </span><strong>KSC 12.1</strong><span> </span>or newer to work. This includes the<span> </span><strong>Network Agent</strong>, which is a part of KSC, and is generally installed on the host alongside KES.
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	Using an outdated version of Network Agent (10.5, 11, etc.) will lead to the mentioned error when opening incident cards. If Network Agents were not upgraded along KSC, it's better upgrading them for EDR Optimum.
</p>

<h3 style="background-color:#ffffff;color:#000000;font-size:16px;padding:0px;">
	KES 11.7+
</h3>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	Check that EDR Optimum feature is enabled in registry (GSI &gt; Registry &gt; HKLM_Software_Wow6432Node_KasperskyLab.reg.txt ).
</p>

<div style="border:1px solid #ffeaae;color:#333333;font-size:14px;padding:10px 10px 10px 36px;">
	<div style="padding:0px;">
		<p style="padding:0px;">
			<strong>[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\KasperskyLab\protected\KES\Installer\features]</strong>
		</p>

		<p style="padding:0px;">
			EdrOptimumFeature = 1
		</p>

		<p style="padding:0px;">
			If value is 0, run<span> </span><span style="color:#000000;"><strong>Change application components</strong><span> </span>task on the host, enabling EDR Optimum in KES.</span>
		</p>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	Also in traces (*.SRV.log) you can search for sentence<span> </span><strong>bundles::InstalledFeaturesProvider::InstalledFeaturesProvider</strong><span> </span>and check that<span> </span><strong>EDROptimumFeature</strong><span> </span>is there, for instance in example below such component is missing
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="border-bottom:none #cccccc;padding:5px 15px;text-align:left;">
		<span><span style="font-size:0px;text-align:left;vertical-align:text-bottom;"> </span></span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">KES.21.9.6.465_05.18_14.00_3952.SRV.log</code>
	</div>

	<div style="border-top:1px solid #cccccc;color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										 
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">11:00:36.897    0x26a0  INF bundles::InstalledFeaturesProvider::InstalledFeaturesProvider{ 3 (AVScannerAndCoreFeature)  28 (AdaptiveAnomaliesControlFeature)  0 (AdminKitConnectorFeature)  24 (AdvancedThreatProtectionFeature)  27 (AmsiFeature)  7 (ApplicationControlFeature)  17 (BehaviorDetectionFeature)  30 (CloudControlFeature)  4 (CriticalScanTask)  6 (DeviceControlFeature)  23 (EssentialThreatProtectionFeature)  11 (ExploitPreventionFeature)  8 (FileThreatProtectionFeature)  19 (FirewallFeature)  5 (FullScanTask)  2 (HostIntrusionPreventionFeature)  16 (MailThreatProtectionFeature)  14 (NetworkThreatProtectionFeature)  12 (RemediationEngineFeature)  25 (SecurityControlsFeature)  18 (UpdaterTask)  21 (WebControlFeature)  20 (WebThreatProtectionFeature)  22 (WholeProductFeature) }</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<strong>KSWS+KEA</strong>
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	The same rule applies: KEA component needs to be installed in KSWS. KSWS does not have a "Change application components" task in KSC, so this has to be taken into account during KSWS deployment.
</p>

<div style="border:1px solid #ffeaae;color:#333333;font-size:14px;padding:10px 10px 10px 36px;">
	<div style="padding:0px;">
		<p style="padding:0px;">
			Here is a quick way to determine if<span> </span><strong>KEA</strong><span> </span>was installed as a component of<span> </span><strong>KSWS</strong>. Open regedit, then navigate to:
		</p>

		<p style="padding:0px;">
			<strong>[HKEY_LOCAL_MACHINE\Software\Wow6432Node\KasperskyLab\\WSEE\11.0\Install]</strong>
		</p>

		<p style="padding:0px;">
			<code>"Features"="AntiCryptorNAS=0;AntiCryptor=0;AntiExploit=0;AppCtrl=0;AVProtection=0;DevCtrl=0;Fim=0;Firewall=0;ICAPProt=0;IDS=0;Ksn=0;LogInspector=0;Oas=0;Ods=0;RamDisk=0;RPCProt=0;ScriptChecker=0;Soyuz=0;WebGW=0"</code><br />
			<em>(<code>Soyuz</code><span> </span>needs to be set to<span> </span><code>1</code>)</em>
		</p>

		<p style="padding:0px;">
			If<span> </span><code>Soyuz</code><span> </span>is set to<span> </span><code>0</code>, apply workaround to enable it. KSWS allows to change its components<span> </span><a href="https://support.kaspersky.com/KSWS/11/en-US/147680.htm" rel="external nofollow" style="color:#265951;"><u>locally</u></a><span> </span>or via<span> </span><a href="https://support.kaspersky.com/KSWS/11/en-US/147700.htm" rel="external nofollow" style="color:#265951;"><u>cli</u></a>.
		</p>

		<p style="padding:0px;">
			Here is the example of how to set Soyuz=1 when KEA was installed not as a component of KSWS:
		</p>

		<div style="padding:0px;">
			<div style="padding:0px;">
				<div style="border:1px solid #aab8c6;color:#333333;padding:10px 10px 10px 36px;">
					<div style="padding:0px;">
						<p style="padding:0px;">
							1. Locate ks4ws_x64.msi or ks4ws.msi (depends on OS architecture)
						</p>

						<p style="padding:0px;">
							<img alt="image.png.ed72dcb0eb15dc6626054c6f750741b2.png" class="ipsImage ipsImage_thumbnailed" data-fileid="13721" data-ratio="39.14" style="height:auto;" width="672" data-src="https://forum.kaspersky.com/uploads/monthly_2023_10/image.png.ed72dcb0eb15dc6626054c6f750741b2.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" />
						</p>

						<p style="padding:0px;">
							2. Create custom installation package based on ks4ws_x64.msi or ks4ws.msi from<span> </span><strong>p.1</strong><span> </span>with parameters as per screenshot (add UNLOCK_PASSWORD= if KSWS is protected by password in policy)
						</p>

						<p style="padding:0px;">
							<a class="ipsAttachLink ipsAttachLink_image" data-fileext="png" data-fileid="13722" href="https://forum.kaspersky.com/uploads/monthly_2023_10/image.png.678e438605a287dafbfc36f8390898c6.png" rel=""><img alt="image.thumb.png.0c19022e4e7ce2fa964560653ae4932c.png" class="ipsImage ipsImage_thumbnailed" data-fileid="13722" data-ratio="23.71" style="height:auto;" width="700" data-src="https://forum.kaspersky.com/uploads/monthly_2023_10/image.thumb.png.0c19022e4e7ce2fa964560653ae4932c.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
						</p>

						<p style="padding:0px;">
							3. Deploy package on problematic servers with KSWS and KEA, then check registry that Soyuz=1
						</p>

						<p style="padding:0px;">
							<a class="ipsAttachLink ipsAttachLink_image" data-fileext="png" data-fileid="13723" href="https://forum.kaspersky.com/uploads/monthly_2023_10/image.png.23729ff996cff4e7b563cb2e08c8ee59.png" rel=""><img alt="image.thumb.png.a50f6bb82ec330f1f968f2a14f51ec19.png" class="ipsImage ipsImage_thumbnailed" data-fileid="13723" data-ratio="49.57" style="height:auto;" width="700" data-src="https://forum.kaspersky.com/uploads/monthly_2023_10/image.thumb.png.a50f6bb82ec330f1f968f2a14f51ec19.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
						</p>

						<p style="padding:0px;">
							4. Check host's properties at KSC side - EDRO should be in Running state in KEA
						</p>

						<p style="padding:0px;">
							<a class="ipsAttachLink ipsAttachLink_image" data-fileext="png" data-fileid="13724" href="https://forum.kaspersky.com/uploads/monthly_2023_10/image.png.c10e719385b8ccd7099f4a6abe2b7b34.png" rel=""><img alt="image.thumb.png.d5580e4a72d9ef7e3457cc8af4581729.png" class="ipsImage ipsImage_thumbnailed" data-fileid="13724" data-ratio="57.14" style="height:auto;" width="700" data-src="https://forum.kaspersky.com/uploads/monthly_2023_10/image.thumb.png.d5580e4a72d9ef7e3457cc8af4581729.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
						</p>
					</div>
				</div>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	If KSWS/KEA integration is configured correctly, we can find the following in KSWS traces:
</p>

<div style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<div style="padding:0px;">
		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">19</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">57</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">04.577</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">7a8<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">1310</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">info [edr] Published ThreadDetected:</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">VerdictName : HEUR:Win32.Generic.Suspicious.Access</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">RecordId :<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">DatabaseTime :<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">18446744073709551615</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">ThreatId : {ffb58079-6d8d-4a62-8ab0-021ff4ed61c5}</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">IsSilent :<span> </span></code><code style="border:0px;color:#336699;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">false</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">Technology :<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">3489661023</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">ProcessingMode :<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">3489660948</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">ObjectType :<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">3489660934</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">ObjectName : C:\Windows\System32\wbem\WmiPrvSE.exe</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">Md5 : e1bce838cd2695999ab34215bf94b501</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">Sha256 : 1d7b11c9deddad4f77e5b7f01dddda04f3747e512e0aa23d39e4226854d26ca2</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">UniquepProcessId:<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0xf7c807730e051a0d</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">NativePid :<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">3360</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">CommandLine :</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">AmsiScanType :</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">AmsiScanBlob :</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">FileCreationTime:<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">1601</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">01</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-06T23:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">09</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">56</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">.075520800Z</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	Searching for ThreatID in KEA traces:
</p>

<div style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<div style="padding:0px;">
		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">19</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">57</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">05.583</code><span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">704</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">9b0 debug [bl] ThreatsHandler: detect v2</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">verdictName: HEUR:Win32.Generic.Suspicious.Access</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">detectTechnology:<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0xd000005f</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">processingMode:<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0xd0000014</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">objectType:<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0xd0000006</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">objectName: C:\Windows\System32\wbem\WmiPrvSE.exe</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">nativePid:<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">3360</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">uniquePid:<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">17854528913448180237</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">nativePidTelemetry:<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">3360</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">uniquePidTelemetry:<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">17854528913448180237</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">downloaderUniqueFileId: &lt;none&gt;</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">downloadUrl: &lt;none&gt;</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">isSilentDetect:<span> </span></code><code style="border:0px;color:#336699;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">false</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">threatId: ffb58079-6d8d-4a62-8ab0-021ff4ed61c5</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">19</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">57</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">05.583</code><span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">704</code><span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">650</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">info [evtstt] NetworkConnectionHandler statistics: queueSize=</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">, received=</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">59675</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">, processed=</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">59675</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">, dropped=</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">, queueBytes=</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">191</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">19</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">57</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">05.583</code><span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">704</code><span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">650</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">info [evtstt] NetworkConnectionHandler statistics: queueSize=</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">, received=</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">59676</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">, processed=</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">59676</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">, dropped=</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">, queueBytes=</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">132</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">19</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">57</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">05.583</code><span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">704</code><span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">650</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">info [evtstt] NetworkConnectionHandler statistics: queueSize=</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">, received=</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">59677</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">, processed=</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">59677</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">, dropped=</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">, queueBytes=</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">371</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">19</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">57</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">05.583</code><span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">704</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">9b0 debug [bl] Threats Handler: event processed, id =<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">2</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">19</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">57</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">05.584</code><span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">704</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">1fc debug [killchain] Message discarded: name = ThreatDetect</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	The verdict is<span> </span><strong>Message discarded</strong>, this means the detection won't trigger killchain generation. 
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	No such entries can be found in traces, which might mean that EPP integration is not configured correctly (EDR component is disabled in KSWS).
</p>

<h3 style="background-color:#ffffff;color:#000000;font-size:16px;padding:0px;">
	Check killchain presence on the host
</h3>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	If all pre-requisites are met, it's worth checking if killchain files are actually created on the host. To check that, run<span> </span><code>cmd.exe</code><span> </span>as<span> </span><code>Administrator</code><span> </span>and check the c<code>:\ProgramData\Kaspersky Lab\Endpoint Agent\4.0\Data\killchain\detects</code><span> </span>folder contents. Archives with &lt;threat_id&gt;.zip names should be present in the folder:
</p>

<div style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<div style="padding:0px;">
		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">C:\WINDOWS\system32&gt;dir<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"c:\ProgramData\Kaspersky Lab\Endpoint Agent\4.0\Data\killchain\detects"</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">Volume in drive C has no label.</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">Volume Serial Number is<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">8010</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-ADC0</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												 
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">Directory of c:\ProgramData\Kaspersky Lab\Endpoint Agent\</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">4.0</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">\Data\killchain\detects</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												 
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">08</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">16</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">2021</code><span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">12</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">20</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">PM &lt;DIR&gt; .</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">08</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">16</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">2021</code><span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">12</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">20</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">PM &lt;DIR&gt; ..</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">08</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">16</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">2021</code><span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">09</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">34</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">AM<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">636</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0349c190-4ac3-4da4-9b64-07835298660f.zip<span> </span></code><code style="border:0px;color:#008200;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">//this is an archive with killchain info</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">08</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">16</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">2021</code><span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">12</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">18</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">PM<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">696</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">1d306aa7-f37f-4ab2-969e-d337d398a995.zip</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">08</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">16</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">2021</code><span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">09</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">34</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">AM<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">637</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">23a5dc93-</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">5776</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-43c8-b949-79c102aa1184.zip</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">08</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">16</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">2021</code><span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">12</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">19</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">PM<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">691</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">27bc9ea3-200b-49d2-b8b0-df7954cd428a.zip</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">08</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">16</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">2021</code><span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">12</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">19</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">PM<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">683</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">40673c70-9e8e-420f-b5ce-65b406862b94.zip</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">08</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">16</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">2021</code><span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">12</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">19</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">PM<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">688</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">590b6e30-</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">4509</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-4b25-bdb0-062f89b7e062.zip</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">08</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">16</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">2021</code><span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">12</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">20</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">PM<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">693</code><span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">67993612</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-dc82-45a2-9e5b-74756adc46eb.zip</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">08</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">16</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">2021</code><span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">12</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">20</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">PM<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">685</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">6a892bd1-f452-42d0-80b0-cb953cd7fc26.zip</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">08</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">16</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">2021</code><span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">12</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">19</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">PM<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">686</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">a63fbafa-fcef-46f7-935f-42be4392a172.zip</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">08</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">16</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">2021</code><span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">12</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">19</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">PM<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">699</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">d9d4f5eb-42b2-</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">4460</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-8f8a-eb63bbef8791.zip</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">08</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">16</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">2021</code><span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">12</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">19</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">PM<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">686</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">f6042624-</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">9840</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-4a6e-9b30-9270cce22236.zip</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">11</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">File(s)<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">7</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">,</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">480</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">bytes</code>
											</div>

											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">2</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">Dir(s)<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">240</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">,</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">763</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">,</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">092</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">,</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">992</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">bytes free</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>
	</div>
</div>
]]></description><guid isPermaLink="false">36946</guid><pubDate>Mon, 30 Oct 2023 17:54:21 +0000</pubDate></item></channel></rss>
