<?xml version="1.0"?>
<rss version="2.0"><channel><title>Kaspersky EDR Optimum Latest Topics</title><link>https://forum.kaspersky.com/forum/kaspersky-edr-optimum-177/</link><description>Kaspersky EDR Optimum Latest Topics</description><language>en</language><item><title>Number of licenses to use Kaspersky EDR Optimum in the cloud</title><link>https://forum.kaspersky.com/topic/number-of-licenses-to-use-kaspersky-edr-optimum-in-the-cloud-39474/</link><description><![CDATA[<p>
	I was researching Kaspersky EDR Optimum as I was interested in the plans. Additionally, he would like the use of the cloud resource. But I heard that to use the cloud I need 300 licenses. Is this true? I would like to know if there is a minimum and maximum license limit to use in the cloud as I didn't find any information on the internet, much less in the datasheet.
</p>
]]></description><guid isPermaLink="false">39474</guid><pubDate>Fri, 01 Mar 2024 18:21:55 +0000</pubDate></item><item><title>Exploit.Win32.generic</title><link>https://forum.kaspersky.com/topic/exploitwin32generic-38833/</link><description><![CDATA[<p>
	<span style="color:#374151;font-size:16px;">We recently encountered an issue regarding the identification of Exploit.Win32.Generic on Office files.</span>
</p>

<p>
	<span style="color:#374151;font-size:16px;">This file is important and related to the administrative section. Despite having Optimum EDR, there is no capability to examine the exploit method and address the issue.</span>
</p>
]]></description><guid isPermaLink="false">38833</guid><pubDate>Sat, 27 Jan 2024 11:39:33 +0000</pubDate></item><item><title>Difference between KES block and add IoC by ourselves.</title><link>https://forum.kaspersky.com/topic/difference-between-kes-block-and-add-ioc-by-ourselves-38602/</link><description><![CDATA[<p>
	Hi friends:
</p>

<p>
	I have read the following online help about indicators of compromise: <a href="https://support.kaspersky.com/KESWin/11.7.0/en-US/213408.htm" rel="external nofollow">https://support.kaspersky.com/KESWin/11.7.0/en-US/213408.htm</a>
</p>

<div>
	<div>
		<div>
			<span><span>Hi Kaspersky:</span></span>
		</div>
	</div>

	<div>
		<div>
			 
		</div>
	</div>

	<div>
		<div>
			<span><span>We have Kaspersky EDR optimum which let us add IoC from security center.</span></span>
		</div>
	</div>

	<div>
		<div>
			<span><span>I have questions:</span></span>
		</div>
	</div>

	<div>
		<div>
			 
		</div>
	</div>

	<div>
		<div>
			<span><span>1. If KES can detect and block a certain malicious code or activity. Do we need to add it to IoC?</span></span>
		</div>
	</div>

	<div>
		<div>
			<span><span>2. What's the difference between KES block and IoC block?</span></span>
		</div>
	</div>

	<div>
		<div>
			 
		</div>
	</div>

	<div>
		<div>
			<span><span>In my opinion, if a certain malicious code is found by our team but KES has not detect it, we should add IoC in our organization so it will be blocked ASAP. If we wait until KES block, it will casue some damage. Also, some activities is not KES responsibilities like "unsuccessful attempts to sign in". These suspicious activities should be blocked by people.</span></span>
		</div>
	</div>

	<div>
		<div>
			 
		</div>
	</div>

	<div>
		<div>
			<span><span>Is this true?</span></span>
		</div>
	</div>
</div>
]]></description><guid isPermaLink="false">38602</guid><pubDate>Wed, 17 Jan 2024 05:38:19 +0000</pubDate></item><item><title>ALERTS section of the EDR module</title><link>https://forum.kaspersky.com/topic/alerts-section-of-the-edr-module-36299/</link><description><![CDATA[<div dir="ltr" style="min-height:55px;">
	Hello, good afternoon, I am using the web version 15 LINUX but from what I have seen I cannot find the ALERTS section of the EDR module in the console, does anyone know how to activate its display again? If I go to the reports there I do see the EDR module but it is difficult for me to see the reports to interact with the EDR module
</div>

<div title="Menos">
	<i></i>
</div>

<p>
	<img class="ipsImage ipsImage_thumbnailed" data-fileid="12813" data-ratio="97.89" width="237" alt="firefox_kjv23HtKK6.png.7de22f00cffa69a073004b4831516230.png" data-src="https://forum.kaspersky.com/uploads/monthly_2023_09/firefox_kjv23HtKK6.png.7de22f00cffa69a073004b4831516230.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /><a class="ipsAttachLink ipsAttachLink_image" href="https://forum.kaspersky.com/uploads/monthly_2023_09/firefox_WZaBB8B3nI.png.a4f8abb19da235fd6e0363ebf71fd127.png" data-fileid="12814" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" data-fileid="12814" data-ratio="34.00" width="300" alt="firefox_WZaBB8B3nI.thumb.png.f94cc94f9be96744aabcca46b0dbc280.png" data-src="https://forum.kaspersky.com/uploads/monthly_2023_09/firefox_WZaBB8B3nI.thumb.png.f94cc94f9be96744aabcca46b0dbc280.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
</p>
]]></description><guid isPermaLink="false">36299</guid><pubDate>Fri, 29 Sep 2023 16:15:00 +0000</pubDate></item><item><title>EDRO - Problem with license</title><link>https://forum.kaspersky.com/topic/edro-problem-with-license-33074/</link><description><![CDATA[<p>
	I did the EDRO deployment on several devices, some have "FAILURE" in component change. Checking they have the correct license but they show "INCOMPATIBILITY WITH THE LICENSE" and in events it shows that the endpoint is being updated, when it is not (IT WAS VERIFIED).
</p>

<p>
	When removing and installing the endpoint again, it works normally again. How to fix this problem?
</p>
]]></description><guid isPermaLink="false">33074</guid><pubDate>Thu, 27 Apr 2023 16:44:18 +0000</pubDate></item><item><title>EDRO - Problem with license (Kaspersky Endpoint Security for Business ADVANCED)</title><link>https://forum.kaspersky.com/topic/edro-problem-with-license-kaspersky-endpoint-security-for-business-advanced-35447/</link><description><![CDATA[<p>
	I see Kaspersky Endpoint Security for Business ADVANCED contains EDRO.
</p>

<p>
	And I activated Kaspersky Endpoint Security 12.1.0.506 by KSC 13.2.
</p>

<p>
	It shows EDRO not covered by license on Kaspersky Endpoint Security.
</p>

<p>
	WHY ?
</p>

<p><a href="https://forum.kaspersky.com/uploads/monthly_2023_08/endpoint-advanced.PNG.7d7076534333d50dc2c1c70148eb1e0f.PNG" class="ipsAttachLink ipsAttachLink_image" ><img data-fileid="11580" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" data-src="https://forum.kaspersky.com/uploads/monthly_2023_08/endpoint-advanced.thumb.PNG.ee5438b0b563aca216f110a0d1f33fa3.PNG" data-ratio="101.69" width="295" class="ipsImage ipsImage_thumbnailed" alt="endpoint-advanced.PNG"></a></p>]]></description><guid isPermaLink="false">35447</guid><pubDate>Thu, 10 Aug 2023 03:36:49 +0000</pubDate></item><item><title>USB lock with Kaspersky Endpoint security for windows</title><link>https://forum.kaspersky.com/topic/usb-lock-with-kaspersky-endpoint-security-for-windows-33267/</link><description><![CDATA[<p>
	I need to know how I can carry out the usb blocking policy but for a specific device. It doesn't work for groups or do it per user
</p>
]]></description><guid isPermaLink="false">33267</guid><pubDate>Mon, 08 May 2023 17:37:01 +0000</pubDate></item><item><title>Task  IOC SCAN</title><link>https://forum.kaspersky.com/topic/task-ioc-scan-31778/</link><description><![CDATA[<p>
	Hi, I created an IOC task in the KasperskySecurity Center web console and ran the Scan IOC task. When the scan finished, it turned out that Google Chrome and Notepad were removed from the computer. I would like to know if there is a solution to this problem.
</p>
]]></description><guid isPermaLink="false">31778</guid><pubDate>Fri, 17 Mar 2023 07:34:29 +0000</pubDate></item><item><title>Install Kaspersky EDR</title><link>https://forum.kaspersky.com/topic/install-kaspersky-edr-31742/</link><description><![CDATA[<p>
	I am installing Kaspersky EDR. I installed Central Storage 1, then I installed Central Process 1. The problem appeared when I installed Process 2 after that. The error message "during node authorization kaspersky" appears. How can I fix this error. I use Cluster for my model
</p>
]]></description><guid isPermaLink="false">31742</guid><pubDate>Wed, 15 Mar 2023 02:20:55 +0000</pubDate></item><item><title>How to enable EDR optimum on installed  kasperky for Windows Server</title><link>https://forum.kaspersky.com/topic/how-to-enable-edr-optimum-on-installed-kasperky-for-windows-server-30589/</link><description><![CDATA[<p>
	Hi,
</p>

<p>
	i can't find out how to enable EDR optimum on installed  kasperky for Windows Server.
</p>

<p>
	I followed this video for the client, but it seems doesn't work for server.
</p>

<div class="ipsEmbeddedVideo">
	<div>
		<iframe allowfullscreen="" frameborder="0" height="113" src="https://www.youtube-nocookie.com/embed/d9zP073Y3OE?feature=oembed" title="Kaspersky EDR Optimum - Installation" width="200"></iframe>
	</div>
</div>

<p>
	 
</p>
]]></description><guid isPermaLink="false">30589</guid><pubDate>Fri, 13 Jan 2023 09:14:32 +0000</pubDate></item><item><title>EDRO - Incident Card</title><link>https://forum.kaspersky.com/topic/edro-incident-card-29932/</link><description><![CDATA[<p>
	I have some problems, i have EDR in my organization. I made some tests using a EICAR and i could see the "incident card", but now when i try open this doesn't happen. Anyone now how can i fix this?
</p>

<p>
	 
</p>
]]></description><guid isPermaLink="false">29932</guid><pubDate>Mon, 12 Dec 2022 12:45:00 +0000</pubDate></item><item><title>How to know that EDR is deployed on client side ?</title><link>https://forum.kaspersky.com/topic/how-to-know-that-edr-is-deployed-on-client-side-29121/</link><description><![CDATA[<p>
	Hi,
</p>

<p>
	All is in the title <span>:</span>
</p>

<p>
	<span>How to know that EDR is deployed on client side ?</span>
</p>

<p>
	 
</p>

<p>
	<span>Thank !</span>
</p>
]]></description><guid isPermaLink="false">29121</guid><pubDate>Thu, 10 Nov 2022 10:16:56 +0000</pubDate></item></channel></rss>
