Jump to content

Search the Community

Showing results for 'Quick Launch Keyboard'.

  • Search By Tags

    Type tags separated by commas.
  • Search By Author

Content Type


Forums

  • English Forum
    • Products for Home
    • Products for Business
    • KasperskyOS, Development
    • Kaspersky Centers of Expertise
    • Kaspersky Anti-Ransomware Tool
    • Beta Testing Products for Home & Business
  • Русскоязычный форум
    • Продукты для дома
    • Продукты для бизнеса
    • KasperskyOS, Разработка
    • Центры Экспертизы «Лаборатории Касперского»
    • Kaspersky Anti-Ransomware Tool
    • Бета-тестирование продуктов для дома и бизнеса
  • Deutschsprachiges Benutzer-Forum
    • Für Privatanwender
    • Für Unternehmen
  • Forum para usuarios hispanohablantes
    • Para usuarios particulares
    • Para empresas
  • Forum des Utilisateurs Français
    • Pour particuliers
    • Pour les entreprises
  • Fórum Brasileiro
    • Para casa
    • Para PMES e empresas
  • 中文论坛
    • 家用产品支持
    • 企业产品支持
  • Forum in Italiano
    • Utenti privati
    • Aziende
  • Türkçe Forum
    • Ev için
    • İş için
  • Nederlands Gebruikersforum
    • Voor thuis
    • Voor bedrijven
  • Forum Knowledgebase
    • Instructions
    • Advice and solutions

Blogs

  • Kaspersky Anti Targeted Attack & EDR Expert's KATA & KEDR Expert community articles
  • Kaspersky Security Center's Kaspersky Security Center Community
  • Kaspersky Endpoint Security's KES for Windows
  • Kaspersky Unified Monitoring and Analysis Platform's Advice and Slutions

Categories

  • Articles

Find results in...

Find results that contain...


Date Created

  • Start

    End


Last Updated

  • Start

    End


Filter by number of...

  1. Leo24

    KERNEL.32dll

    • Actually, it was recommended > Speed up your PC > Quick Startup > Disable autorun of rarely used apps to speedup your computer's startup... Encompassing - Wondershare App... • Concerning Internet drop-outs issue, 28 episodes from 01-Oct-24 to 08-Nov-24 were depicted for you on 09-11-24. Such as: Warning 08-Nov-24 15:26:24 Event 27, e1dexpress Intel(R) Ethernet Connection I218-LM Network link is disconnected.
  2. Thank you for your extremely quick reply - it is very appreciated. That's interesting and good to know! Thank you again; I like to keep track of updates.
  3. The Evolution of Cybersecurity: A Look at Emerging Threats and Solutions In today’s interconnected digital world, the cybersecurity landscape is in a constant state of flux. As technology evolves, so do the tactics and tools of malicious actors. At Kaspersky, Threat Research teams are at the forefront of identifying and combating these emerging challenges, offering insights that help individuals and organizations stay ahead of the curve. Here’s a deep dive into the latest trends and how businesses can bolster their defenses against the threats of tomorrow. 1. The Rise of AI-Driven Cyberattacks Artificial Intelligence (AI) is no longer just a tool for defenders; cybercriminals are leveraging it to automate attacks, develop polymorphic malware, and evade traditional detection mechanisms. AI-powered tools are being used to: Create highly personalized phishing campaigns using real-time data. Generate malware capable of adapting its code to bypass security solutions. Launch Distributed Denial of Service (DDoS) attacks with unprecedented precision. What You Can Do: Adopt AI-powered cybersecurity solutions that can analyze patterns and adapt defenses dynamically. Behavioral analysis tools, such as Kaspersky Endpoint Detection and Response (EDR), are crucial in detecting anomalous activities early. 2. Supply Chain Attacks on the Rise Supply chain attacks continue to grow in complexity. Attackers target third-party software providers or infrastructure to infiltrate larger organizations. Recent studies by Kaspersky Threat Research indicate a 30% increase in such incidents in 2024 alone. Key Examples: Compromising trusted software updates (e.g., the SolarWinds incident). Infiltrating critical cloud service providers to gain broader access. Defense Strategy: Regularly audit the cybersecurity practices of your third-party vendors. Use solutions like Kaspersky Endpoint Security for Business, which monitors software behavior across your network to flag suspicious activities. 3. Cybercriminals Target IoT Devices The Internet of Things (IoT) is becoming a favorite target for attackers due to weak security configurations and inconsistent patching. In 2024, over 1 billion IoT devices were exposed to vulnerabilities like default passwords or outdated firmware. Common Targets Include: Smart home devices (e.g., cameras, thermostats). Industrial IoT (IIoT) used in manufacturing and logistics. Mitigation Tips: Segment your network to isolate IoT devices from critical systems. Use secure gateways or hardware that integrates with IoT security platforms like Kaspersky IoT Secure Gateway. 4. The Weaponization of Generative AI Generative AI tools like ChatGPT and MidJourney are now being used by cybercriminals to automate social engineering. These tools can create convincing phishing emails, fake news articles, and even fraudulent documents in seconds. Recent Trends: Kaspersky researchers uncovered phishing kits leveraging AI to mimic corporate branding with near-perfect accuracy, leading to a significant uptick in Business Email Compromise (BEC) scams. Countermeasure: Educate employees about identifying phishing attempts. Combine training with email security solutions that use AI to spot malicious content in real-time. 5. Quantum Computing: A Double-Edged Sword While quantum computing holds promise for breakthroughs in cryptography, it also poses a significant risk. Quantum machines can potentially break traditional encryption algorithms, threatening the security of sensitive data. Future-Proofing Your Data: Transition to quantum-resistant encryption algorithms. Stay informed about the latest standards, such as those from the National Institute of Standards and Technology (NIST). 6. Zero-Day Exploits and Vulnerability Markets Zero-day exploits remain a lucrative market for attackers. These are vulnerabilities unknown to the vendor, allowing attackers to exploit systems without detection. In 2024, Kaspersky researchers identified a new wave of zero-day attacks targeting critical infrastructure. How to Protect Your Systems: Implement multi-layered security solutions, including virtual patching. Regularly update software and firmware across all devices. Conclusion: Staying Resilient in a Dynamic Threat Landscape The cybersecurity battlefield is shifting rapidly, but the tools and strategies for defense are evolving as well. Staying informed about emerging threats is the first step toward resilience. Solutions like Kaspersky Threat Intelligence Services and Kaspersky EDR are designed to provide proactive defense capabilities, helping organizations mitigate risks before they escalate. As we move further into 2024-25, a proactive approach to cybersecurity—one that combines robust technology with informed human oversight—will be key to staying ahead of adversaries. Stay secure, stay vigilant.
      • 2
      • Like
  4. Hello. Thank you for your quick reply. 1 I use Opera and Firefox 2 I don't know how to check if I'm using Incognito / Private mode? but rather not, because I didn't change it. 3 I didn't install anything extra. 4 Yes, the problem repeats. 5 The problem started a week ago. 6 I'm using Windows 11 7 Kaspersky Premium 21.19.7.527 8 Yes
  5. I got a notification around 2.55pm today (20 Nov 2024) from Kaspersky saying malicious object detected: HEUR:Trojan.Multi.Misslink.a I clicked on it too clickly and was not able to check what the detection item actually was, to diagnose where it came from. Here are the 3 logs for disinfection: How or what can I check or use to determine the source of this registry key that was so threatening? I want to know what malicious launch activity it was doing while disguising itself with Run:Steam.
  6. Dear Support Team, Please I have my website https://www.cilico.com/ and https://new.cilico.com which does not have a Phishing now. I totally cleaned it but Kaspersky keeps flagging my domain and subdomain as dangerous. This scan shows that no threats were detected in our files, further indicating that these detections are likely false positives. ClamAV Scan Results: However, these domains are still flagged, and our newly developed temporary domain, new.cilico.com, which is scheduled for an upcoming launch, has also been flagged. Kindly reanalyze for me. Help me remove the blacklist. Thank you very much!
  7. I can't launch valorant it says the app doesnt give permission to enable i cant launch valorant while kaspersky is on. It says this app doesn't give permission to open valorant. Please provide a solution
  8. Hi, I was just checking my Kaspersky license(s) the I noticed that notice(s) and notifications in notification area (bell icon) is in another language. For example, when My Kaspersky just opened (by clicking menu from Kaspersky Standard > Profile) there are two notices. One saying I have to authorize first to access My Kaspersky, the other one is about Kaspersky PURE license isn't being used but in Spanish (notifications area also in Spanish). After a refresh, the notice and notifications area changed to French. screenshots attached All other element(s) still in English and the site is set to English (I even re-set it to English) How and why did this happen? My laptop region and language setting is English (Indonesia). Installed keyboard layout are English (active) and Japanese (inactive)
  9. I finally resorted to stopping Kaspersky from starting up on next Restart. I got my software downloaded and installed, then restarted Kaspersky. Quick scan to check for threats - none detected. The file disappeared again so I know it's Kaspersky that is deleting the file and there is zero warning or record of the deletion - this is not acceptable. I want Kaspersky to aggressively protect me but not without my knowledge.
  10. Hello @Psiu47, Welcome back! For (your) own privacy & security please hide all personal information before posting to any public forum. With all bugs (you're) finding do not assume the Kaspersky 'programming staff' somehow magically know about them & will fix them; please follow the correct process & log incident requests with Kaspersky Customer Service so the issues are registered in the Kaspersky system & allocated to the expert Kaspersky teams; you can also make posts in the Forum but please include the logging of the issues into (your) process. We don't know which "bugs" (you're) referring to - they're not discussed anywhere in this topic & our recommended process is a clean install always which (you've) eventually done, successfully - which, without seeing historical data from your machine implies there was a problem with the previous installation. Again, no idea what "quick mouse action got back to normal" refers to, it's not discussed anywhere in this topic, but it's clearly fixed. Ok. fixed. Don't understand this question, please provide more information? This has been complained about by a multitude of Kaspersky users, our observation so far is Kaspersky has not shown any indication that they're willing to change it, nor have they explained why they've designed it as they have; they are aware it impacts people with vision issues. In Interface settings there's Design theme, with Dark option, it still has the two different colours but may be more comfortable (for reading/focus)? This is a known issue, currently in hand with @Mikhail Shakhov, please read: URL Adviser / URL Advisor not working (green icons missing in searchg results). Thank you🙏 Flood🐳+🐋
  11. Hey there again fellas from Kaspersky forum. It have been quite a while I was resisting to use Kaspersky Standard 21.18.5.438(a) and by then there have been bugs it were annoying me for months and the thoughts about the programming staff be willing to fix them were being left aside. I had to push my attempts to fix the problem by myself. Relieved I am by today as the unknown bugs were resolved, there have been few more problems I'm highlighting here. Went to My Kaspersky and downloaded once more KS installer. I've tried repairing the installation but no effects and bugs were still occurring. Then I pushed forward to uninstall the whole antivirus program and putt to install from scratch. After two consecutive OS restarts, the quick mouse action got back to normal. KSN / virus scan are displaying as should and seems to bug on report page are no longer disappearing. However this kaspersky4win202121.19.7.527pt_46480.exe installer is a differnt version which I've noticed later. So what was the deal for using Kaspersky Standard 21.18.5.438(a) before? Other observations I've noticed is that the interface for KS 21.19.7.527(a) is somehow mixed with a gray color bar on the left that makes the reading on the right side be harder to focus. Tried to change the interface between simple and Operating System match but made no any impact at all. Is the company looking forward to fix this color layout? Other question why is Kaspersky Protection extension on Google Chrome 130.0.6723.117 browser not popping the indexed information KSN window when I move mouse cursor onto those green K icons? They work as intended on Microsoft Edge but on Google Chrome they won't.
  12. My Windows 11 device is currently suffering from a problem that makes Explorer to launch extremely slowly and making the context menu almost unusable. The symptom looks like Explorer is taking forever to load Kaspersky's context menu. Uninstalling Kaspersky solved the issue and re-installing it can reproduce the problem. The context menu looks like this if Kaspersky is installed ("正在加载..." means Loading...) When trying to show more options, Explorer will become unresponsive and must be killed using Task Manager. If you wait long enough, the context menu will eventually load. The version of Kaspersky Plus is 21.19.7.527(a). I didn't experience this problem before yesterday, and I haven't downloaded/installed any new software during this time. I checked all other context menu entries and tried to uninstall them, but it seems like it's Kaspersky that is causing the issue. Disabling Kaspersky has no effects, it must be uninstalled for Explorer to function properly again. The last Windows Update is on 10/26 and the patch is KB5044384. I've been using Kaspersky for years and never experienced problems like this. But I think I'll just uninstall Kaspersky for my PC to handle my work properly.
  13. KarDip

    KERNEL.32dll

    Hello @Leo24 To investigate which process or application loaded this DLL and triggered the error, examining the Windows Event Logs and Process Monitor can be very effective. Here’s a step-by-step guide to help you track down the source of the load error: Step 1: Check the Windows Event Viewer The Event Viewer can reveal system or application errors related to DLL loading issues. Open Event Viewer: Press Win + R, type eventvwr, and press Enter. Navigate to System and Application Logs: In the left pane, expand Windows Logs and select System. Look for Error or Warning events that occurred around the same time as the DLL load error. Similarly, check under Application for any error entries related to DLL loading or system issues. Filter Event Logs: You can filter the logs to make it easier to find specific events. Right-click System or Application logs, select Filter Current Log…, and filter by Event level (select "Error" and "Warning") and the time range you suspect. Look for events with ID 1000 (Application Error) or ID 7000 (Service Control Manager). These may indicate specific errors related to failed DLL loads. Analyze the Event Details: Click on any relevant event and review its General and Details tabs. Note any filenames, process names, or paths related to the load error. Step 2: Use Process Monitor to Track DLL Loads Process Monitor (from Sysinternals) is invaluable for tracking file activity and pinpointing which process tried to load the DLL. Download and Launch Process Monitor: You can download Process Monitor from the Microsoft Sysinternals site. Run it as an administrator for full access to system events. Set a Filter for the DLL File: In Process Monitor, go to Filter > Filter…. Add a filter for Path that contains the name of the DLL (e.g., kernel32.dll). Click Add, then OK to apply the filter. Reproduce the Load Error: Try to reproduce the scenario that triggers the load error if possible. Process Monitor will capture the events related to this DLL. If the load error appears randomly, you can simply let Process Monitor run in the background while observing for the error. Analyze the Process Monitor Logs: Look for entries related to the DLL in question. Check the Process Name and PID (Process ID) to identify which application or service was attempting to load the DLL. Examine the Result and Details columns, especially for any entries marked with Path Not Found, File Not Found, or Access Denied errors. Investigate the Process Details: Once you have identified the process triggering the load error, you can investigate further by: Checking if this process has known issues with dependencies or compatibility on Windows 7. Verifying if updates or reinstallation are available for this application. Step 3: Review System Startup and Autoruns If the DLL load error occurs during startup, it may be linked to startup programs or services. Use Autoruns (Sysinternals Tool): Download and run Autoruns. Go to the Everything tab and search for entries related to the DLL or the process name. Disable any non-essential entries that reference the DLL, restart your computer, and see if the error persists. Summary These tools—Event Viewer, Process Monitor, and Autoruns—can give you a clearer picture of the process triggering the load error. Let me know if you discover any specifics, and I can help further analyze the findings. Thank you
  14. Wesly.Zhang

    KERNEL.32dll

    Hello, @Leo24 Received, then there is no problem with the file itself, so let's investigate who loaded this file and made the error. We may need to try to find some clues in the Windows logs. We need to get here. Start by pressing the Win + R keys on your keyboard. Second, in the pop-up Run window, type: eventvwr.msc and press Enter. Check the opened System Event Viewer for anything about the kernel32.dll error and see if there is any mention of the process that went wrong. We are waiting for your reply if you find relevant content. Regards.
  15. Leo24

    KERNEL.32dll

    "Maybe you can tell us which program you run when this error appears" •Please be informed that during download pdf articles, such announcement ..."kernel32.dll ... Entry Point Not Found"... popped up twice on two separate occasions. Also such announcement popped up, while using Pdf Creator, within an attempt to "print" the selected article. Moreover, Acrobat Reader DC version 22.3.20314.0 used to freeze for ~ 10 seconds after file opening. So, it was uninstalled and replaced with the earlier AdbeRdr11010. "whether there is any malicious program activity on your computer" •In fact, Internet drop-outs persisted for some time! Ten minutes after starting Internet session and then variously. As I was about to finish and while checking Wireless Network Connection Status, often interruption occurred. • "You can send a screenshot of the error here" Sadly, I failed to figure it out on my Latitude E5540 (Win 7 Pro), while using Fn + Print Scr keys. Possibly, due to the planned obsolescence by Dell. Consequently, some keyboard keys didn't work, yet the numeric pad numbers functioned OK.
  16. Hello @Gigabyte You’re absolutely on the right track by blocking attacker IPs temporarily and focusing on keeping everything up-to-date. The combination of Kaspersky Endpoint Security (KES) and Unifi Network Application running on the same server does introduce unique complexities, especially when managing network security in tandem with endpoint security. Let’s optimize your monitoring and incident response a bit further. Suggested Steps to Streamline Your Approach: 1. Adjust Temporary IP Blocking Policy for KES If you notice multiple repeated attacks from the same IPs, consider increasing the block time from 1 hour to 24 hours or longer to reduce workload. Use Kaspersky's automatic response settings to log attack sources more effectively and identify persistent threats. 2. Check Kaspersky Logs More Thoroughly In KES, look under: Copy code Reports → Intrusion Detection or Network Threat Protection Look for event logs that indicate blocked attacks and cross-reference the exact timestamps with the Unifi Network Application logs. This can help determine whether it’s a real attack or an environmental quirk (e.g., false positives from network probing tools). 3. Enable KES Application Control Policies (if not already active) Set rules that restrict the Unifi Network Application’s communication to trusted IPs only. This reduces the risk of malicious actors exploiting vulnerabilities in either the network or application console. 4. Unifi Controller Logs and Device Segmentation Strategy Even though the Unifi APs remain functional when KES blocks an IP, it’s worth checking: Events and Alerts in the Unifi Network Console: Look for anomalies like multiple disconnections or abnormal bandwidth usage. System logs on the server hosting the Unifi application to confirm there’s no indirect issue. Use device grouping and segmentation to ensure critical infrastructure stays isolated from guest and IoT devices on the same network. This minimizes attack surfaces. 5. Regular Threat Intelligence and Firmware Sync Continue applying the latest firmware and software updates to both KES and Unifi systems. Subscribe to Kaspersky’s Threat Intelligence feeds and Ubiquiti’s community alerts to stay ahead of any vulnerabilities or zero-day issues that may arise in their platforms. 6. Automate Device Blocking via Unifi Policies (Optional) If attacks become more frequent, you can configure Unifi's firewall rules to temporarily block devices at the AP level, rather than relying solely on KES. This will ensure that malicious connections are dropped network-wide without affecting device usability. 7. Conduct a Test Simulation Simulate an intrusion attempt in a test environment to ensure both KES and the Unifi Network Application work harmoniously without introducing conflicts. This will also give insights into which logs to focus on for quick future troubleshooting. In essence, it sounds like KES is doing its job well by blocking suspicious connections without disrupting regular operations. Keep up the monitoring efforts, and cross-check logs regularly to ensure alignment between KES and Unifi security policies. If the issue persists or escalates, a more permanent IP blacklisting strategy or additional network segmentation rules might help eliminate attack vectors more effectively. Thank you
  17. KarDip

    heur trojan-psw.script.generic

    Hello @Ray Jax No need to worry! Since Kaspersky blocked the download, it successfully prevented any potential threat from affecting your system. Just a few steps to ensure peace of mind: Delete Any Residual Files: Although Kaspersky blocked the download, checking your downloads folder or temp files for any incomplete or suspicious files is a good habit. Scan for Potential Threats: Running a quick or full system scan with Kaspersky will confirm that no other parts of this download attempt slipped through. Keep Kaspersky Updated: Ensure your antivirus definitions and program are fully updated so it continues catching any future threats. If Kaspersky blocked it right away, your system should be safe, and no further action is needed beyond these checks! Thank you
  18. @harlan4096 The file (MsiInfo.exe) still shows up as corrupted when I do a quick scan. Also, I hadn't mentioned earlier, but there is also another thing that shows up: Event: Object not processed User: OMNI\[redacted] User type: Active user Component: Virus Scan Result: Not processed Result description: Not processed Object type: File Object path: C:\Users\[redacted]\AppData\Local\VirtualStore\Program Files (x86) Reason: File not found Anything I should do? Should I upload the file here(somehow)?
  19. Hello, I'm using Kaspersky Plus and I have an issue with downloads. Whenever I try to download something from a browser, Kaspersky blocks it. This is especially noticeable with medium to large size files. Kbs files most of the time are no problem cause they're quick enough to download. But the larger files get blocked during the process. It happens on every site, even files from the Kaspersky website get blocked. If I suspend the Kaspersky protection, I'm then able to download files without problems. Kaspersky Plus version: 21.18.5.438(a)
  20. Hi guys, Thanks for the quick response. #3. Yes, it has been running on my system for almost a year but I always had issue with Gliffy and Draw.io in Confluence. They just did not work. Yesterday, after some months of quiet time, I gave another go to Confluence with Draw.io (a new temporary full license and added Draw.io to my space). I made my first diagram but after saving it, I got the error above, "Diagram Not Found". I tested this issue with Edge, Chrome and Firefox (including private browsing) on Windows 10 and I could not see my diagram in Confluence. Then I read the following case at the Atlassian Community website. So I de-installed Kaspersky Premium and surprisingly I could see my Draw.io diagram in all Internet browser platfroms. Then I re-installed Kaspersky Premium (it was a clear install", and installed/enabled Kaspersky Protection Extension for Firefox. This produced the original problem with reading my Draw.io diagram. I played with Kaspersky Protection Extension for Firefox but nothing worked (even disabling it). So I removed Kaspersky Protection Extension from Firefox, and restarted Firefox. Unfortunately, my Draw.io still did not work and Kaspersky Premium still showed that the Kaspersky Protection Extension for Firefox is ON. Then I stopped and started Kaspersky Premium again and finally it showed that Kaspersky Protection Extension for Firefox was not enabled. And my Draw.io diagram worked again. #2. I will test this and come back #1. I did not enabled Kaspersky Protection Extension, for Private Browsing. But I tested the issue on all the three Internet browser platform in Private (Firefox), Incognito (Chrome) and InPrivate (Edge) modes, none of them worked. The same happend in non private mode of these Internet browsers. I will set this up for Private browsing to see how it works.
  21. How hard is it to give us an option to disable that very annoying popup? Your users have been suffering for years and have been asking for a way to get rid of the secure keyboard input popup while still having the feature ENABLED and working in the background, but things are the same even with your latest editions (Kaspersky Plus). I think whoever thought it was a smart idea to remind the user about it every single time shouldn't have the power to manage and develop your software. Im a paying customer since 2006 and I had to turn off this feature and live without it whenever it came out (it's definitely been 5+ years). I just moved to a new computer and I've been configuring my settings and guess I will still need to disable it and live without that feature for many years to come...
  22. Hello @ LouisLewis To address the attack and improve your protection, I’ll walk you through several possible solutions to enhance your Kaspersky Endpoint Security (KES) configuration and bolster your network defenses. Since this attack caused a disruption, it indicates either a potential misconfiguration or an area where additional layers of protection are needed. Here’s a step-by-step approach to strengthen your setup: 1. Review Kaspersky Configuration and Policies Application Privilege Control: Ensure Application Control is fully enabled and configured. Set up Network Rules to restrict certain IP addresses or block applications that attempt suspicious outbound or inbound connections. Intrusion Detection and Prevention (IDS/IPS): Enable the Network Attack Blocker feature in KES if it’s not already active. This module can detect and prevent suspicious network behavior. Web Control: Use Web Control policies to block access to malicious sites or IPs flagged during the attack. Cross-check the IP in Kaspersky’s threat intelligence or an external source like VirusTotal to confirm its malicious intent. 2. Block the Attacking IP Address on the Firewall Even though KES offers endpoint protection, it is crucial to complement it with perimeter defenses. Add the IP to your firewall blocklist. Use Geo-blocking if the attack originates from a suspicious or irrelevant region. Implement Rate Limiting or Traffic Shaping on your firewall to mitigate DDoS or flood attacks. 3. Enable Firewall and Host Intrusion Prevention on Endpoints Make sure that KES Firewall is properly configured: Add a custom rule to block the specific IP address involved in the attack. Enable Host Intrusion Prevention (HIPS) to detect and block exploitation attempts on endpoints. 4. Update Threat Feeds and Indicators of Compromise (IoC) Use Kaspersky's Threat Intelligence feeds and any available IoCs to proactively block known bad IPs or domains. If your KES has EDR (Endpoint Detection and Response) or Threat Hunting capabilities, upload any indicators (e.g., the attack method or IP address) to block future attempts. 5. Advanced Logging and Alerts Setup Enable event logging and notifications in Kaspersky Security Center (KSC): Configure alerts for specific events such as repeated failed login attempts, new IP connections, or brute force attacks. Integrate KSC with your SIEM solution to get real-time monitoring and correlate logs for suspicious activity. 6. Check for Configuration Gaps Run a KES Policy Audit: Make sure all machines have the latest KES policies applied. Use Security Profile Reports in KSC to identify any endpoints with incorrect configurations. Install Kaspersky Network Agent (NA) on all endpoints to ensure real-time communication with KSC. This helps with quick policy updates and ensures accurate reporting. 7. Complementary Security Measures Implement Multi-Factor Authentication (MFA): This mitigates risks from unauthorized login attempts. Patch Management: Ensure all software on your endpoints is up-to-date to avoid vulnerabilities. Summary of Actions: KES Configuration: Ensure IDS/IPS and firewall rules are configured correctly. Add IP-specific block rules. Firewall Configuration: Block the attacker’s IP and implement rate limiting. Alerts & Notifications: Enable logging and alerts for suspicious activity in KSC. Threat Intelligence: Regularly update Kaspersky with IoCs and threat feeds to block known malicious IPs proactively. By reinforcing both KES and your network firewall, you’ll minimize the chances of a future attack causing service disruptions. If you need help auditing your Kaspersky setup or configuring any of the above features, let me know! Thank you
  23. Hello, Please check this article for further details about adding an Applications Launch Control rule : https://support.kaspersky.com/KSWS/11.0.1/en-US/178908.htm
  24. I'm trying to install kaspersky stander plus, once downloaded the installer do nothing. I have tried: Run as administrator Clean temp files Installed framework 4.8 Windows updates are up to date I dont know what else to do. The installer does not run on windows 10. The wizard to instal the antivirus does not appear.
  25. Hi, I had run a quick scan about two days ago, and I hadn't noticed that the AV had found two (one?) corrupted objects and a missing file. Just wanted to know what I can do about it and what it means. The relevant part of the log: 10/14/2024 6:32:35 AM C:\Program Files (x86)\Windows Kits\10\bin\10.0.22621.0\x86\MsiInfo.exe\Obsidium Corrupted Object corrupted File C:\Program Files (x86)\Windows Kits\10\bin\10.0.22621.0\x86\MsiInfo.exe// Obsidium Corrupted OMNI\[redacted] Initiator 10/14/2024 6:32:35 AM C:\Program Files (x86)\Windows Kits\10\bin\10.0.22621.0\x86\MsiInfo.exe Corrupted Object corrupted File C:\Program Files (x86)\Windows Kits\10\bin\10.0.22621.0\x86 MsiInfo.exe Corrupted OMNI\[redacted] Initiator 10/14/2024 6:34:03 AM C:\Users\[redacted]\AppData\Local\VirtualStore\Program Files (x86) Not processed Object not processed File not found File C:\Users\[redacted]\AppData\Local\VirtualStore\Program Files (x86) Not processed OMNI\[redacted] Active user
×
×
  • Create New...