Advice Request Kaspersky Endpoint Security Custom Install Info needed

  • Thread starter Deleted member 2913
  • Start date

Please provide comments and solutions that are helpful to the author of this topic.

Status
Not open for further replies.
D

Deleted member 2913

Thread author
Check this link about Kaspersky Monitores ports setting, I think is also applicable to KES10.
Taken from KES10 Help:


KES10 has Anti-Phishing settings integrated in its Web Anti-Virus module.

Yes...

Yes...

And yes (using KSN service)... :D
Couple software in Low Restricted were transferred to Trusted...thats good.

Port 443 is used only for email & not HTTPS websites?
 
  • Like
Reactions: Logethica

harlan4096

Moderator
Verified
Staff Member
Malware Hunter
Well-known
Apr 28, 2015
8,671
Yes, I think there is no scanning for encrypted connections in KES10, as in home products (KAV/KIS/KTS), no Kaspersky Root Certificate is used (pinning) in browsers. But I think is users to filter traffic for HTTS in same way, as You can see in KES10 Monitores ports setting:
Sin_t_tulo.png
 
Last edited:
D

Deleted member 2913

Thread author
harlan,

I dont know anything about ports & dont understand too technical things.

I see in the screenshot only port 443 is mentioned as HTTPS. So does this means everything HTTPS works through port 443?
Or what all for port 443 is used?

Are you too running KES?

I read in the forum here you are a Gold Beta Tester for Kaspersky.
What does GBT for Kas means i.e benefits of GBT for Kas?
And you beta test KES too?
 
  • Like
Reactions: Logethica

harlan4096

Moderator
Verified
Staff Member
Malware Hunter
Well-known
Apr 28, 2015
8,671
I think not only Mail Traffic: Network Traffic Interception

Yes, I have KES10 installed in my laptop (with W10 Pro x86 and managed by KSC10, which is in a Windows Server 2002R2) :)

Yes, I'm GBT, but mostly for home products, I have not enough big infrastructure (and time) to test corporate products :D

To be GBT, in general are users that usually tests/check new beta products, sending reports and reporting bugs... it's Kaspersky who selects You as an official GBT. If You usually join many Kaspersky beta testings and are very active in their official forum, They will probably name You as a GBT in the end (that's how I became a GBT).

Benefits? well, actually not many... after every beta testing (depending on the products) They usually reward with free licenses. And in some special beta testings and if You are very active, You even may get some others gifts...
 
Last edited:
D

Deleted member 2913

Thread author
harlan,

Thanxx for replying all my queries. You have been a great help.

For now I have no queries regards KES.

If any will request you the info here.

Hav fun
 
D

Deleted member 2913

Thread author
Oh damn, I had it in my mind but forgot to ask.

Notification settings - I am lost in this. There are so many options, dont know what should be enabled & not?

So what you say?
 

harlan4096

Moderator
Verified
Staff Member
Malware Hunter
Well-known
Apr 28, 2015
8,671
Well, Notifications options in KES10 are fully rich :) I would like to have them also in Kaspersky home products :mad: (many of them were cut some years ago since 2014 version).

Well, IMHO I would enable all those related to detection/disinfection/quarantine (as there is no Interactive Mode in KES10) and all related to movements of applications to low/high restricted/untrusted groups...
 
D

Deleted member 2913

Thread author
Is the "System Audit" for remote management or local system?
Coz there are some duplicates i.e same option in system audit & file/web, etc...
 
D

Deleted member 2913

Thread author
If Your KES10 are not managed by KSC10, them local system.
Ok.

The local help files are not in detail in regards to all the notification events.

Any online help files with detail explanation of events?

I tried enabling some events & tried opening couple programs & started getting quite a few popups for single program.
 

harlan4096

Moderator
Verified
Staff Member
Malware Hunter
Well-known
Apr 28, 2015
8,671
Well, here You are my Notifications on Screen. I'm in "Paranoid Clan", so I try to emulate "Interactive Mode" of KIS/KTS :D. Maybe so many notifications, feel free to disable the ones You don't want or annoy You.
image.png

image.png

image.png

image.png

image.png

image.png

image.png

image.png

image.png

image.png

image.png

image.png
 
D

Deleted member 2913

Thread author
harlan,

No System Audit screenshot? You haven't enabled any on that? Coz protection components, self defense, etc... options are there.

I see you have not enabled informational events...I too will not enable...critical & important covers need to know events...no need IEs.

I enabled most events & testing with harmless samples & other way to get an idea of the alert type, number of alerts, etc...

Is Firewall in KES & Home products same or KES Firewall is on little stricter side?
 

harlan4096

Moderator
Verified
Staff Member
Malware Hunter
Well-known
Apr 28, 2015
8,671
Too many events/notifications logging not so good I think :D too much information, even maybe affecting the performance of the system...

I just showed my screen notifications, all the others kept by default...
 
D

Deleted member 2913

Thread author
I have set notification for events. I have altogether set only 9 notifications. Some dont need, some not important & can be checked from reports, some windows security center also takes care, etc...

For now it seems my KES is set.

Thanxx for your time & support harlan.
 
D

Deleted member 2913

Thread author
In KES, is there a way to set "App Control Rules" to default i.e default apps will be there & all the other apps will be removed?
 
  • Like
Reactions: Logethica

harlan4096

Moderator
Verified
Staff Member
Malware Hunter
Well-known
Apr 28, 2015
8,671
Sorry for my late answer, so busy days...

I'm not sure what You mean... You have Default Control Rules/Different Trusted Groups according to KSN/White Listing. You may change those rules... but no rules for delete except if malware is detected (disinfect, delete, etc.).
 
  • Like
Reactions: Logethica
D

Deleted member 2913

Thread author
Sorry for my late answer, so busy days...

I'm not sure what You mean... You have Default Control Rules/Different Trusted Groups according to KSN/White Listing. You may change those rules... but no rules for delete except if malware is detected (disinfect, delete, etc.).
I meant reset application control to default i.e like it was at the time of install i.e remove all the new added programs under application control.

I got it. Under advanced settings - manage settings - restore gives quite a few options to reset to defaults.
 
  • Like
Reactions: Logethica
D

Deleted member 2913

Thread author
harlan,

Couple programs are in trusted as well in low restricted?
Like one of my portable programs entry pkeyconfigs.exe is under trusted 1 time & under low restricted 3 times. All 4 seems the same entry.
The entry in trusted & 2 entries in low restricted always show "Today" for "Appeared in KSN" & less than 10 users. And the remaining 1 in low restricted shows 12/20/2012 for 'Appeared in KSN" & more than 10,000 users.

Any info?
 
  • Like
Reactions: Logethica
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top