Behavior Detection
By default, the Behavior Detection component starts when Kaspersky Embedded Systems Security starts and monitors the malicious activity of the applications in the operating system. When malicious activity is detected, Kaspersky Embedded Systems Security can terminate the process of the application that performs malicious activity.
Behavior Detection component settings
Setting |
Description |
---|---|
Behavior Detection enabled / disabled |
This toggle button enables or disables the Behavior Detection component. The check toggle button is switched on by default. |
Behavior Detection component operating mode |
The action to be performed by Kaspersky Embedded Systems Security upon detecting malicious activity in the operating system:
|
Exclusions by process |
Clicking the Configure exclusions by process link opens the Exclusions by process window. In this window, you can exclude the activity of processes. |
Exclusions by process window
The table contains the exclusion scopes for exclusion by process The exclusion scope for exclusion by process lets you exclude the activity of the indicated process and files modified by the indicated process. By default, the table is empty.
Exclusion scope settings for exclusion by process
Setting |
Description |
---|---|
Exclude / Do not exclude trusted processes from scans |
The switch enables or disables the configured exclusions by process in the operation of the Behavior Detection component. The toggle button is switched off by default. |
Exclusion scope name |
Exclusion scope name. |
Path |
Full path to excluded process. |
Status |
The status indicates whether the application uses this exclusion. |
You can add, edit, and delete items in the table.
Page topAdding a process exclusion scope window
In this window, you can add and configure exclusion scopes for exclusion by process.
Exclusion scope settings
Setting |
Description |
---|---|
Process-based exclusion scope name |
Field for entering the Process-based exclusion scope name. This name will be displayed in a table in the Exclusions by process window. The entry field must not be blank. |
Use this exclusion |
This check box enables or disables this scan scope exclusion when the application is running. The check box is selected by default. |
Path to excluded process |
Full path to the process you want to exclude from scans. You can use masks to specify the path. The entry field must not be blank. |
Apply to child processes |
Exclude child processes of the excluded process indicated by the Path to excluded process setting. This check box is cleared by default. |