Kaspersky Embedded Systems Security for Linux

Behavior Detection

The Behavior Detection component allows you to monitor for any malicious activity from applications in the operating system. When malicious activity is detected, Kaspersky Embedded Systems Security can terminate the process of the application that performs malicious activity.

The Behavior Detection component is enabled automatically with the default settings when Kaspersky Embedded Systems Security starts.

You can enable, disable, and configure Behavior Detection:

  • Select an action to be performed by Kaspersky Embedded Systems Security upon detecting malicious activity in the operating system: inform the user or block the application that performs malicious activity.
  • Exclude process activity from scans.

In this Help section

Configuring Behavior Detection in the Web Console

Configuring Behavior Detection in the Administration Console

Configuring Behavior Detection in the command line