for Windows
The component monitors operations performed only with those files that are stored on mass storage devices with the NTFS file system and that are not encrypted with EFS.
Protection of shared folders against external encryption provides for the analysis of activity in shared folders. If this activity matches a behavior stream signature that is typical for external encryption, Kaspersky Endpoint Security performs the selected action.
If Kaspersky Endpoint Security detects an attempt to modify files in shared folders, it takes the following actions:
Anti-Cryptor settings for Pro View
Parameter |
OS |
Description |
|---|---|---|
Action on threat detection |
|
Inform. If this option is selected, on detecting an attempt to modify files in shared folders, Kaspersky Endpoint Security adds information about this attempt to the list of active threats, and adds an entry to the report. Block connection for (min) N min. If this option is selected, when Kaspersky Endpoint Security detects an attempt to modify files in shared folders, it blocks access to file modification for the session that initiated the malicious activity and creates backup copies of the modified files. |