Kaspersky Next XDR Expert

Viewing and confirming detections performed using Adaptive Anomaly Control rules

Expand all | Collapse all

To view the list of detections performed by Adaptive Anomaly Control rules:

  1. In the main menu, go to OperationsRepositoriesRule triggers in Smart Training state.

    The list displays the following information about detections performed using Adaptive Anomaly Control rules:

    • Administration group
    • Virtual Administration Server
    • Device name
    • Name
    • Status
    • Detections count
    • User name
    • Source process path
    • Source process hash
    • Source object path
    • Source object hash
    • Target process path
    • Target process hash
    • Target object path
    • Target object hash
    • Processed

To view the properties of a detection:

  1. In the main menu, go to OperationsRepositoriesRule triggers in Smart Training state.
  2. Do one of the following:
    • In the Name column, click the link with the name of the detection you want to view.
    • In the list of detections, select the check box next to the detection you want to view, and then click the Properties button.

The properties window of the selected detection opens, displaying information about it.

You can confirm any detection from the list of detections of Adaptive Anomaly Control rules or from the properties window of a selected detection.

To confirm a detection:

  • Select one or several detections in the list of detections, and then click the Confirm button.
  • Open the properties window of a selected detection, and then click the Confirm button.

The status of the detection is changed to Confirming. The detection will disappear from the list of detections after the next synchronization of the client device with the Administration Server.

Your confirmation will contribute to the statistics used by the rules. For more information, refer to Kaspersky Endpoint Security for Windows Help.