Kaspersky Next XDR Expert

Obtaining and viewing a list of executable files stored on client devices

You can obtain the list of executable files stored on client devices in one of the following ways:

  • Enabling notifications about applications startup in Kaspersky Endpoint Security policy.
  • Creating an inventory task.

Enabling notifications about applications startup in Kaspersky Endpoint Security policy

To enable notifications about applications startup:

  1. Open the Kaspersky Endpoint Security policy settings, and then go to General settingsReports and Storage.
  2. In the Data transfer to Administration Server settings group, select the About started applications check box, and save the changes.

When a user attempts to start executable files, information about these files is added to the list of executable files on a client device. Kaspersky Endpoint Security sends this information to Network Agent, and then Network Agent sends it to Administration Server.

Creating an inventory task

For Kaspersky Endpoint Security for Linux, the feature of inventorying executable files is available since no earlier that version 11.2.

You can reduce load on the database while obtaining information about the installed applications. To save database space, run an inventory task on reference devices on which a standard set of software is installed. The preferable number of devices is 1-3.

To create an inventory task for executable files on client devices:

  1. In the main menu, go to Assets (Devices) → Tasks.

    The list of tasks is displayed.

  2. Click the Add button.

    The New task wizard starts. Follow the steps of the wizard.

  3. On the New task settings page, from the Application drop-down list, select Kaspersky Endpoint Security for Linux or Kaspersky Endpoint Security for Windows, depending on the operating system of the client devices.
  4. From the Task type drop-down list, select Inventory.
  5. On the Finish task creation page, click the Finish button.

After the New task wizard has finished, the Inventory task is created and configured. If you want, you can change the settings for the created task. The newly created task is displayed in the list of tasks.

For a detailed description of the inventory task, see the Kaspersky Endpoint Security for Linux Help and the Kaspersky Endpoint Security for Windows Help.

After the Inventory task is performed, the list of executable files stored on managed devices is formed, and you can view the list.

During inventory, executable files in the following formats can be detected (depending on the option that you select in the inventory task properties): MZ, COM, PE, NE, SYS, CMD, BAT, PS1, JS, VBS, REG, MSI, CPL, DLL, JAR, and HTML.

Viewing the list of executable files stored on managed devices

To view the list of executable files stored on client devices:

In the main menu, go to Operations → Third-party applications → Executable files.

The page displays the list of executable files stored on client devices.

If necessary, you can send the executable file of the managed device to the device where your OSMP Console is open.

To send an executable file:

  1. In the main menu, go to Operations → Third-party applications → Executable files.
  2. Click the link of the executable file that you want to send.
  3. In the window that opens, go to the Devices section, and then select the check box of the managed device from which you want to send the executable file.

    Before you send the executable file, make sure that the managed device has a direct connection to the Administration Server, by selecting the Do not disconnect from the Administration Server check box.

  4. Click the Send button.

The selected executable file is downloaded for further sending to the device where your OSMP Console is open.

See also:

Using Application Control to manage executable files