Kaspersky Endpoint Agent

Enabling Anomaly Detection using Sigma Rules

August 27, 2024

ID 270608

To enable Anomaly Detection using Sigma rules:

  1. Do one of the following:
    • for a group of protected devices, open the application policy properties window.
    • for an individual protected device, open the application settings for the device.
  2. In the Anomaly Detection using Sigma rules section, select the Enable Anomaly Detection using Sigma rules check box.
  3. Add one or more collections of Sigma rules.
  4. Click the Save button.

    Kaspersky Endpoint Agent will search for anomalies using the enabled collections of Sigma rules.

See also

Changing the state of a collection of Sigma rules

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.