Documentation Index

Fetch the complete documentation index at: https://knowledge.catonetworks.com/llms.txt

Use this file to discover all available pages before exploring further.

Managing Agentic Threat Prevention

Prev Next

Overview

Agentic Threat Prevention automatically applies controls to hosts to reduce the attack surface and help prevent threats before they impact your environment. For more information, see What is Agentic Threat Prevention?.

For each threat category,  define the automatic action: Block or Monitor and how each action is tracked. These threat categories represent different stages of the attack lifecycle, such as lateral movement or command and control. You can view the enforced rules and the threats they prevent.

Prerequisites

  • TLS is enabled

Configuring Agentic Threat Prevention

By default, Agentic Threat Prevention is enabled. For each Threat Category, the Action is set to Block, and the tracking is set to create an event. To meet your security requirements,  change these configurations.

To configure Agentic Threat Prevention:

  1. From the navigation menu, click Security > Agentic Threat Prevention.

  2. (Optional) For each Threat Category, configure the Action and tracking options. For more information, see Monitoring Agentic Threat Prevention.

  3. Enable the toggle.

  4. Click Save.

Monitoring Agentic Threat Prevention

You can monitor Agentic Threat Prevention activity with:

  • The Agentic Threats Page: View details of the controls applied to hosts and the threats prevented from the Agentic Threats page. For more information, see Monitoring Agentic Threat Prevention.

  • Events: Agentic Threat Prevention generates the following event types:

    • Control Applied: Generated when a control is applied to a host

    • Malicious Action Detected (optional): Generated when a malicious action is detected
      Configure whether to generate an Event, Notification, or both. If you have an XOps license, an XOps story is also generated

    Note: Agentic Threat Prevention Events have the subtype Dynamic Prevention. They can be viewed on the Events page with the Dynamic Prevention preset. For more information, see Analyzing Events in Your Network.

To enable Events or Notifications:

  1. From the navigation menu, click Security > Agentic Threat Prevention.

  2. For each Threat Category, click Event.

  3. Configure the required tracking options:

  4. Click Save.

Excluding Hosts From Controls

To prevent specific controls from being applied to a host, add the relevant signature to the IPS Policy Allowlist.  For more information, see Allowlisting IPS Signatures.

You can allowlist either:

  • Suspicious behavior signatures: No controls associated with the suspicious behavior are applied to the host

  • Control signatures: Only the selected control is excluded from the host

Identifying Signatures for the IPS Policy Allowlist

Identify both suspicious behavior and control signatures from the Threat Catalog. For more information, see Using the Threat Catalog.

Identifying Suspicious Behavior Signatures

Suspicious behavior signatures describe behaviors detected by the Agentic Threat Prevention engine. Opening a signature shows a description of the behavior and the controls that are applied when the behavior is detected.

To identify Suspicious Behavior signatures:

  1. From the navigation menu, click Resources > Threat Catalog.

  2. In the Engine filter, add a filter for Dynamic Prevention.

  3. In the Signature filter, enter cid_atp_c.
    The suspicious behavior signatures are displayed.

Identifying Control Signatures

Control signatures represent the individual controls that can be applied when suspicious behavior is detected. Opening a control signature shows a description of the control.

To identify Control signatures:

  1. From the navigation menu, click Resources > Threat Catalog.

  2. In the Engine filter, add a filter for Dynamic Prevention.

  3. In the Signature filter, enter cid_atp_r.
    The control signatures are displayed.

Excluding Hosts from the Events Page

Add suspicious behavior or control signatures to the IPS Policy Allowlist directly from the Events page.

Click the Signature ID link to open a panel with a pre-populated IPS Policy allowlist rule. Review or edit the rule as needed, and then click Apply to add it to the allowlist.