Windows Agent Features

The Windows agent provides comprehensive workstation monitoring, capturing user activity, network connections, file operations, application executions, and peripheral device events. Built-in analysis and blocking mechanisms prevent information leaks. A configurable rules system allows you to tailor agent behavior to your organization’s specific requirements.

Agent Distribution

Installation, Update, Removal

Several methods are supported:

  • Web console commands

  • Active Directory and Kaspersky Security Center

  • Staffcop remote installation utility

  • Staffcop interface installer

Agent Protection

Prohibit Actions Without a Password

When protection is enabled, a password is required to delete, stop,
change, or update an agent

Local Agent Database Encryption

The agent encrypts all collected data and writes it to the local database.

Assigning Agents

Apply Configuration

Using agent list, domain, or Active Directory group

Monitoring Agent Status

Monitor Agent and PC Status

The service automatically transmits the following data to the server:

  • Agent presence and functionality

  • Agent update and deletion status

  • PC network availability

Data Collection Settings

Data Collection Settings

Configurable packet size, interval, server sending interval, compression.
If there is no server response, the interval is automatically increased.

Local Agent Database

Events and files are stored in the local database.
If the database is full, old data is overwritten: first files, then events.
When the specified size is exceeded, the current log is saved to the archive and the agent starts writing to a new file.

Agent Logs

User Monitoring

Login and Session Monitoring

Monitors local and remote employee authentication,
distinguishes between local and remote sessions,
records session blocking and unblocking.

Monitoring Exclusions

Allows you to exclude users from statistics collection.

Application Control

Launch and Installation Monitoring

Monitors application installation, launch, and activity.

Application Blocking

Blocks system and user processes.

Exclusions

Black/white lists for monitoring and blocking applications.
Excludes the installation, activity, and launch of selected applications from monitoring.
Blocks applications from the list.

Alerts

Configure alerts for access attempts to blacklisted applications or sites.

Activity Tracking

User Activity Monitoring

Monitors employee activity.
Used in all Time Tracking reports.

Application Activity

Creates an Activity Time event based on activity in the focused application
Determines websites visited by employees via browsers.

Adjustable Activity Period

Sets the length of idle time after the user’s last action.

Screenshots

General Features

Takes screenshots to record employee actions.
Screenshot quality, color depth, and compression are configurable.
Capture frequency for individual apps and websites can also be set.
Creates a Screenshot event.

Screenshots on Changing Focus

Takes screenshots when the active app changes.
Takes two screenshots: immediately upon focus change and after a specified interval.

Screenshot Interval

Takes screenshots at a specified interval from the start of the user’s activity.
If the interval is set to 0, no periodic screenshots are taken.
Does not take screenshots of lock screen.

Special control

Captures screenshots at a specified interval for certain apps and websites.
You can set a custom interval for specific apps or websites.

Screenshot Batch

Continuous Screen Recording

A series of screenshots, regardless of user activity.
Using screenshots instead of video saves disk space.

Interval and Duration

Configurable interval between screenshots in a batch.
Set the packet duration.

Quality and Compression

Adjusts color depth, quality, and compression algorithm.
The agent automatically adjusts compression based on load.

Cursor Display

The cursor is drawn on each screenshot to help understand user actions.

Keyboard and Clipboard

Keyboard Input

Keyboard input monitoring: intercepts text and passwords.
Low-level keylogger also intercepts system keystrokes.
Intercepts passwords in Windows dialog boxes during system authentication without tying them to a user.
Keyboard Input Event

Clipboard

Intercepts text and screenshots from the clipboard.
Creates a Clipboard event with text or image information.
Blocks copy-paste operations across applications.

Drag-and-Drop

Blocks moving text or files by dragging them between windows.
No errors or notifications are displayed; the movement simply doesn’t occur.

Command Input Control

Intercepts command input and output in cmd.exe and PowerShell.
Creates a Command Input Terminal event.
Large command output is split across multiple events.

Keyboard Exclusions

Black and white lists of applications to exclude from keyboard input monitoring.
Clipboard exclusions are not available.

Watermarks

Display Watermarks

Overlaid on the user’s screen for applications, websites, or windows specified in the rules.
Display the exact time.
The agent displays the watermarks even when activity tracking is disabled.
Works only when rules are configured.
For permanent display, create a rule for Windows Explorer (explorer.exe).

Display settings

You can customize the angle, transparency, and font size.
Ranges from 0 (transparent) to 255 (opaque).
The refresh rate of watermarks ranges from 60 to 1800 seconds.

Rule Configuration

You can configure a complex query for the rendering script.

  • Related article

Network Connections

Network Activity Monitoring

Captures traffic from instant messengers, email, web forms, and search queries.
Certificate substitution for HTTPS access.
Blocks websites, shadow copying of files during uploads.
Creates Network event.

Exceptions Configuration

Black and white lists for applications, IP addresses, ports, and web addresses.
Disable certificate substitution for individual resources to stop interception.
Learn more about exceptions in the article Network Connections

Internet

Web Traffic Monitoring

Intercept browser requests to web resources.
Create shadow copies of files when uploading to web resources.

Search Queries

Capture search queries in search engines.
Requires network monitoring to be enabled.
Creates a Search Query event.

Web Forms

Intercepts data and file submitted through web forms.
Creates a Form Data event.

Configure Exclusions

Black and white lists for managing:

  • Websites — exclude from interception by content type

  • Web Forms — disable form monitoring for specific resources.

Block Websites

Black and white list to block or allow web resources.

Mail and Messengers

Webmail

Interception of outgoing messages and attachments in web services:
Gmail, Yandex, Mail.ru, Rambler.ru, Outlook.com, VK Mail.
Drafts are created for unsent messages.
Creates Mail event or Intercepted file event for attachments.

Mail Clients

Intercepts incoming and outgoing messages and attachments sent or received in mail applications
via any supported protocols: POP, IMAP, SMTP, or MAPI.
Creates Mail event or Intercepted file event for attachments.

Messengers

Intercepts all correspondence and files in desktop and web versions of messengers:
MS Teams, Bitrix24, WhatsApp, VK Teams, Yandex Messenger, Max


WhatsApp from the Microsoft Store is not intercepted.
Telegram: incoming/outgoing messages, outgoing attachments only,
file search for non-standard installations. The desktop version of Telegram
does not require network monitoring or certificate replacement.


Creates Internet pager event or Intercepted file event for attachments.

Cloud Services

Intercept file uploads and downloads in web versions of:
WebDav, OneDrive, Yandex Disk, Google Drive.
Creates Messenger event or Intercepted file event for attachments.

Files

File Operation Monitoring

Intercepts user and background file operations.
Generates a File Operations event

Shadow Copying

Creates a shadow copy when writing a file to an external drive or network share.
Copies are not created for files intercepted from networks, files with a size of 0,
or files larger than set limit.
Intercepted File event

FTP

Intercepts FTP data transfer.
FTP event

External Storage and Mobile Devices

Intercepts files from USB storage devices and mobile devices (WPD) upon connection.
File Operations Disk Contents event

Performance Settings

SMB Caching — speeds up processing of file operations with large amounts of data.
File Name Normalization — converts short Windows names to full names
to ensure the correct file name is displayed in events.

Exclusion Settings

Black and white lists using location, mask, and application; exclusion of Read operations and associated shadow copies.
For more information, see Files

Devices

Device Connection Control

Intercepts USB device connections.
Creates Device event.
For external drives, an additional External Drive event is created.
This module must be enabled for read-only mode and device blocking,
as the rules are applied at the time of connection.

Access Restriction

Blocks USB drives: full blocking or read-only.
Blocks file operations for CD drives.
Rules are applied when device is connected.

CD Drive Monitoring

Intercepts user and background file operations on CD drives.
Creates shadow copies of all file operations on CD drives.
Creates File Operations event or Intercepted file event for copies.

Exclusion Settings

Black and white lists using device ID, class, and group.
For more information, see Devices

USB Manager

USB Control

The agent records the serial numbers of USB drives.
Creates a Device event

Access Control

Restricts user actions with specified USB serial numbers
based on rules set in the USB manager.

Printers

Print Monitoring

Monitors printing.
Printing event with a document shadow copy and screenshot.

Interception Settings

The agent intercepts the document in the system print queue.
If the printer bypasses the queue, the agent automatically reconfigures it for interception.

Webcams

Webcam Snapshots

Takes webcam snapshots at a specified interval.
Enables user identification through facial recognition in snapshots.
Webcam Snapshot event

Snapshot Settings

Select camera: all or default only.
Snapshots only occur when the user is logged in and active.
Configure the snapshot interval. A separate interval for apps and websites under special control is available.

Offline Webcam Recording

Continuous recording of webcam video in segments of a specified duration.

Audio Recording

Audio Recording

Records audio from the microphone and/or speakers.
Starts when the noise threshold is exceeded, stops when noise stops.

Recording Settings

Configurable duration, microphone volume increase,
silence interval, recording quality, and noise threshold.

Application Recording

Records audio when an application from a set list is running.
Recording settings are configured separately.

Remote Control

Remote Connection

Allows you to connect from the server to an employee’s screen to monitor their actions.

Remote PC Lock

Completely locks user access to the system on administrator command.
Unlocks from server.

Remote Disk Lock

Blocks read and write access for all connected devices.
Unlocks from server.

Video Control

Online Desktop Recording

Real-time screen recording.
Recording is triggered only when user activity is detected.
A cursor is drawn on each frame to help understand user actions.
Desktop video event

Offline Desktop Recording

Continuous screen recording, regardless of activity and connection to the server.
Desktop video event

Recording Settings

Configurable frame rate, bit rate, and fragment duration

Special Control

Records only when using specified applications and websites.
Applications and websites are specified in the rules.

Inventory

Devices

Scans the registry of installed devices whenever you change configuration.
Device inventory event

Software

Scans the registry of installed software when the configuration changes.
Device inventory event

Local Users

Scans local accounts on the computer when the configuration changes.
Displays list of users, permissions, status, and last access date.
Scans each time the configuration is retrieved.

Presence at Workplace

Tray Indicator

Displays the agent icon in the taskbar.
Specified text is displayed on hover.

Notifications

Notification when agent configuration changes.

Reason for Absence

If agent is inactive for a long time, a reason will be requested.
The user’s response is sent to the server and generates a Reason for absence alert.
The inactivity period before the request is configurable.

Availability check

If agent is inactive for a long time, a verification question will be sent.
A correct answer results in a Presence confirmed event,
an incorrect answer results in a Presence confirmed with error event,
no answer results in an Absence from work event.
The maximum response time is configurable.

Working Hoursя

Data collection and blocking are performed only during the specified working day.
The agent can request a scheduled end of workday and PC shutdown..

User Agent Management

The user can disable statistics collection and blocking via the tray menu.

Tags and Access Blocking

DLP Module

The agent analyzes file content during file operations.
If a tag is found, it is recorded in an event.

Blocking Rules

If the blocking rules are triggered, the agent stops the operation.
Sends the Operation blocked event to the server

Video Conference System

Sharing Detection

The agent detects the start of screen sharing during a video conference.
Sends the Screen sharing alert to the server every minute sharing is active.

Block Sharing

The agent blocks screen sharing if the DLP module detects a file that matches the blocking rules.
Sends a notification to the server upon blocking.
A notification can be configured for the user. If no text is specified, the employee will not receive any notification.

File Scanner

File Scan

The agent scans files with the specified content types in the workstation directories.
Network resources and connected devices are not scanned.
A File event is created, which contains the file dimensions and text content.

Exclusions

Black and white lists using paths and masks exclude files from scan results.

Bulk Copy

Block Bulk Copying

The agent blocks external drives if too many files or data are written to them
within the specified time period.
When triggered, the server status is set to Blocked Drives

Trigger Conditions

Threshold exceeded for one of the following parameters:

  • Number of copied files

  • Total volume of copied data

Monitoring Exclusions

Event Exclusion

If an event matches the exclusion rules, the agent does not record it or send it to the server.

Scope

Applies to screenshots, video recordings, and files intercepted during file operations.
If online recording is enabled, the agent terminates the remote connection,
to protect data from being recorded.

Last Updated: 21.08.26