Configuration Field Descriptions and Default Settings

The following table provides a brief description and default values for the Kiosk Configuration screen.

Basic Configuration

Configuration SettingDescriptionDefault ValueRange
Primary MetaDefender ServerURL of the primary MetaDefender server(Blank)
API KeyThe API Key of the primary MetaDefender server, if one is set(Blank)
Server is a load balancer

Indicates that the primary server is a load balancer for MetaDefender

If checked, the API key is disabled

Unchecked
Periodically test Core servers every # hours

Periodic interval in which Kiosk will send an EICAR test file to test the Core server detection.

An alert will be logged if no engines detect the EICAR file.

0 hour

0 disables the periodic check

Min: 1 hour

Backup ServerAdditional MetaDefender servers for the Kiosk to use if the primary is inaccessible (URL & API Key)Empty
MFT ServerMFT servers to be used among different workflows (URL & Admin API key)Empty
Printer SetupSelect the color of the printing output: Black & White or ColorBlack & White
Side marginsLeft and right margin length3

0 or greater

Recommended settings:

3 for a Zebra printer

200 for a Laser Jet

Display the MetaDefender URL in the session printoutThe URL of the MetaDefender server (Core or MFT) used for a session will be displayed on the printoutDisabled
Include page numbersInclude the page number on each printed pageEnabled
Custom introduction messageAdd a special header message to the first page of the printoutDisabled
Custom logoAdd a logo image to the first page of the printoutDisabledRecommended max image size of 400 x 400
Session Log > Destination Media

Enables a session text/PDF log to be created at the end of a session on the source media.

This will not apply to read-only media such as discs or USBs that are not writable.

Disabled

If enabled, the log will be saved to the root of the source media

Session Log > Destination Media

Enables a session text/PDF log to be created at the end of a session on the destination media.

This will not apply to read-only media such as discs or USBs that are not writable.

Disabled

If enabled, the log will be saved to the root of the destination media

Session Log > Directory PathEnables a session text/PDF log to be created at the end of a session in a specified location (local or network share)

Enabled

Logging directory: <kiosk install dir>\Client\Log

Save as Text File / Save as PDFSpecifies whether the session log will be a text or PDF fileText file
Display the MetaDefender URL in the session logThe URL of the MetaDefender server (Core or MFT) used for a session will be displayed in the log fileDisabled
Wipe MethodSpecifies which wipe options to display to the userAll wipe methods shown0,1,3,7 pass wipe
Exit passwordRequire password when terminating the Kiosk UI (ALT+S)Disabled
Kiosk Administrator's credentialsRequire AD Management Console Admin credentials to close the Kiosk UIDisabled
WatchdogCustom action watchdog that will run when the Kiosk UI is unexpectedly terminatedRestart Windows

Options:

Do nothing

Restart MetaDefender Kiosk

Log out of Windows

Lock Windows

Restart Windows

Export Session HistoryEnables auto export of session history (in CSV)Disabled
Export File HistoryEnables auto export of files history (in CSV)Disabled
FrequencyInterval between history exports1 hour

Min: 1 hour

Max: 365 Days

Export PathDirectory where the history will be exported to(Blank - <kiosk install dir>\Client\Log)
Country of OriginCOO engine detects the country an exe\dll binary originated from and marks the binary as blocked if the country is configured to be forbiddenDisabled
Image MediaEnables an image of the inserted media to be taken with the FTK Imager configuredDisabled
FTK Imager PathThe full path to the FTK Imager executable that handles imaging the media (ftkimager.exe)(Blank)
Image TypeThe image type FTK will outputRAW/DD
Fragment SizeThe size of chunks the image will be separated into1 GB

0 disables fragmenting the image

Min: 1

Max: 1024

(Min\Max per unit: KB - TB)

Compression LevelThe compression applied to the image0

Min: 0 (no compression)

Max: 9 (best compression)

Encrypt with password

Enables the image to be encrypted with a password.

The password is the name of the user logged in to the session and the id of the session: "<sessionID><username>"

Disabled
Encryption certificate path

The full path to a X.509 certificate to encrypt the image with.

Supported certificate formats:

  • PKCS#12 / PFX (*.p12, *.pfx)
  • PEM (*.pem)
  • Stand-alone public key only (*.cer, *.crt, *.der)
(Blank)
MFT ServerMFT entry to upload the image to(Blank)
DirectoryDirectory to upload the image to(Blank)

Advanced Configuration

Configuration SettingDescriptionDefault ValueRange
Max number of parallel scansMaximum amount of concurrent file processing requests Kiosk will make to a MetaDefender server200 or greater
Max number of retries when MetaDefender Core is too busyMaximum amount of retries that Kiosk will attempt on a file when the Core server notifies that it is too busy to handle new requests. Once the maximum amount of retries is reached for a file, the session will be canceled.0

0 for infinite

100 or greater

Boot sector processing

Allows processing of the first 512 bytes of an input media's partitions\disks.

When enabled, these boot sector files can be selected during browse or are automatically included when 'Process All' is selected.

Boot sector files cannot be included in file handling operations at the end of a session.

Enabled
Display warning for network errorsDisplay a warning to the user regarding network issues with the Core server while files are being processedEnabled
Allow decryption of encrypted archivesAllows you to input passwords when encrypted archives are detectedEnabled
Allow user to skip entering a password for McAfee Encrypted USBIn the case that a McAfee encrypted drive is set to unlock via other means instead of a password, a user can skip entering a passwordDisabled
Skip processing locked system filesEnables skipping of system files on media that Core cannot access and will typically result in a failed scanDisabled
Continue processing media with inaccessible contentAction to take when media has deeply nested directories that Kiosk cannot accessDisabled
Mount and scan Virtual Hard DisksAllow processing of the contents within an VHD\VHDX fileDisabled
  • Scan original Virtual Hard Disks
Enables sending the entire VHD\VHDX file to MetaDefender after all contents have been processedEnabled
Mount and scan Virtual Machines

Allow processing of the contents within a VMDK file

Only VMDK with Windows file systems are currently supported.

Disabled
  • Scan original Virtual Machines
Enables sending the entire VMDK file to MetaDefender after all contents have been processedEnabled
Mount and scan Acronis disk backupsAllow processing of the contents within an Acronis disk backupDisabled
  • Scan original Acronis disk backups
Enables sending the entire Acronis disk backup to MetaDefender after all contents have been processedEnabled
Acronis Executable PathThe full path to the Acronis executable that handles mounting the disk backup (acrocmd.exe)(Blank)
Heuristic File Type DetectionKiosk will heuristically group similar file type extensions for reportingDisabled
NTFS alternate data stream detection

Kiosk will display a warning in a file's details in both the result UI and reports if alternate data streams are detected in the file.

Alternate data streams will not be scanned - they will be ignored.

Disabled
Eclypt Management Application PathThe full path to the Eclypt Management Application that handles unlocking the Viasat drives (ema-ui.exe)(Blank)
Choose File Scanning Option (Kiosk 4.7.2 or newer)

Available options:

  • Select files: User can select files for processing
  • Process all files: User has to process all files in the media
  • Select or process all files: User can select between ‘Select files’ or ‘Processing all files’ options
  • Disable file processing: Kiosk does not process files
Select or process all files
User Interface TimeoutThe Kiosk UI will automatically switch back to the idle screen if there is no user action within a specified time on the final screens of the session.5 minutes

Min: 60 seconds

Max: 20160 minutes (2 weeks)

Display disclaimer screenDisplay the disclaimer screen to a user when a new session is startedEnabled
Display scan estimation timeDisplay the scan estimation time to a user when a scan session is processingEnabled
Allow user to browse for filesAllow user to select files before processing mediaEnabled
Allow user to process all filesAllow user to select to process the entire mediaEnabled
Alert user if MetaDefender Core license is close to expirationAlerts you on the Kiosk idle screen if the Core license is close to expirationDisabled
Alert user if MetaDefender Kiosk license is close to expirationAlert you on the Kiosk idle screen if the Kiosk license is close to expirationDisabled
Reboot at end of sessionSpecifies if the system should reboot after a session is completed or canceled. Exiting the Kiosk UI (ALT+S) during the session is not part of this option.Disabled
Allow user to select languagesAllow user to select which language the Kiosk UI's text will be displayed as. If this setting is disabled, the default language selected will be locked in.Enabled
Available KeyboardsThe keyboards allowed for users to select within the on-screen Kiosk keyboardAll keyboards enabled
Choose LanguageThe default language to be used for the UIEnglish
Multiple PartitionsSelects the method for processing files on partitionsProcess files on all accessible partitions
Parallel File Copy Threshold

Enhance performance by maximizing the number of concurrent files copied to the secondary location.

This setting applies to all types of secondary locations including Directory, User media, and MFT Server.

1

Default value is recommended for copying to MFT.

Min: 1

Max: 100

Boot Hardening - [Enable] [Disable]Enables/Disables the process that causes the taskbar on the desktop not to load when Windows is logged in to run Kiosk, thereby disallowing any PC functionality until the Kiosk starts.Disabled
Anti-tamper Hardening - [Enable] [Disable]

Enables/Disables security enhancement to prevent escaping the Kiosk UI while running.

Your system needs to be restarted to finish the changes.

Disabled
Active Keyboard Filter

Configure the keyboard filter to disable access certain key on the keyboard.

Only available if Anti-tamper Hardening is enabled.

Enabled
HostIP or DNS of SMTP server127.0.0.1
PortPort of the SMTP server25
Enable SSLEnable the use of SSLDisabled
UsernameUsername to authenticate to the SMTP server(Blank)
PasswordPassword to authenticate to the SMTP server(Blank)
Email TemplateTemplate for customizing logos, colors, and font sizes for a workflow's email configuration
Enable (Pop Up Detection)Enables Kiosk to detect any windows / pop ups open on the systemDisabled
Time Open ThresholdThreshold, in minutes, for a pop up to be open to trigger notification5 minutes

Min: 1 minute

Max: 60 minutes

Notification ActionAction to be taken when a pop up exceeds the time open thresholdDisplay warning
Process AllowlistIgnore pop ups from the processes listed(Blank)
File Integrity MonitorEnables the File Integrity Monitor, which will shut Kiosk down if any unauthorized changes are made in the Kiosk install directoryKiosk: disabled
ServerFile Integrity Monitor server locationKiosk: (blank)
PortPort to connect to the File Integrity Monitor serverKiosk: 0
UsernameUser name to log into File Integrity Monitor serverKiosk: (blank)
PasswordPassword to log into File Integrity Monitor serverKiosk: (blank)
Verify SSL CertificatesEnables verification of SSL certificates when connecting to Core\MFT via HTTPSEnabled
Add CA CertAdd any self-signed or specialized certificates used for Kiosk to successfully verify(blank)
Log Retention - Application LogSpecifies the length that Application Log entries will exist before being automatically deleted.NeverNever - 12 months
Log Retention - Session History

Specifies the length that Session History entries will exist before being automatically deleted.

File history associated with the expired session history will also be deleted.

NeverNever - 12 months
Log Retention - Service log file size limitSpecifies the size that Service log file will exists before being automatically deleted.500MBMin: 25MB Max: 500MB
Size Summary - DisplayDisplays the total files and size of selected files\folders when browsing for files.Disabled
Size Summary - Max size to stop calculating

Kiosk stops calculating the selected files and folders if the accumulated size exceeds this threshold value.

This prevents users from waiting a long time when the total size is large.

2 MB

Min: 1 MB

Max: 1024 GB

Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard