Home Solutions Kaspersky
Endpoint · EDR · APT Defense · Authorized partner: CYBER BOOST
Kaspersky logo

Start with antivirus,
grow into mature APT defense.

Kaspersky has 27 years of threat research behind it. KESB protects endpoints, and EDR Optimum/Expert helps you investigate attacks. KATA and Sandbox catch targeted APT attacks, and the MDR service connects the Kaspersky SOC to your systems. CYBER BOOST supplies, licenses and supports the whole stack.

Threat Intelligence Network
live
K
400M
KSN sensors
270+
APT campaigns analyzed
200+
countries
An illustration of the Threat Intelligence Network: Kaspersky’s global telemetry network.
27 years
of cyberthreat research; GReAT uncovered Stuxnet, Equation, Carbanak and Lazarus.
100+
independent AV-TEST and AV-Comparatives tests, with Kaspersky a leader in detection.
220,000
organizations are protected by Kaspersky products in 200+ countries.
EAL2+
Common Criteria certification; SOC 2 Type II, ISO 27001.
Product map

Build your Kaspersky stack
as your security matures.

You can start with basic KESB Select, then add EDR Optimum and Sandbox. The last step is KATA for targeted attacks and the MDR service on top of the whole stack.

Level 1 · Foundation
Endpoint Protection (EPP)
Basic protection
KESB SelectEndpoint Security for BusinessAntivirus, exploit protection, application, device and web control.
KESB Advanced+ EncryptionFull-disk + file-level encryption, patch management, mobile protection.
KESB Total+ Mail / Web GatewayProtection for Exchange/IIS mail, a web gateway, collaboration protection.
KES CloudA SaaS option for SMBsThe same KESB, managed from the browser, for teams with up to 250 workstations.
Level 2 · Detection & Response
EDR and Sandbox
SOC starter pack
EDR OptimumEDR for mid-size businessesAttack chain visualization, manual remediation, IoC search, simple integration with KSC.
EDR ExpertEnterprise EDRTelemetry, threat hunting, retroscan, YARA, integration with TIP and KATA.
SandboxA local on-prem sandboxA hardware and software sandbox for suspicious files, isolated from the cloud.
Level 3 · APT Defense
Targeted attacks, threat intelligence
Mature SOC
KATAAnti Targeted Attack PlatformNetwork sensors + email + Sandbox + EDR correlation to detect APT attacks.
TIPThreat Intelligence PortalAPT reports, IOC feeds, context on domains/hashes, with a financial and ICS focus.
MDRManaged Detection & ResponseThe Kaspersky SOC watches your stack 24/7; Optimum and Expert tiers.
Level 4 · Industry / Specialized
Specific use cases
OT · Mobile · Embedded
KICSIndustrial CyberSecurityProtection for the OT/ICS segment: Nodes for ICS workstations and Networks for fieldbus traffic.
KSMGSecurity for Mail GatewayAnti-spam, anti-phishing, DMARC and BEC protection for Linux gateways.
KSVSecurity for VirtualizationA light agent for VMware, Hyper-V and Citrix; protection for VDI environments without overloading the hypervisor.
KUMAUnified Monitoring & AnalysisKaspersky’s own SIEM: collection, normalization, correlation, SOAR playbooks.
KESB · tier comparison

Endpoint Security for Business - Select / Advanced / Total.

Capability Select
Basic AV for business
Advanced
+ Encryption / Patch
Total
+ Mail / Web Gateway
Anti-malware, HIPS, Exploit Prevention✓✓✓
Application / Device / Web Control✓✓✓
Kaspersky Security Center (KSC)✓✓✓
Endpoint Encryption (FDE + File-level)-✓✓
Patch Management + OS Provisioning-✓✓
Vulnerability Assessment-✓✓
Security for Mail Server (Exchange, Linux Mail)--✓
Security for Internet Gateway (Squid, ISA)--✓
Security for Collaboration (SharePoint)--✓
You can add EDR Optimum/Expert, Sandbox or KATA to any tier with a separate license.
KATA + EDR + Sandbox

How Kaspersky catches an APT in 5 steps.

KATA links network sensors, the sandbox and EDR agents into one event graph. A targeted attack doesn’t get through, even if initial access succeeded.

01
Telemetry collection
KATA Sensor mirrors network traffic and email, and EDR agents send endpoint events.
02
Sandbox analysis
Suspicious files are detonated in Kaspersky Sandbox, producing a behavioral snapshot in minutes.
03
Correlation
KATA merges network, email, sandbox and endpoint events into a single kill chain.
04
Threat Intelligence
Attribution through TIP: which group the TTPs belong to and which IoCs from APT campaigns match.
05
Response
EDR isolates the host, KSC rolls back changes and a KUMA playbook blocks the attack at the perimeter.
Network Sensor
SPAN / TAP traffic

Analysis of DNS, HTTP, SMTP and SMB; detection of C2 communications and network anomalies.

Mail Sensor
Email channel

Analysis of attachments and URLs before delivery; protection against spear phishing and BEC.

Endpoint Sensor (EDR)
Processes, registry, artifacts

Deep telemetry on processes and changes; YARA, IoC search, retro-scan.

GReAT · research-driven protection

Protection written by the same people who catch APTs in the wild.

The Global Research & Analysis Team has 40+ researchers in 17 countries. GReAT’s findings go straight into product detections and Threat Intelligence Portal feeds.

  • Stuxnet (2010) - analysis of the worm aimed at Iranian centrifuges.
  • Equation Group (2015) - reverse engineering of a firmware implant.
  • Carbanak (2014–18) - investigation of attacks that stole $1B from banks.
  • Lazarus (2017→) - ongoing tracking of the North Korean group.
  • Operation Triangulation (2023) - a zero-click iMessage exploit.
Securelist · the latest APT reports
What GReAT is writing right now
APT
SideWinder · a campaign against government bodies in Central Asia
Spear phishing with office documents in targeted campaigns.
Crime
FakeUpdates / SocGholish · loader-as-a-service
JavaScript injections on legitimate websites, drive-by ransomware.
ICS
Attacks on the energy sector · Q1 overview
Trends in the OT/ICS segment and incident statistics by region.
GReAT reports are available in the Kaspersky Threat Intelligence Portal to customers with an active TIP license.
Industries and use cases

Where CYBER BOOST deploys Kaspersky.

Banks and fintech

Protecting core banking systems, ATM networks and traders’ workstations. KATA bundled with anti-fraud tools, and real attacker attribution through GReAT.

Public sector

On-prem KSC and KATA in isolated segments; certifications ready for a regulator’s audit.

Energy and oil & gas

KICS for Nodes and Networks protect SCADA, MES and operator workstations. Air-gapped updates.

Telecom and IT

Protecting billing and BSS servers, EDR Expert for the SOC, MDR for night shifts.

Healthcare

Protecting hospital information systems and medical equipment, fine-tuning HIPS for legacy software, patch management.

Holding companies and groups

A hierarchical KSC console, delegation of rights to subsidiaries, a single license.

CYBER BOOST × Kaspersky

A reliable Kaspersky partner for the whole stack.

We supply KESB, EDR (Optimum/Expert), Sandbox, KATA, TIP, MDR, KICS and KUMA. Our local engineers are Kaspersky-certified and have experience migrating from old antivirus products and integrating with SIEM.

14 days
typical deployment of KESB + KSC on 1,000 endpoints.
RU/UZ
certified engineers; runbooks and training in two languages.
KCS+
Kaspersky Certified Specialist certifications for most products.
UZS / USD
contracts in both currencies and installment plans for government customers.
FAQ

Frequently asked questions about Kaspersky.

How is Kaspersky EDR Optimum different from EDR Expert?
EDR Optimum is a lightweight EDR for mid-size businesses: attack chain visualization, manual remediation and basic IoC search. EDR Expert is built for large enterprises: extended telemetry, threat hunting, retroscan, YARA rules and integration with the Threat Intelligence Portal and KATA.
What is KATA and do we need it?
KATA (Kaspersky Anti Targeted Attack Platform) is a network add-on that detects APT attacks. It analyzes email, network traffic and Sandbox results, and matches events with EDR data. It is for organizations that expect targeted attacks: banks, the public sector, critical infrastructure.
What does the Kaspersky MDR service include?
With Kaspersky MDR, the Kaspersky SOC handles the detections from your EDR/KATA 24/7. Its analysts investigate incidents, escalate confirmed attacks, advise on response and send quarterly reports. The Optimum or Expert tier is chosen to match how mature your SOC is.
Can Kaspersky be used in air-gapped networks?
Yes. Kaspersky Security Center (KSC) is deployed fully on-prem, and antivirus database updates are delivered through isolated repositories. For the OT segment there is a separate product, Kaspersky Industrial CyberSecurity (KICS) for Nodes and Networks.
What is GReAT and how does it relate to protection?
GReAT (Global Research & Analysis Team) is Kaspersky’s research unit, which uncovered Stuxnet, Equation, Carbanak, Lazarus and dozens of other targeted campaigns. GReAT’s findings go straight into product detections and Threat Intelligence Portal feeds.
Can we replace our current antivirus with Kaspersky without downtime?
Yes. In a “parallel phase”, KESB is installed next to your current antivirus and tested on live data for 1-2 weeks. Then the old product is removed centrally through KSC. No maintenance window is needed.
Request · Kaspersky

A KESB or EDR pilot in 2 weeks.

Tell us how many workstations and servers you have and which security tools you use now. We will send you a migration plan and pilot licenses.