What are the key advantages of Kaspersky Anti Targeted Attack Platform Advanced?
Central console – One on-premises web console for all sensors.
Network detection – IDS analysis of mirrored network traffic copies.
Advanced sandbox – Detonates suspicious files in isolated virtual environments.
Threat intelligence – Alerts enriched and mapped to MITRE ATT&CK.
Gateway response – Automated blocking through ICAP proxy integration.
Important note – No antivirus, patching or encryption is included.
Download: Kaspersky Anti Targeted Attack Platform
Network traffic analysis – IDS rules, TLS fingerprinting and URL reputation on mirrored traffic.
Advanced Sandbox – Detonates suspicious objects from web, mail and endpoint sources.
Central web console – Single on-premises interface for alerts, investigation and response.
Threat intelligence enrichment – Kaspersky Security Network data mapped to MITRE ATT&CK techniques.
Gateway-level response – ICAP integration blocks objects at proxy and mail gateway.
Important – No antivirus, patch management, encryption or mobile coverage included.
Kaspersky Anti Targeted Attack Platform is an on-premises anti-APT solution that combines network detection and response with an integrated sandbox, operated from one central web console on your own physical or virtual servers. Kaspersky previously marketed the solution as the KATA Platform bundled with Kaspersky EDR Expert; that endpoint line is now sold separately as Kaspersky Next EDR Expert.
Full network visibility – IDS detection on mirrored traffic without endpoint agents installed.
Isolated file detonation – Sandbox verdicts without exposing production systems to samples.
Alert prioritisation – Automated scoring reduces manual triage work for analysts.
Native Kaspersky integration – Works with Secure Mail Gateway and Web Traffic Security.
Local data processing – Runs on your own physical or virtual servers.
Alert-linked packet capture – PCAP attached to IDS alerts documents what actually happened.
This platform assumes someone reads network alerts and acts on them. Kaspersky positions it for large enterprises with a SOC or a dedicated information security team, and for mid-sized organisations that cannot use cloud-based analysis. A company without in-house security staff will generate alerts nobody works through.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rare | By sector | By sector |
| NIS 2 in the European Union | ✕ | By sector | ✓ |
| Security questionnaire from large customers | Partial | ✓ | ✓ |
| Traffic mirroring and analyst capacity available | ✕ | Limited | ✓ |
| This product fits | ✕ | Limited | ✓ |
The reporting obligation under the revised Information Security Act applies to operators of critical infrastructure, not to every Swiss company, and has been in force since 1 April 2025. Affected organisations must submit an initial report to the Federal Office for Cybersecurity (BACS) within 24 hours of discovering a cyberattack, followed by a complete report within 14 days. The platform supports the discovery step directly: IDS alerts, sandbox verdicts and the packet capture stored with each alert give you a timestamped record of what was seen on the wire, which is the raw material for the 24-hour report and for the detailed follow-up. It does not detect what it cannot see, so segments without traffic mirroring and endpoints without a Kaspersky agent stay outside its view, and it does not cover the organisational side at all: no incident response process, no defined reporting workflow, no named responsible person, no submission to BACS. It also does not replace endpoint protection, backup or access control, which are the measures that determine whether an incident is contained in the first place. This description is not legal advice; whether your organisation is subject to the reporting obligation should be clarified with your own legal counsel.
No product makes a company compliant with the NIS 2 Directive, because the directive addresses the organisation and its risk management, not individual software. NIS 2 requires essential and important entities to put in place measures across defined categories: risk analysis and information system security policies, incident handling, business continuity and crisis management, supply chain security, security in network and information system acquisition and maintenance, procedures to assess the effectiveness of measures, cyber hygiene and training, cryptography, human resources security and access control, and multi-factor authentication. This platform contributes to two of them in a substantive way. It supports incident handling by detecting network-level indicators such as command-and-control traffic, lateral movement and data exfiltration, and it supports the assessment of effectiveness by producing alert data that shows whether monitoring is actually working. The remaining categories are not addressed: it provides no cryptography, no multi-factor authentication, no backup or continuity function, no access control, no vulnerability or patch management, and no training component. Supply chain security is a particular point to think through here, because the vendor question described below is itself part of that category.
Two authority actions concerning the vendor are verified and still in force. The United States Department of Commerce, through its Bureau of Industry and Security, issued a Final Determination on 20 June 2024 that prohibits Kaspersky from entering into new transactions with US persons from 20 July 2024, and from providing signature and codebase updates or operating the Kaspersky Security Network for US persons from 29 September 2024. Germany's Federal Office for Information Security has warned against the use of Kaspersky antivirus software since 15 March 2022; that warning remains published and, following the German implementation act that took effect on 6 December 2025, is now issued under Section 13 of the BSI Act. Kaspersky rejects the German warning as unjustified and states that it was not based on a technical analysis of its software, pointing to its Global Transparency Initiative, under which threat-related data from European users has been processed in two data centres in Zurich since November 2018 and source code can be reviewed at its transparency centres. Both authority actions concern trust in the vendor and supply chain risk rather than published detection performance, and neither authority has stated that the detection technology itself fails. In practice this matters most to three groups: public sector bodies and their suppliers, companies whose large customers impose vendor-origin requirements through contracts or questionnaires, and any group with US entities or US persons in scope. For a private Swiss or EU company with no such requirements, this is a decision to document rather than an obstacle.
Yes, for the detection and monitoring block, and not much beyond it. It answers questions on network security monitoring, intrusion detection, malware analysis capability, threat intelligence use, security event logging, and whether detected incidents can be investigated and responded to centrally. Mapping to MITRE ATT&CK is often accepted as evidence for the question about detection coverage frameworks. It answers none of the following: endpoint protection deployment and coverage rate, patch and vulnerability management, encryption of data at rest and in transit, multi-factor authentication, backup and recovery testing, identity and access management, asset inventory completeness, and security awareness training. It also does not answer questions about vendor origin, sanctions exposure or supply chain restrictions, which increasingly appear in questionnaires from large customers and public sector clients, and where the assessments described above are the relevant input. To close the technical gaps, the cheaper route is usually to stay inside the same family: Kaspersky Endpoint Security covers the endpoint protection and encryption management items, and moving to the KATA Ultra tier adds the Expert EDR and native XDR functionality that answers the endpoint detection questions, rather than adding a second vendor and a second console.
The single decisive difference is that only KATA Ultra includes Expert EDR capabilities and native XDR functionality; the other two tiers are network-side only. The second difference is the depth of network analysis: the base KATA tier detects on north-south traffic with IDS rules, TLS fingerprinting and URL reputation, while KATA NDR Enhanced adds deep packet inspection, east-west detection, the network map and inventory module, anomaly and shadow IT detection, and stored raw traffic for retrospective analysis. The Advanced Sandbox, threat intelligence enrichment and ICAP gateway response are present in all three tiers. Which tier a retail listing labelled Advanced corresponds to is not published by Kaspersky, so confirm the functional scope before ordering.
| Function | KATA | KATA NDR Enhanced | KATA Ultra |
|---|---|---|---|
| Advanced Sandbox | ✓ | ✓ | ✓ |
| IDS north-south, TLS fingerprinting, URL reputation | ✓ | ✓ | ✓ |
| Gateway response and ICAP blocking | ✓ | ✓ | ✓ |
| Deep packet inspection and IDS east-west | ✕ | ✓ | ✓ |
| Network map, session table, inventory | ✕ | ✓ | ✓ |
| Raw traffic storage and retrospective analysis | ✕ | ✓ | ✓ |
| Anomaly and shadow IT detection | ✕ | ✓ | ✓ |
| Expert EDR and native XDR functionality | ✕ | ✕ | ✓ |
The most important regional point: this vendor's cybersecurity and antivirus products cannot be sold to or updated for US persons, which affects any group with a US entity in scope, and Kaspersky Security Network does not operate on US systems. The second point is scope. This is a detection platform, not endpoint protection, so it needs Kaspersky Endpoint Security on the hosts and Kaspersky Security Center version 14.2 or higher to deliver endpoint telemetry, and the EDR (KATA) component cannot run on the same endpoint as EDR Optimum or EDR Expert. Endpoint monitoring covers Windows and Linux; macOS and mobile devices are outside the telemetry scope entirely, and patch management and encryption are not part of the product at any tier. Deployment is on-premises on your own physical or virtual servers, which means you need port mirroring or a network tap on the segments you want to see, plus staff to size and maintain the sensor and central node servers. Finally, because Advanced is a retail label rather than an official Kaspersky tier name, confirm with your supplier which of the three functional tiers the listing actually covers before ordering.
No. It analyses network traffic and detonates suspicious objects, but it does not protect endpoints. Kaspersky Endpoint Security remains required on hosts, and its File Threat Protection, Behavior Detection and Host Intrusion Prevention components are prerequisites for the KATA agent functionality to work at all.
Alerts, traffic metadata and sandbox results stay on your own servers, because the platform is deployed on-premises. Reputation lookups sent to Kaspersky Security Network are a separate matter: threat-related data from European users has been processed in two data centres in Zurich since November 2018 under the vendor's Global Transparency Initiative.
Yes. The platform provides native integration with SIEM systems, including Kaspersky SIEM and third-party tools, and supports ICAP and an API for object scanning, alert forwarding and response actions from external systems. This matters if your SOC already correlates in a central tool and does not want a second console as the primary workspace.