What are the key advantages of Kaspersky Anti Targeted Attack Platform EDR Agent Add-On?
Central management – Policies from Kaspersky Security Center, response from KATA console.
Platform requirement – Needs Anti Targeted Attack Platform already deployed.
Third-party compatible – Runs beside an existing non-Kaspersky endpoint protection platform.
Continuous telemetry – Tracks processes, network connections and file changes.
Response actions – Host isolation, execution prevention, quarantine and IOC scans.
Important note – No anti-malware protection; a separate EPP stays required.
EDR Agent configuration – Kaspersky Endpoint Security for Windows without protection components.
Endpoint telemetry – processes, open network connections and modified files, sent continuously.
KATA console management – run tasks, handle quarantined objects and view reports.
Response actions – network isolation, execution prevention rules by path or hash.
Hunting tasks – OpenIOC scans and YARA scans across connected hosts.
Important – no anti-malware, web or device control; separate EPP required.
Kaspersky Anti Targeted Attack Platform EDR Agent Add-On extends an existing Anti Targeted Attack Platform installation to Windows computers that are already protected by a third-party endpoint protection platform. Deployment and settings run through Kaspersky Security Center, while alerts, tasks and response actions are handled in the Anti Targeted Attack Platform console; on Kaspersky Endpoint Security 11.2.0 to 11.8.0 this role was filled by the separate Kaspersky Endpoint Agent.
No EPP replacement – keep your current antivirus vendor while adding Kaspersky detection.
One investigation view – endpoint telemetry joins network sensor data in one console.
Faster containment – isolate a suspect host without walking to the desk.
Retrospective hunting – rerun OpenIOC and YARA scans when new indicators arrive.
Staged rollout – deploy per group with existing Kaspersky Security Center tasks.
Evidence trail – alert and task history supports incident reports after attacks.
This add-on assumes an organisation that already runs the Anti Targeted Attack Platform and has people who read alerts. Telemetry without an analyst produces a data store, not security, which is what usually rules the product out at the small end.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | Often |
| NIS 2 in the European Union | Rarely | ✓ | ✓ |
| Security questionnaire from large customers | Occasional | ✓ | ✓ |
| Own analyst team to work the EDR telemetry | ✕ | Partial | ✓ |
| This product fits | ✕ | Partial | ✓ |
The Swiss reporting obligation applies to operators of critical infrastructure, not to every company. Since 1 April 2025 the revised Information Security Act requires those operators to report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with the full report following within 14 days. The hard part is the 24 hours, and this is where the add-on contributes: the Anti Targeted Attack Platform console holds the process, connection and file telemetry from the affected Windows host, so the initial report can state what was observed and when instead of describing a suspicion. What it does not cover is everything that decides whether the deadline is actually met, because the product files no report, does not judge whether an incident is reportable, and does not replace an on-call rota or a defined escalation path. Coverage also stops at Windows computers that carry the agent, so incidents on macOS, Linux, mobile or unmanaged devices will not appear in that timeline at all. This description is not legal advice, and whether your organisation is subject to the reporting obligation should be clarified with your own legal counsel.
No software product makes an organisation NIS 2 compliant, because the directive places duties on the organisation rather than on a tool. NIS 2 requires measures in risk analysis and security policies, incident handling, business continuity, supply chain security, security in acquisition and development, procedures to assess the effectiveness of measures, cyber hygiene and training, cryptography, access control and asset management, and multi-factor authentication. This add-on contributes to two of those areas: incident handling, by supplying the endpoint evidence a responder needs to reconstruct an attack, and the detection side of risk management, through isolation and execution prevention that contain a case while it is being worked. It contributes nothing to business continuity, supply chain security, secure development, training, cryptography, access control or multi-factor authentication, and it generates no policy documentation. Since the directive is transposed separately in each member state, the applicable deadlines and the competent authority depend on where your organisation is established.
In March 2022 the German Federal Office for Information Security (BSI) recommended replacing Kaspersky antivirus software, and when asked again in June 2024 the BSI confirmed that this recommendation still stood. In June 2024 the US Department of Commerce Bureau of Industry and Security issued a Final Determination prohibiting new sales of Kaspersky software in the United States from 20 July 2024 and, from 29 September 2024, prohibiting signature and codebase updates, operation of the Kaspersky Security Network in the US, and resale or integration of the software by third parties. Both measures remain in force. Kaspersky rejects the assessments as politically rather than technically motivated and has stated that it would pursue the legal options available to it. The Swiss position differs: the Federal Office for Cybersecurity (BACS) has issued neither a warning nor a ban, has stated that it warns only where it holds confirmed technical evidence of a security risk, and has said that no misuse of Kaspersky software has been reported in Switzerland, while Kaspersky products are no longer in use in the federal administration. Independent European test laboratories have continued to include Kaspersky products in their comparative tests. In practice this matters most if you sell into the United States, hold public-sector contracts in Germany, or answer supply chain requirements from customers who exclude vendors named in national security assessments; for other buyers it is a documented risk factor to weigh rather than an operational restriction.
Partly, and it is worth knowing which half. It answers the endpoint detection block directly: whether EDR telemetry is collected from endpoints, whether processes, network connections and file changes are recorded, whether a compromised host can be isolated, whether execution of specific files can be blocked by path or hash, and whether indicator-based searches using OpenIOC and YARA can be run retrospectively across the estate. It answers none of the items that usually sit in the same section, because it provides no anti-malware protection, no patch or vulnerability management, no disk or removable media encryption, no multi-factor authentication, no mobile device coverage, and no macOS or Linux endpoint coverage, since the agent configuration runs on Windows only. It also does not answer questions on round-the-clock monitoring, because the platform detects but does not staff a response team; the same agent configuration supports Kaspersky Managed Detection and Response, which is the route that closes that particular line. Where several of these gaps appear at once, adding components from the same Kaspersky line is usually cheaper to document than mixing vendors, because one console and one evidence trail are far easier to describe to an auditor than three.
The decisive difference is protection: the EDR Agent configuration deliberately ships without protection and control components, which is exactly what makes it installable next to a third-party endpoint protection platform. Both configurations send the same telemetry to the Anti Targeted Attack Platform and both accept the same response actions from its console. Choose the built-in agent when Kaspersky Endpoint Security is already the protection layer on that machine, and the EDR Agent configuration when another vendor holds that role and you only want detection and response on top.
| Capability | Built-in agent | EDR Agent |
|---|---|---|
| Anti-malware protection | ✓ | ✕ |
| Web, device and application control | ✓ | ✕ |
| Telemetry to the platform | ✓ | ✓ |
| Isolation and execution prevention | ✓ | ✓ |
| Runs beside a third-party EPP | ✕ | ✓ |
| Device status in Kaspersky Security Center | Normal | Critical by design |
The add-on has no standalone value: it requires an existing Kaspersky Anti Targeted Attack Platform, and the target computers must already sit under a Kaspersky Security Center console with Network Agent installed. The EDR Agent configuration runs on Windows only, so macOS and Linux machines in the same estate stay outside the telemetry and outside every response action. Because the protection components are absent by design, machines running the agent are displayed with Critical status in Kaspersky Security Center, which is expected and needs no action but does mean the KSC status view stops working as a quick health check for those devices. The usual follow-up purchase is therefore not more EDR but the layers around it, most often patch management or encryption. One regional restriction is decisive for some buyers: following the US Department of Commerce Final Determination, Kaspersky software cannot lawfully be sold, resold or updated in the United States, so this product is not an option for US sites or US subsidiaries.
Because the File Anti-Virus component is not present in this configuration, and Kaspersky Security Center reads its absence as a critical state. This is expected behaviour and requires no action, since protection on that machine is provided by the third-party endpoint protection platform.
Yes. The EDR Agent configuration also supports Kaspersky Managed Detection and Response, the Kaspersky Unified Monitoring and Analysis Platform (KUMA) from Kaspersky Endpoint Security 12.6 for Windows, and the NDR part of the Anti Targeted Attack Platform from version 12.7.