What are the core benefits of Kaspersky Anti Targeted Attack Platform Enterprise?
Central console – on-premises web console, no cloud dependency.
Network detection – IDS and traffic analysis across mirrored traffic.
Advanced sandbox – detonates suspicious objects in isolated virtual machines.
Guided response – gateway-level blocking through ICAP integration.
SIEM export – alerts published over Syslog and REST API.
Important note – endpoint protection and EDR are not included.
Download: Kaspersky Anti Targeted Attack Platform
Network traffic analysis – Monitors mirrored SPAN traffic for signs of intrusion using IDS rules.
Advanced sandbox – Detonates suspicious objects in isolated virtual machines and returns verdicts.
Central Node console – On-premises web interface for alerts, tasks and configuration.
Threat intelligence – Alerts enriched with KSN reputation data and MITRE ATT&CK mapping.
SIEM export – Alerts published over Syslog, plus a REST API integration.
Important – Endpoint protection agents and EDR are not part of KATA.
Kaspersky Anti Targeted Attack Platform Enterprise is an on-premises anti-APT solution that combines network detection and response with an integrated sandbox, operated from its own Central Node web console rather than a vendor-hosted cloud portal. Kaspersky now markets the product as Kaspersky Anti Targeted Attack (KATA), so older documentation and retail listings still carry the longer Platform name.
Encrypted traffic triage – TLS fingerprinting flags suspicious sessions without breaking encryption.
Gateway level blocking – ICAP integration stops flagged objects at the web proxy.
Alert evidence capture – A PCAP is stored with each intrusion detection alert.
SOC tool integration – Syslog and REST API feed your existing SIEM workflows.
Private reputation lookups – KPSN keeps file and URL reputation checks on premises.
Multi-tenant operation – Service providers separate customer data across distributed Central Nodes.
KATA is designed to be operated, not just installed: alerts have to be triaged, sandbox verdicts read, and network sessions investigated. Organisations without at least a part-time security analyst usually get more value from a managed service than from a self-run NDR platform.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | By sector |
| NIS 2 in the European Union | ✕ | By sector | By sector |
| Security questionnaire from large customers | ✓ | ✓ | ✓ |
| Staff available to triage network alerts | ✕ | Partial | ✓ |
| This product fits | ✕ | Limited | ✓ |
The Swiss reporting obligation does not apply to companies in general, but to the operators of critical infrastructure named in the revised Information Security Act (ISG): energy and water suppliers, transport companies, listed hospitals, cloud and data centre providers, and cantonal and municipal administrations. Since 1 April 2025 these organisations must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further 14 days to complete the report. KATA supports that deadline in one concrete way: every intrusion detection alert is timestamped and stored with its associated PCAP, and alerts can be pushed to a SIEM over Syslog, so the first report can be assembled from one evidence source instead of reconstructed from switch logs. What it does not do is decide anything for you – it does not file the report, does not judge whether an incident crosses the ISG threshold, and covers none of the organisational duties such as naming a responsible contact or documenting the escalation path. This text is not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal counsel.
No software product creates NIS 2 compliance, because the directive addresses management responsibility and process, not tooling. NIS 2 requires risk management measures across several categories: incident handling, business continuity and backup, supply chain security, vulnerability handling, cryptography, access control and multi-factor authentication, cyber hygiene and training, and policies to assess whether the measures actually work. KATA maps to one of these categories in depth – incident handling – through network monitoring, sandbox analysis, alert prioritisation and both automated and manual response actions, and its reporting output can serve as evidence when effectiveness is assessed. It contributes nothing to backup and continuity, vulnerability and patch management, encryption, identity and access control, multi-factor authentication, or staff training, all of which need separate products and processes. Whether an entity is in scope at all depends on the sector and size thresholds set by the directive itself.
In March 2022 the German Federal Office for Information Security (BSI) issued a public warning against the use of Kaspersky virus protection software and recommended replacing it with alternative products; the warning is now governed by Section 13 BSIG and the BSI confirmed in 2026 that it is maintained. In the United States, the Department of Commerce issued a Final Determination on 20 June 2024 prohibiting Kaspersky from supplying cybersecurity and anti-virus products to US persons; since 29 September 2024 resale, licensing and integration by US persons are prohibited and Kaspersky Security Network may not operate on US persons' systems. In Switzerland there is no comparable measure: BACS, formerly the NCSC, states that it does not issue recommendations on the use of individual products and warns only where it has confirmed technical evidence of a security risk, and it has reported none for Kaspersky. Kaspersky's own position is that these decisions are political rather than the result of a technical evaluation, and it points to its transparency programme, data processing for European customers in Zurich, source code and SBOM review, and external audits. On the technical side, Kaspersky was named a Leader in the SPARK Matrix Network Detection and Response report 2025. In practice this matters most to public sector tenders, suppliers to German public bodies, organisations with US entities or US-person staff, and companies whose large customers exclude software of Russian origin in their supply chain requirements; for private companies in Switzerland and the EU there is no legal restriction on purchase or use.
Partly, and the split is predictable. It answers the questions about network-level monitoring, intrusion detection coverage, malware analysis in an isolated environment, central log collection with Syslog and REST export to a SIEM, role-based access for security officers, and where data is processed – since KATA runs on your own servers, the data residency question can be answered with your own location rather than a vendor region. It answers none of the questions about endpoint protection deployment and coverage, patch and vulnerability management, disk encryption on notebooks, multi-factor authentication, backup and recovery testing, mobile device management, or security awareness training, and it does not by itself prove 24/7 coverage, because the platform is a tool your team operates during your team's hours. The cheaper route to closing those gaps is usually to stay inside the same family: the Ultra level adds endpoint EDR and native XDR scenarios, and Kaspersky MDR covers the round-the-clock monitoring question, whereas mixing vendors means answering integration and interoperability questions on top of the original ones. Expect one further question that no product feature answers: several questionnaires now ask directly about official authority warnings concerning your suppliers, and that answer has to be prepared in writing rather than technically.
The single decisive difference is endpoint coverage: EDR capability and native XDR scenarios exist only in the Ultra level, so the two lower levels see the network but not what happens inside the hosts. The second most costly difference in practice is east-west visibility – deep packet inspection, IDS rules for internal traffic, the network session table and the inventory module all start at NDR Enhanced, which is what you need to detect lateral movement rather than only perimeter crossings. Retrospective work also depends on the level: only NDR Enhanced and Ultra store raw traffic for later analysis, while the base level keeps a PCAP tied to each IDS alert. Sandboxing, threat intelligence enrichment and MITRE ATT&CK mapping are present at every level.
| Capability | KATA | KATA NDR Enhanced | KATA Ultra |
|---|---|---|---|
| Advanced sandbox | ✓ | ✓ | ✓ |
| IDS north-south traffic | ✓ | ✓ | ✓ |
| IDS east-west traffic and DPI | ✕ | ✓ | ✓ |
| Network map and inventory | ✕ | ✓ | ✓ |
| Raw traffic storage and retrospective analysis | Per alert | ✓ | ✓ |
| Shadow IT and anomaly detection | ✕ | ✓ | ✓ |
| Endpoint EDR and native XDR | ✕ | ✕ | ✓ |
| Sale and resale in the United States | Prohibited | Prohibited | Prohibited |
The most important regional restriction is the United States: since 29 September 2024, resale, licensing and integration of Kaspersky cybersecurity software by US persons is prohibited and Kaspersky Security Network may not run on US persons' systems, which matters for any Swiss or European group with US subsidiaries or US-person staff. The platform is on-premises only – there is no vendor-hosted cloud console, so you provide, run and maintain the Central Node, Sandbox and Sensor machines yourself, and the operating effort is a real part of the total cost. Endpoint protection is not included and is the follow-up purchase that surprises buyers most often: KATA analyses network traffic, while endpoint telemetry requires Kaspersky Endpoint Security agents, and full endpoint detection and response only exists in the Ultra level. There is no patch management, no encryption management and no mobile device coverage in this product at all. One naming point deserves a check before you order: the vendor currently publishes three levels named KATA, KATA NDR Enhanced and KATA Ultra, while retail packaging still uses older labels such as Standard and Enterprise, so confirm with the supplier which of the three capability sets your package actually covers.
Yes. Instead of the cloud-based Kaspersky Security Network, you can operate Kaspersky Private Security Network, which holds the file and URL reputation database on a server inside your own network. Sandbox verdicts can then be published to that local reputation database rather than leaving the environment.
Yes. A server running Kaspersky Secure Mail Gateway or Kaspersky Security for Linux Mail Server can be used as a mail sensor, and Kaspersky Web Traffic Security integrates on the web side, so mail and web objects reach the sandbox without a second network tap.
No. KATA is a platform your own analysts operate, and alerts are only acted on when someone is watching the console. Continuous monitoring by an external team is Kaspersky MDR, a separate service.