What are the key advantages of Kaspersky Anti Targeted Attack Platform Extension Module Add-On?
Central console – All alerts handled in one on-premises interface.
Network detection – Analyses mirrored SPAN traffic for intrusion signs.
Integrated sandbox – Detonates suspicious files in isolated virtual machines.
Response actions – Isolate hosts and run tasks centrally.
SIEM export – Forwards alerts to your existing SIEM system.
Important note – Add-on only, an existing KATA deployment is required.
Network traffic analysis – Inspects mirrored SPAN, ERSPAN and RSPAN traffic for threats.
Integrated network sandbox – Detonates suspicious objects in isolated virtual machines.
Web and mail sensors – Receives copies via ICAP and SMTP or POP3.
Central Node console – One web interface for alerts, policies and roles.
SIEM and API export – Forwards alerts and accepts scan requests from external systems.
Important – EDR was removed from KATA 8.0 and is licensed separately.
This add-on extends an existing installation of Kaspersky Anti Targeted Attack, an on-premises anti-APT platform that is administered centrally through the Central Node web interface rather than device by device. Older Kaspersky material and distributor price lists describe the same offering as the KATA Platform with Kaspersky EDR Expert at its core, which is the name many buyers still search for.
Unmanaged devices visible – Detects hosts and services that carry no endpoint agent.
Faster alert triage – Alerts are mapped to MITRE ATT&CK for ranking.
East-west coverage – IDS rules cover internal traffic, not only the perimeter.
Own data location – Detection data stays on your own on-premises servers.
Multitenancy for providers – Service providers separate tenants within one distributed installation.
Raw traffic export – Stores traffic copies for analysis in external tools.
Kaspersky positions KATA for large enterprises with a security operations centre or a dedicated information security department, and for mid-sized organisations with regulatory or data-location constraints. The decisive question is not the number of devices but whether someone in the organisation works through network alerts every day.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | ✓ |
| NIS 2 in the European Union | Rarely | By sector | ✓ |
| Security questionnaire from large customers | Sometimes | ✓ | ✓ |
| Staff who work network alerts daily | ✕ | Partial | ✓ |
| This product fits | ✕ | Partial | ✓ |
In Switzerland the revised Information Security Act applies to operators of critical infrastructure, including energy and drinking water suppliers, transport companies, listed hospitals, data centres and cantonal and communal administrations; ordinary commercial businesses are not covered. Since 1 April 2025 these operators must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with 14 days to complete an incomplete first report. The product supports that deadline in a narrow but decisive way: network alerts with the affected hosts, sessions and MITRE ATT&CK context appear in the Central Node console, and copies of raw traffic can be stored, which is what the reporting form actually asks about. It does not cover the organisational side, because no software determines who is on call at 03:00, who is authorised to submit the report, or how the case is handed over to management, and the platform will not detect an attack that never touched monitored traffic or a host with an agent. This information is not legal advice, and the assessment of your own reporting obligations belongs with your legal advisers.
No product makes a company compliant with the NIS 2 Directive, because the directive addresses the organisation and its processes rather than any single tool. NIS 2 requires measures in categories such as risk analysis and security policies, incident handling, business continuity, supply chain security, security in acquisition and maintenance, procedures for assessing the effectiveness of measures, cyber hygiene and training, cryptography, access control and multi-factor authentication. This add-on contributes to incident handling and to the effectiveness assessment, since it supplies detection at network level, sandbox verdicts and exportable alert data that can be shown as evidence of monitoring. It contributes nothing to cryptography, access control, multi-factor authentication, training or supplier management, and it does not produce the written policies that auditors ask to see. Treat it as one technical control inside a wider programme, not as a NIS 2 answer.
Germany's Federal Office for Information Security (BSI) issued a warning against the use of Kaspersky antivirus software on 15 March 2022, arguing that a manufacturer in Russia could be compelled to act against its own customers. The warning remains in force in 2026, is now based on Section 13 of the amended BSI Act, and applies to Kaspersky's antivirus portfolio; the BSI states that it has made no assessment of the company's other products, and it has no legal power to issue a ban. In the United States the Department of Commerce went further and prohibited the sale of Kaspersky software and the delivery of updates to US customers in 2024. Kaspersky rejects the assessment, points to the relocation of data processing to its transparency centre in Zurich and to its holding structure outside Russia, and in January 2026 formally asked the BSI to withdraw the warning while reserving the right to legal steps. In Switzerland the position is different: BACS has issued no warning and no ban, has stated that no misuse of Kaspersky software has been reported to it, and warns only where it has substantiated technical evidence, which leaves the decision with each organisation. In practice this matters most if you hold public sector contracts, work in a regulated sector, or answer supplier questionnaires from German or US customers, where the vendor's country of origin is a scored question regardless of the technology.
Yes, for the detection and monitoring block, and not at all for several others. It answers questions on network monitoring and intrusion detection, on sandbox analysis of suspicious files, on retention and export of security events to a SIEM, on role-based access to the security console, and on the location of processing, since detection data stays on your own servers. It does not answer questions on endpoint protection, patch management, disk encryption, backup, identity and access management, mobile device management, or security awareness training, and it produces no policy documents, penetration test reports or certifications. It also does not answer the vendor-country question, which appears in a growing number of questionnaires from German and US customers. Where gaps remain, the cheaper route is usually to move up within the same family, for example to a tier that includes advanced NDR or to the separate on-premises EDR product, rather than to run two vendors and answer the same questionnaire twice.
The single decisive difference is how much of the network you can actually see and whether endpoint telemetry is included. All three tiers contain the network sandbox and the Central Node console; the base tier provides essential NDR, while NDR Enhanced adds the advanced capabilities such as the network map, the session table and intrusion detection across internal east-west traffic. KATA Ultra is the only tier that has historically included EDR. Note that Kaspersky has removed the EDR functional block from KATA version 8.0, where it becomes the separate on-premises product KEDR Expert 8.0, so confirm the tier and version before you plan an endpoint rollout on top of it.
| Capability | KATA | KATA NDR Enhanced | KATA Ultra |
|---|---|---|---|
| Network sandbox | ✓ | ✓ | ✓ |
| NDR scope | Essential | Advanced | Advanced |
| Central Node console | ✓ | ✓ | ✓ |
| EDR capabilities | ✕ | ✕ | Until 8.0 |
This is an add-on and does nothing on its own: it requires an existing Kaspersky Anti Targeted Attack installation, and the tier of that installation determines what the extension actually unlocks. Kaspersky sells the module as a European Edition, and Kaspersky products cannot be purchased or updated in the United States following the 2024 Commerce Department prohibition, which matters if your group has US entities or US-based subsidiaries in scope. The most expensive surprise in practice is the endpoint side: the EDR functional block has been removed from KATA 8.0 and continues as the separate on-premises product KEDR Expert 8.0, so an upgrade deletes existing EDR data and a fresh licence is needed for endpoint detection. KATA is also not an endpoint protection platform and does not replace antivirus, patch management or encryption on workstations and servers. Finally, the platform depends on being fed: without mirrored traffic from the right switches, an ICAP connection to the proxy and a mail sensor, large parts of the detection logic simply have nothing to analyse, and that network work is usually the longest item in the rollout plan.
Yes for the network side. Traffic analysis, sandbox verdicts, URL reputation checks and the detection of unmanaged or shadow IT devices all work from mirrored traffic alone. An agent based on Kaspersky Endpoint Security is only required for endpoint telemetry and for actions on a host, such as network isolation.
Detection data is processed and stored on your own Central Node servers on premises, which is one of the main reasons organisations with data location constraints choose this platform. Reputation lookups use the Kaspersky Security Network cloud; in isolated or air-gapped networks the private variant, Kaspersky Private Security Network, is used instead so that no request leaves the perimeter.