What are the core benefits of Kaspersky Anti Targeted Attack Platform Standard?
Central console – On-premises web console manages all sensors centrally.
Network detection – IDS analysis of mirrored north-south network traffic.
Advanced sandbox – Detonates suspicious files in isolated virtual environments.
Threat intelligence – Alerts enriched with MITRE ATT&CK mapping.
SIEM export – Publishes alerts via syslog to existing SIEM.
Important note – EDR and endpoint agents are not included.
Download: Kaspersky Anti Targeted Attack Platform
Central Node – Core server that stores verdicts and runs detection engines.
Network Sensor – Receives mirrored SPAN traffic and scans it with IDS rules.
Advanced Sandbox – Detonates suspicious objects in isolated virtual operating systems.
URL reputation analysis – Checks files and links against the Kaspersky Security Network.
Network guided response – Gateway-level blocking through ICAP integration with proxy servers.
Important – EDR, endpoint protection and patch management are not included.
Kaspersky Anti Targeted Attack Platform Standard is an on-premises anti-APT platform that analyses mirrored network traffic and detonates suspicious objects in a sandbox; Kaspersky now markets the line simply as Kaspersky Anti Targeted Attack, so older listings carrying the Platform suffix refer to the same family. Every component is administered from one self-hosted web console on the Central Node server, with no cloud tenant involved.
Sees unmanaged devices – Covers hosts where no endpoint agent can be installed.
No cloud dependency – Runs fully on-premises with data staying in-house.
Feeds existing SIEM – Publishes alerts over syslog and a REST API.
Mail sensor integration – Secure Mail Gateway can act as a network sensor.
Multitenancy for providers – Separates tenants across Primary and Secondary Central Nodes.
Documented alert trail – Timestamped alerts usable as evidence in incident reports.
The platform assumes someone reads the alerts. It fits organisations with a security team or an external SOC that already triages events daily; a company without that capacity will generate alerts nobody actions.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | ✓ |
| NIS 2 in the European Union | ✕ | By sector | ✓ |
| Security questionnaire from large customers | Sometimes | ✓ | ✓ |
| Analyst capacity to triage network alerts | ✕ | Limited | ✓ |
| This product fits | ✕ | Limited | ✓ |
Since 1 April 2025 the revised Information Security Act (ISG) obliges operators of critical infrastructure in Switzerland to report significant cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further 14 days to complete the report. The obligation covers sectors such as energy, water supply, healthcare, finance, telecommunications, transport and cantonal and municipal administrations rather than every company, and since 1 October 2025 a failure to report can be sanctioned with a fine of up to CHF 100,000. Within that 24-hour window the platform contributes the detection side: timestamped IDS alerts, sandbox verdicts and the packet capture attached to an alert give the reporting team an approximate attack start time, the affected internal addresses and an object hash. It does not file the report, does not decide whether an incident crosses the reporting threshold, and in this tier does not store raw traffic for retrospective analysis, so anything older than the current alert has to be reconstructed from other logs. This text is buyer information and not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal counsel.
No product creates NIS 2 compliance, because the directive obliges organisations and their management, not software vendors. NIS 2 requires categories of measures including risk analysis and security policies, incident handling, business continuity, supply chain security, security in acquisition and maintenance, procedures to assess the effectiveness of measures, cyber hygiene and training, cryptography, access control and asset management, and multi-factor authentication. This product maps to incident handling and to the detection part of network and information system security: it monitors mirrored traffic for intrusions, prioritises alerts and exports them by syslog so they can be correlated centrally. It contributes nothing to business continuity and backup, cryptography, access control, asset management or multi-factor authentication, and it does not cover endpoints unless a higher tier is licensed. Supply chain security is touched only indirectly, through visibility into traffic between your network and external connections.
On 20 June 2024 the United States Department of Commerce issued a Final Determination under its ICTS supply chain authority prohibiting Kaspersky from entering new agreements with US persons from 20 July 2024, and from 29 September 2024 also prohibiting anti-virus signature and codebase updates, operation of the Kaspersky Security Network in the United States, and the resale, licensing or integration of Kaspersky cybersecurity software by US persons. Germany's Federal Office for Information Security has warned against the use of Kaspersky anti-virus software since 15 March 2022; that warning is still published and has been issued under Section 13 BSIG since 6 December 2025. Both measures remain in force. Switzerland has taken no comparable step: BACS has stated that no internal directive or prohibition on Kaspersky products exists and that it issues warnings only where it holds confirmed technical evidence of a security risk. Kaspersky rejects the assessments, describes the German warning as not based on an objective technical analysis of its software, and points to its transparency centres and third-party audits. Recognition of the product itself is a separate matter from the political assessment: Kaspersky was named a Leader in the QKS Group SPARK Matrix for Network Detection and Response in 2025. In practice the restrictions bite for buyers with a US parent company, US federal contracts, or customers whose supplier requirements exclude vendors subject to a national warning; a Swiss or EU company without that exposure faces no legal barrier to purchase, but should expect the question in audits and supplier questionnaires.
Partly, and only on the network side. It answers directly whether network traffic is continuously monitored for intrusions, whether suspicious files are detonated in a sandbox before they reach users, whether alerts are timestamped and forwarded to a SIEM, and whether incident response has technical detection behind it. It answers none of the endpoint items — endpoint protection, EDR telemetry, device and application control, patch status, disk encryption, mobile device management — and nothing on backup, business continuity, identity or access management. In this tier it also cannot answer questions about retrospective traffic analysis or a complete network asset inventory, because raw traffic storage, the network session table and the inventory module belong to the NDR Enhanced tier. To close the endpoint gaps, moving up to KATA Ultra or adding Kaspersky Next EDR Expert from the same family is normally cheaper to run than pairing a network product from one vendor with an endpoint product from another, because the verdicts stay in a single console instead of being correlated by hand.
The decisive difference is where detection happens. The base tier inspects north-south traffic passing the sensor, NDR Enhanced adds east-west traffic, deep packet inspection, a network map and an inventory module, and Ultra adds endpoint detection and response on top. The base tier stores no raw traffic, so once an alert has aged out there is nothing left to re-examine; anomaly detection and shadow IT detection also start at NDR Enhanced. Native XDR scenarios, where network and endpoint verdicts correlate automatically, exist only in Ultra. Kaspersky's own documentation names the three tiers KATA, KATA NDR Enhanced and KATA Ultra, so confirm which of the three a retail listing covers before ordering.
| Capability | KATA (base) | NDR Enhanced | Ultra |
|---|---|---|---|
| Advanced sandboxing | ✓ | ✓ | ✓ |
| IDS on north-south traffic | ✓ | ✓ | ✓ |
| Gateway response via ICAP | ✓ | ✓ | ✓ |
| IDS on east-west traffic and DPI | ✕ | ✓ | ✓ |
| Raw traffic storage and retrospective analysis | ✕ | ✓ | ✓ |
| Network map and inventory | ✕ | ✓ | ✓ |
| Anomaly and shadow IT detection | ✕ | ✓ | ✓ |
| Endpoint detection and response | ✕ | ✕ | ✓ |
| Native XDR scenarios | ✕ | ✕ | ✓ |
The regional restriction here runs the opposite way to the usual case: the software cannot be sold, resold, licensed or integrated into products for US persons, so a Swiss or EU group with US subsidiaries cannot standardise on it across all sites. The platform only sees traffic that actually reaches the sensor, which means SPAN, ERSPAN or RSPAN mirroring has to be configured on the switches first, and encrypted traffic is inspected only where SSL certificate replacement is already running on the proxy. There is no cloud console: Central Node, Sensor and Sandbox run on your own servers or virtual machines, which helps with data residency but costs administrative time for teams that do not want to operate appliances. The follow-up purchase that comes up most often is endpoint coverage, because alerts regularly point at a host this tier can neither examine nor isolate. Missing anomaly detection, shadow IT detection and retrospective packet analysis are the other common reasons buyers move up a tier shortly after deployment.
Yes. Reputation lookups for files and URLs can be directed to Kaspersky Private Security Network (KPSN) instead of the public Kaspersky Security Network, which keeps the requests inside your own infrastructure. This is the usual setup for organisations that cannot send metadata to an external reputation service.
Yes. Kaspersky Secure Mail Gateway and Kaspersky Security for Linux Mail Server can be configured as mail sensors and forward copies of messages to the Central Node for scanning and sandboxing. Integration with a mail server over POP3 is also supported.