Kaspersky Anti-Targeted Attack Platform vs Microsoft Defender XDR comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Fortinet FortiEDR
Sponsored
Ranking in Endpoint Detection and Response (EDR)
12th
Average Rating
7.8
Number of Reviews
32
Ranking in other categories
No ranking in other categories
Kaspersky Anti-Targeted Att...
Ranking in Endpoint Detection and Response (EDR)
55th
Average Rating
6.6
Number of Reviews
5
Ranking in other categories
No ranking in other categories
Microsoft Defender XDR
Ranking in Endpoint Detection and Response (EDR)
7th
Average Rating
8.4
Number of Reviews
85
Ranking in other categories
Extended Detection and Response (XDR) (5th), Microsoft Security Suite (1st)
 

Mindshare comparison

As of June 2024, in the Endpoint Detection and Response (EDR) category, the mindshare of Fortinet FortiEDR is 7.4%, up from 4.6% compared to the previous year. The mindshare of Kaspersky Anti-Targeted Attack Platform is 0.2%, up from 0.1% compared to the previous year. The mindshare of Microsoft Defender XDR is 8.4%, up from 0.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Detection and Response (EDR)
Unique Categories:
No other categories found
No other categories found
Extended Detection and Response (XDR)
23.3%
Microsoft Security Suite
4.9%
 

Featured Reviews

SP
May 1, 2023
We saw time to value within two weeks of implementing the solution, which strengthened our use cases
We use FortiAI, FortiSIEM, and FortiEDR Fortinet helped us scale large-scale deals with clients because of its strong offerings. Fortinet is very straightforward to use. I have access to a lot of technical resources, and I have been able to use them effectively. Fortinet has helped free up around…
RR
Jun 29, 2023
Can identify abnormal activities on the endpoint, such as a user opening a malicious email attachment or a workstation downloading a payload
So many cyberattacks are still unknown, with no known signatures or attributes that allow you to identify them definitively. However, any kind of cyberattack leaves traces behind. For example, after some activities, attackers may be unable to delete all the clues they go through in the infrastructure. An EDR solution can identify abnormal activities on the endpoint, such as a user opening a malicious email attachment or a workstation downloading a payload. In most cases, antivirus software cannot detect these attacks, but EDR can. You can collect all necessary metadata from EDR, which can then be analyzed automatically by a data anti-barging site or manually by threat-hunting analysts.
Brian Mulambuzi - PeerSpot reviewer
May 14, 2024
Helps improve our visibility, our security posture, and defends against advanced threats
Microsoft Defender XDR provides a unified identity and access management platform. It does a good job with identity protection. Including identity and access management within Defender XDR is valuable because it streamlines our organization's security by consolidating multiple tools into one. This eliminates the need to manage and pay for separate solutions and licenses, simplifying our security posture. Microsoft Defender XDR has improved our visibility, making us more efficient by providing threat details and remediation steps as well as improving our security posture. It safeguards our organization by preventing advanced threats like ransomware and business email compromise, along with stopping lateral movement within our network that could enable attackers to spread and gain wider access. It includes the ability to stop attacks and adapt to evolving threats. This is an important feature for us. We have been enabled to discontinue using Microsoft Sentinel. Microsoft Defender XDR helps save costs through the licensing for businesses which is around $20 each and helps save time for our security team.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The stability is very good."
"This is stable and scalable."
"It is very easy to set up. I would rate my experience with the initial setup a ten out of ten, with ten being very easy to set up."
"Impressive detection capabilities"
"I like FortiClient EMS. FortiEDR has a lot of great features like lockdown mode, remote wipes, and encryption. I can set malware outbreak policies and controls for detecting abnormalities. You can also simulate phishing attacks."
"I get alerts when scripts are detected in the environment."
"The ease of deployment and configuration is valuable. It's very easy compared to other vendors like Sophos. Sophos' configuration is complex. Fortinet is a lot easier to understand. You don't need a lot of admin knowledge to do the configuration."
"Fortinet has helped free up around 20 percent of our staff's time to help us out."
"The solution is very easy to use. Its interface is very simple, and you can build IOC's indicators. You can use your rules to detect these attacks because you can leverage threat intelligence. Y"
"Kaspersky Anti-Targeted Attack Platform is stable and runs all the time."
"The email security feature is really good."
"The most valuable use is detailing metadata collection from the endpoint and network."
"I feel the anti-ransomware update is one of the tool's valuable features."
"The most valuable feature is the DLP because that's where we can have an added data protection layer and extend it not just to emails but to the documents that users are working on. We can make sure that sensitive data is tagged and flagged if unauthorized parties are using it."
"I like Defender XDR's automation capabilities. XDR isn't automated by default, but you can automate it to respond. If an attack is performed anywhere within the organization, you can isolate that instance from the network. This is what I can figure out for it. When integrated with Sentinel, you can set up playbooks to automate all the alerts gathered on Sentinel from different Microsoft solutions. Sentinel has a wider range of capabilities than XDR."
"We are able to consolidate licences and make use of many Microsoft products using this solution. If we have any Microsoft customers, we encourage them to use this solution for enterprise defence."
"Microsoft 365 Defender's most valuable feature is the ability to control the shadow IP."
"Microsoft 365 Defender is a stable solution."
"I have found the ability to delete unwanted threats beneficial."
"The most valuable features are spam filtering, attachment filtering, and antivirus protection."
"Scanning, vulnerability reporting, and the dashboard are the most valuable features."
 

Cons

"It takes about two business days for initial support, which is too slow in urgent situations."
"I haven't seen the use of AI in the solution."
"FortiEDR could add a separate scanning dashboard. In incident management, we prefer to remove the endpoint system from the environment and scan the system. We typically use Symantec for that, but if we want to use FortiEDR for that, then we need a scanning tab to clarify things."
"The solution should address emerging threats like SQL injection."
"Intelligence aspects need improvement"
"There's room for improvement in the quick response time and technical support for integration issues, especially when dealing with multiple vendors."
"Everything with Fortinet having to do with their cloud services. They need to invest more in their internal infrastructure that they are running in the cloud. One of the things I find with their cloud environment compared to others' is that they go cheap on the equipment. So it causes some performance degradation."
"The only minor concern is occasional interference with desired programs."
"The backup and recovery features of the product are not good."
"Kaspersky Anti-Targeted Attack Platform is not a good product. We had problems with endpoints and the solution did not detect it. We didn't get any alerts about the attack."
"The solution lacks cloud integrations."
"In some of the places I have come across, even though they use Kaspersky, the ransomware enters their system."
"The blind spot or gap in the platform is network analysis functionality."
"Correctly updated records are the most significant area for improvement. There have been times when we were notified of a required fix; we would carry out the fix and confirm it but still get the same notification a week later. This seems to be a delay in records being updated and leads to false reporting, which is something that needs to be fixed."
"There are other SIEM solutions that are easier to use, mainly based on the creation of rules, use cases, and groups."
"The data recovery and backup could be improved."
"Offboarding latency should be reduced. Even after a device has been successfully offboarded using a particular offboarding script, it still shows up as onboarded."
"The documentation on their website is somewhat outdated and doesn't show properly. I wanted to try a query in Microsoft Defender 365. When I opened the related documentation from the security blog on the Microsoft website, the figures were not showing. It was difficult to understand the article without having the figures. The figures were there in the article, but they were not getting loaded, which made the article obsolete."
"Defender's AI for identifying suspicious activity could be improved. Also, I do a lot of home updates. Maybe there is a way to set it up faster. For example, let's say that I want to automatically update seven computers, servers, etc. I wouldn't do it to a user, but maybe the server. I don't mind if the server restarts automatically."
"Improving scalability, especially for very large tenants, could be beneficial for Microsoft Defender XDR."
"There are still some components, such as vulnerability management within the vendor product, where improved integration would be beneficial."
 

Pricing and Cost Advice

"It is expensive and I would rate it 8 on the scale."
"Offered at a high price"
"The pricing is typical for enterprises and fairly priced."
"There are no issues with the pricing."
"Fortinet FortiEDR is available at a very competitive price compared to the other products in the market."
"The hardware costs about €100,000 and about €20,000 annually for access."
"The solution is not expensive."
"It's not cheap, but it's not expensive either."
"Kaspersky is one of the cheaper solutions."
"The solution has competitive pricing."
"Kaspersky Anti-Targeted Attack Platform is cheap."
"Understanding the subscription model has been a bit challenging, as every feature or requirement comes with an additional cost."
"The price could be better. Normally, the costs depend on the country you're located in for the license. When we were in the initial stage, we went with the E5 license they call premium standard. It cost us around $5.20 per month for four users."
"Its licensing and pricing are handled by someone else. My role is limited to incidents or issues with the portal, but you get what you pay for. It is worth the cost."
"I would like to have more security features in the lower licenses because not every customer is able to buy E5 licenses. The bundling isn't always easy for our customers to understand. Compared to other tools, it's a good price."
"I believe that the pricing of the licensing is fair."
"The solution is too expensive."
"While Microsoft Defender XDR carries a higher cost, its ease of use compared to Defender may justify the investment."
"Microsoft Defender XDR is expensive."
report
Use our free recommendation engine to learn which Endpoint Detection and Response (EDR) solutions are best for your needs.
787,779 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Government
8%
Manufacturing Company
8%
Financial Services Firm
8%
Educational Organization
48%
Computer Software Company
15%
Financial Services Firm
7%
Healthcare Company
4%
Computer Software Company
17%
Financial Services Firm
10%
Government
8%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What's the difference between Fortinet's FortiEDR and FortiClient?
I suggest Fortinet’s FortiEDR over FortiClient for several reasons. For starters, FortiEDR guarantees solid protectio...
What do you like most about Fortinet FortiEDR?
We have FortiEDR installed on all our systems. This protects them from any threats.
What is your experience regarding pricing and costs for Fortinet FortiEDR?
The pricing of the solution is on the high end compared to its offerings and capabilities.
What do you like most about Kaspersky Anti-Targeted Attack Platform?
The solution is very easy to use. Its interface is very simple, and you can build IOC's indicators. You can use your ...
What is your experience regarding pricing and costs for Kaspersky Anti-Targeted Attack Platform?
Its price is reasonable; it's neither very high nor very low, considering its capabilities.
What do you like most about Microsoft 365 Defender?
Microsoft Defender XDR provides strong identity protection with comprehensive insights into risky user behavior and p...
What is your experience regarding pricing and costs for Microsoft 365 Defender?
Microsoft Defender XDR is expensive, especially for the full suite functionality. However, when compared to buying mu...
What needs improvement with Microsoft 365 Defender?
Improving scalability, especially for very large tenants, could be beneficial for Microsoft Defender XDR. Additionall...
 

Also Known As

enSilo, FortiEDR
Kaspersky Anti Targeted Attack
Microsoft 365 Defender, Microsoft Threat Protection, MS 365 Defender
 

Overview

 

Sample Customers

Financial, Healthcare, Legal, Technology, Enterprise, Manufacturing ... 
Republic of Serbia, Goods.ru, Tael, Insolar
Accenture, Deloitte, ExxonMobil, General Electric, IBM, Johnson & Johnson and many others.
Find out what your peers are saying about Kaspersky Anti-Targeted Attack Platform vs. Microsoft Defender XDR and other solutions. Updated: May 2024.
787,779 professionals have used our research since 2012.