No more typing reviews! Try our Samantha, our new voice AI agent.

Kaspersky Anti Targeted Attack vs Kaspersky Next EDR Expert comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Apr 9, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Kaspersky Anti Targeted Attack
Average Rating
6.6
Reviews Sentiment
6.1
Number of Reviews
6
Ranking in other categories
Network Traffic Analysis (NTA) (25th), Network Detection and Response (NDR) (28th)
Kaspersky Next EDR Expert
Average Rating
8.2
Reviews Sentiment
6.5
Number of Reviews
51
Ranking in other categories
Endpoint Detection and Response (EDR) (21st)
 

Mindshare comparison

Kaspersky Anti Targeted Attack and Kaspersky Next EDR Expert aren’t in the same category and serve different purposes. Kaspersky Anti Targeted Attack is designed for Network Traffic Analysis (NTA) and holds a mindshare of 1.1%, up 0.7% compared to last year.
Kaspersky Next EDR Expert, on the other hand, focuses on Endpoint Detection and Response (EDR), holds 1.2% mindshare, down 1.4% since last year.
Network Traffic Analysis (NTA) Mindshare Distribution
ProductMindshare (%)
Kaspersky Anti Targeted Attack1.1%
Darktrace15.7%
Cisco Secure Network Analytics9.0%
Other74.2%
Network Traffic Analysis (NTA)
Endpoint Detection and Response (EDR) Mindshare Distribution
ProductMindshare (%)
Kaspersky Next EDR Expert1.2%
CrowdStrike Falcon7.4%
Microsoft Defender for Endpoint5.9%
Other85.5%
Endpoint Detection and Response (EDR)
 

Featured Reviews

FarkhundAbbas - PeerSpot reviewer
Security Engineer at adcb
The tool provides excellent sandboxing and email security features, but the backup and recovery features are not good
If my primary solution is down, no backup solution is available to restore it. It is one of the biggest weaknesses of the platform. If I need to update the solution, there is no option to pick the events and the logs from it and deploy it in another solution. The backup and recovery features of the product are not good. I need backup. If the tool is down for some time, I cannot get the logs at that particular time.
Ravi-Upadhyay - PeerSpot reviewer
Founder at Inspira Enterprise
Provides strong threat detection and response through behavior analytics and network isolation
I have found the most valuable features of Kaspersky Endpoint Detection and Response Expert to be its ability to tackle the biggest challenges customers face when they have to mitigate any kind of a malware, ransomware attack, or online theft scenarios. The solution utilizes its HIPS, which is the host intrusion prevention system, behavior analytics system, and device control mechanism, making the antivirus capabilities of EDR quite strong. It is able to detect zero-day threats as well as historical or legacy malware, providing protection against current threats in the market and legacy malware. My opinion on the advanced threat detection algorithms in Kaspersky Endpoint Detection and Response Expert is that the ATP functionality is quite strong because it utilizes the behavioral analytics engine in the backend, which employs machine learning mechanisms to identify any kind of vulnerability or exploit running on the operating system level and the network level. If an attack is about to happen on the endpoint, it is able to protect over the network as well and checks for any illegitimate encryption activities. The machine learning capability within Kaspersky Endpoint Detection and Response Expert has contributed to improving detection accuracy and reducing false positives in my environment by helping me identify malicious activity and differentiate between any malicious activity on the operating system level and on the network level. I have seen customers with in-house developed applications that have no public signatures available. Once I whitelist a particular application, it intelligently whitelists not only the executable but also all the dependent services required to run that application. Furthermore, Kaspersky Endpoint Detection and Response Expert has successfully blocked network-level attacks on the endpoint. For example, during a recent DoS attack aimed at choking the entire network, Kaspersky detected the attack, isolated the device in a sandbox network, and alerted my SOC team via email for corrective action, thereby proactively helping me detect and protect devices from malicious attacks.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable use is detailing metadata collection from the endpoint and network."
"The Kaspersky Anti-Targeted Attack Platform provides visibility into telemetry data, enabling comprehensive monitoring of environmental activities."
"The product's deployment phase is easy."
"The email security feature is really good."
"I feel the anti-ransomware update is one of the tool's valuable features."
"Kaspersky Anti-Targeted Attack Platform is stable and runs all the time."
"The solution is very easy to use. Its interface is very simple, and you can build IOC's indicators. You can use your rules to detect these attacks because you can leverage threat intelligence. Y"
"The most valuable feature of Kaspersky Endpoint Detection and Response is security, as it has better security than other solutions, such as Symantec."
"The product has an easy-to-use EDR module based on signature-based antivirus detection. It is a complete software."
"Has great behavior detection and a very good firmware scanner."
"It's scalable enough for us."
"In my opinion Kaspersky is the best product on the market, it's very easy to handle, user-friendly and they provide a lot of features that are difficult to find in other endpoint solutions."
"The solution does a good job of filtering and blocking unusual traffic."
"We have a central console and from there you can monitor all workstations via an agent."
"The most valuable feature is Endpoint's management."
 

Cons

"The backup and recovery features of the product are not good."
"The blind spot or gap in the platform is network analysis functionality."
"Kaspersky Anti-Targeted Attack Platform is not a good product. We had problems with endpoints and the solution did not detect it. We didn't get any alerts about the attack."
"The solution lacks cloud integrations."
"In some of the places I have come across, even though they use Kaspersky, the ransomware enters their system."
"I think the tool is still not really good enough for integration compared to other products."
"The installation process could be more streamlined."
"Kaspersky Endpoint Detection and Response should continue to improve its protection while adapting to the changing threat ecosystems. Having more advanced features would be a benefit."
"I would like better integration with other products."
"Installing Kaspersky is complex. It requires more work from system admins and takes almost one week to deploy, including integration and mapping with other solutions. You also have to configure Kaspersky EDR sandboxing then set up permissions for various teams and customers."
"The product should release more frequent updates. The tool needs to improve its scalability as well."
"If a customer wants to use Kaspersky on-prem, they'll need to spend a lot on the hardware. Their server must be strong because EDR is a heavy product. You need excellent hardware to run it. It might make sense to deploy the solution in the cloud. If they add features, it will only make the product heavier and increase the hardware costs."
"My opinion is that behavior detection could work better. This feature gets a high rate of false positives."
"Could include some additional protection."
 

Pricing and Cost Advice

"Kaspersky is one of the cheaper solutions."
"The solution has competitive pricing."
"Kaspersky Anti-Targeted Attack Platform is cheap."
"Kaspersky is licensed on a yearly basis."
"We have been satisfied with the license of the solution."
"The product has a valuable pricing model. We need to purchase its monthly subscription."
"The solution's cost is reasonable compared to other vendors."
"We were on a three-year license to use Kaspersky Endpoint Detection and Response. The price could be better."
"Pricing for Kaspersky Endpoint Detection and Response is so-so when you compare it with its competitors. Its pricing isn't cheap nor expensive."
"The solution isn't the cheapest considering what you get. I would rate the pricing as seven out of ten."
"The solution is worth its cost so I rate pricing a ten out of ten."
report
Use our free recommendation engine to learn which Network Traffic Analysis (NTA) solutions are best for your needs.
899,204 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
12%
Construction Company
11%
Retailer
9%
Financial Services Firm
8%
Financial Services Firm
10%
Computer Software Company
10%
Manufacturing Company
9%
Comms Service Provider
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business30
Midsize Enterprise4
Large Enterprise18
 

Questions from the Community

What needs improvement with Kaspersky Anti-Targeted Attack Platform?
I think the tool is still not really good enough for integration compared to other products. If you need to integrate with the ecosystem of the Kaspersky primary, and if we are going to the third p...
What advice do you have for others considering Kaspersky Anti-Targeted Attack Platform?
I recommend the tool for enterprise customers. Previously, carry, like only antivirus products, was used by many. If you want to upsell a product, then you need to go with EDR and Kaspersky Anti-Ta...
What is your primary use case for Kaspersky Anti-Targeted Attack Platform?
I use the solution in my company since it has many good features, like sandbox features and other tech aspects. When I find other use cases or see feedback, I learn what the tool's strengths are fr...
What needs improvement with Kaspersky Endpoint Detection and Response Expert?
The user interface of Kaspersky Endpoint Detection and Response Expert could be more intuitive, and I would appreciate more flexibility or optimization in certain aspects. Moreover, the achievement...
What is your primary use case for Kaspersky Endpoint Detection and Response Expert?
My usual use cases for Kaspersky Endpoint Detection and Response Expert involve detecting ransomware earlier and proactively addressing all ransomware and all threats.
 

Also Known As

Kaspersky Anti Targeted Attack
Kaspersky EDR
 

Overview

 

Sample Customers

Republic of Serbia, Goods.ru, Tael, Insolar
Ferrari, Insolar, Tael, Republic of Serbia
Find out what your peers are saying about Darktrace, Auvik, Cisco and others in Network Traffic Analysis (NTA). Updated: May 2026.
899,204 professionals have used our research since 2012.