Currently, I use Kaspersky Endpoint Detection and Response for security on my computer. I am an end user.
Kaspersky Endpoint Detection and Response integrates antivirus, threat response, and EDR with high detection rates, behavior detection, and device control. It supports centralized management for seamless operation across remote and on-premise servers.



| Product | Mindshare (%) |
|---|---|
| Kaspersky Next XDR Expert | 0.8% |
| CrowdStrike Falcon | 9.2% |
| SentinelOne Singularity Endpoint | 5.9% |
| Other | 84.1% |
| Type | Title | Date | |
|---|---|---|---|
| Category | Extended Detection and Response (XDR) | Aug 4, 2026 | Download |
| Product | Reviews, tips, and advice from real users | Aug 4, 2026 | Download |
| Comparison | Kaspersky Next XDR Expert vs SentinelOne Singularity Endpoint | Aug 4, 2026 | Download |
| Comparison | Kaspersky Next XDR Expert vs CrowdStrike Falcon | Aug 4, 2026 | Download |
| Comparison | Kaspersky Next XDR Expert vs TrendAI Vision One | Aug 4, 2026 | Download |
| Title | Rating | Mindshare | Recommending | |
|---|---|---|---|---|
| CrowdStrike Falcon | 4.3 | 9.2% | 97% | 138 interviewsAdd to research |
| Cortex XDR by Palo Alto Networks | 4.2 | 4.5% | 96% | 115 interviewsAdd to research |
| Company Size | Count |
|---|---|
| Small Business | 7 |
| Midsize Enterprise | 5 |
| Large Enterprise | 6 |
| Company Size | Count |
|---|---|
| Small Business | 117 |
| Midsize Enterprise | 50 |
| Large Enterprise | 96 |
Kaspersky Endpoint Detection and Response offers a robust platform featuring automated responses, advanced reporting, and customizable policies. Users appreciate its lightweight agent and compatibility, though many report issues with stability and resource intensity. While effective in malware detection and incident response, challenges remain in configuration, integration, and efficient patch management. Zero-day detection and cloud version stability have room for improvement. However, its capabilities make it highly recommended in regions like Pakistan.
What are the key features of Kaspersky Endpoint Detection and Response?In industries prioritizing security, such as finance and healthcare, Kaspersky Endpoint Detection and Response aids in threat hunting and behavior analysis. It integrates with SIEM systems, allowing precise encryption, targeted attack protection, and device management. Deployed on servers, workstations, and mobile devices, it's particularly esteemed in areas like Pakistan for its robust capabilities.
| Author info | Rating | Review Summary |
|---|---|---|
| IT Manager at R K Khanna and Associates | 4.0 | I use Kaspersky EDR mainly as a firewall, and while it’s affordable and stable, it’s less effective and more resource-heavy than CrowdStrike, which I preferred but stopped using due to its high cost. |
| Manager Cyber Security Department at Mana | 3.0 | I've used Kaspersky Endpoint Detection and Response for two years in threat hunting, finding its detection adequate but lacking features, scalability, and support compared to industry leaders like CrowdStrike and Trend Micro, making it unsuitable for long-term use. |
| Security Engineer at adcb | 4.0 | We prioritize Kaspersky for its effective detection and response features, particularly its sandbox environment for malware analysis. However, support needs improvement due to slow response times. We switched from CrowdStrike due to data privacy concerns and cost efficiency. |
| Network administrator at a comms service provider with 201-500 employees | 4.5 | I use Kaspersky on numerous servers and workstations, finding its IT management features valuable, though it lacks XDR capabilities. Our security improved significantly after transitioning from McAfee, though Cortex offers better security features. |
| Senior Information Security Analyst at EastNets Holding Ltd. | 5.0 | In my company, we use Kaspersky Endpoint Detection and Response for environment scanning and SIEM integration. Its centralization feature is invaluable, though the UI needs improvement. Previously, I used Malwarebytes and GravityZone for smaller setups, but Kaspersky suits larger environments. |
| IT Manager at Ducart | 4.0 | I find Kaspersky Endpoint Detection and Response easy to use with good protection that doesn't impact computer performance. However, there's room for enhancing security and performance. I previously didn't consider other solutions and have no preferred cloud provider. |
| Head of Information Security at Faisal Islamic Bank of Egypt | 4.0 | I primarily use Kaspersky Endpoint Detection and Response for endpoints due to its high detection rate and valuable features like behavior detection and threat prevention. It could improve integration capabilities. Transitioning from Symantec was seamless, saving us about 70% in costs. |
| Head Information & Communication Technology at Uganda Finance Trust Ltd. | 4.0 | I use Kaspersky Endpoint Detection and Response for mobile devices and laptops, appreciating its reporting and malware detection features. However, its patch management needs improvement, prompting me to consider additional solutions like Sophos. Technical support response time could also improve. |
| Senior Security Engineer at a government with 10,001+ employees | 4.0 | We use Kaspersky Endpoint Detection and Response to enhance malware detection. Its consolidated features, including a unified agent and cloud/on-premise functionality, simplify management. However, the user interface needs improvement. Compared to Fidelis, Kaspersky's functionality and threat response are superior. |
| CEO at Haniya Technologies | 4.0 | As a Kaspersky partner, I find their EDR effective for early threat detection and competitively priced. However, it needs improvements in resource optimization and user-friendliness, despite good premium support. I rate it 8/10. |

Currently, I use Kaspersky Endpoint Detection and Response for security on my computer. I am an end user.
I am using Kaspersky Endpoint Detection and Response as a firewall. I have Kaspersky Endpoint Detection and Response firewall on my computer, which sits at the gate, so I manage maximum things through that.
I do customize the policies to determine what to do and what not to do. All things have been customized.
It is automated only.
Kaspersky Endpoint Detection and Response is sitting on the machine to monitor. The main network is being monitored through the firewall at that level. For individual machines, Kaspersky Endpoint Detection and Response sits to check the endpoint.
Kaspersky Endpoint Detection and Response is not up to the mark compared to what I have seen from earlier products. I was using CrowdStrike, and Kaspersky Endpoint Detection and Response is not up to the mark compared to CrowdStrike and other products. Kaspersky Endpoint Detection and Response sometimes seems to allow certain files which should not be allowed on its own. I trust Kaspersky Endpoint Detection and Response to check the files, but I cannot sit and check all the files that are coming in. Kaspersky Endpoint Detection and Response has its own weaknesses.
Kaspersky Endpoint Detection and Response slows the system slightly. It uses more resources than what CrowdStrike does.
When any attack happens or something is happening with other products I am using, Kaspersky Endpoint Detection and Response stops certain things. However, it does not take me to the file, and it is not user-friendly.
I have been using this solution for about three or four months.
Stability is present with no problems.
There are no scalability issues.
My vendor takes care of any issues, so I have not contacted Kaspersky Endpoint Detection and Response directly for these matters.
Neutral
I was using CrowdStrike. CrowdStrike was very good and really was monitoring things without any interference from me or any user. I give the machines to the users, and CrowdStrike stops wrong sites, fraudulent sites, fraudulent apps, and fraudulent files. Everything CrowdStrike used to stop. Kaspersky Endpoint Detection and Response is not doing that. There are certain things CrowdStrike stops that may not be proper, and I can check and then bypass them. Kaspersky Endpoint Detection and Response is not checking all fraudulent files and unwanted things, sites, or websites.
CrowdStrike cost was so high that I did not try it again.
The installation is the same as other products and not a big deal.
My vendor takes care of any issues.
Kaspersky Endpoint Detection and Response is cheap.
If CrowdStrike can give me a good rate like Kaspersky Endpoint Detection and Response, I can use it.
It seems okay. CrowdStrike was not heavy on my network or usage. I would rate this product an 8.

The main use case for Kaspersky Endpoint Detection and Response is to protect the endpoints. I use it in the financial industry.
We are security people, and we use it for threat hunting. We are not system administrators and we are not the owners of the product, so I can't tell you about these things. I can tell you about the features regarding threat hunting and threat intelligence.
This is not our use case, as we use it just for the Kaspersky Endpoint Detection and Response.
We use Kaspersky Endpoint Detection and Response customizable detection rules and policies.
In terms of security requirements, it meets expectations.
Regarding the machine learning capability in Kaspersky Endpoint Detection and Response, it performs adequately when considering its improvement in detection accuracy and reduction of false positives.
I have observed just an extra security layer on the endpoints during these two years of usage.
I'm facing challenges because the local support is not up to mark, and its features are not comparable to industry-leading solutions such as CrowdStrike and Trend Micro.
Kaspersky needs to improve its local support to become a better product for future releases. The local support is inadequate, and compared to Trend Micro and CrowdStrike, many features are missing in this tool regarding investigation, threat hunting, and threat intelligence. These features are not up to mark in this tool compared to other EDR solutions, and the interface is very unfriendly.
I have been working for two years with this solution.
We have not integrated Kaspersky Endpoint Detection and Response with our existing security frameworks.
I have faced stability issues. As I mentioned, I'm not a system administrator. We use it in our security department for threat hunting and threat intelligence.
It is not a scalable solution at all. I rate scalability for Kaspersky Endpoint Detection and Response a four out of ten.
I rate the support for Kaspersky Endpoint Detection and Response a three out of ten.
The problem with support is that they don't have much expertise to resolve the root cause of issues and to resolve solutions timely regarding deployments and other matters.
Neutral
I previously used Trend Micro before working with Kaspersky Endpoint Detection and Response.
I started using Kaspersky Endpoint Detection and Response because my current organization uses Kaspersky. In my previous organization, I was working with Trend Micro.
The setup for Kaspersky Endpoint Detection and Response is not complex. I rate the initial setup of Kaspersky Endpoint Detection and Response a seven out of ten.
For deployment, I used a local partner.
Kaspersky Endpoint Detection and Response is a very low-cost solution.
I think it's just a normal tool; compared to other market EDRs, this is a very poor product. In the near future, we are going to replace it with an industry's best solution.
I would recommend Kaspersky AV as a good product, but for Kaspersky Endpoint Detection and Response, I don't recommend using it. I always recommend the world's top products such as CrowdStrike, Trend Micro, and Palo Alto Networks. I never recommend anyone to use Kaspersky Endpoint Detection and Response, though their AV is a good product.
Overall, I rate Kaspersky Endpoint Detection and Response six out of ten.

Our use cases include ISC's indicator for compromise, blocking, caching, and automation. For example, the detection of any USB or removable device on any system triggers a response.
Additionally, if any malware is detected in the system, the EDR solution removes it. These are the primary use cases we focus on.
Another scenario involves the detection of a large data transfer, such as 3GB via a USB device, to another system, which must be identified. These are the main use cases we prioritize.
One of the good features is the provider's Faulting capability. If any of our systems detect malware, we can check the behavior of the malware by sending it to Kaspersky's sandbox environment.
This helps us assess how destructive the malware is. After analyzing it, we can create use cases and protection measures based on that behavior. So, this is the best feature of Kaspersky.
Kaspersky's support team is not that much supportive. If we need any help from them, they do not provide a good solution, and it takes too long to resolve the issue. This is the main thing because some cases are easy and need urgent resolution.
However, when we create a support ticket, it takes three days to get it planned, and we have urgent requirements. So, the ticketing process needs improvement.
I have been using this solution for two years.
It is a stable solution. I would rate the stability an eight out of ten.
I would rate the scalability an eight out of ten. Around six end users are using this solution. We have plans to increase the further usage in future.
There is room for improvement in the support.
Neutral
We used CrowdStrike. We switched to Kaspersky because of two reasons. Firstly, because I work in the financial sector. CrowdStrike is a cloud-based EDR solution, and for our financial sector, they don't allow us to put our financial data in the cloud.
And the second thing is the pricing issue because CrowdStrike is more expensive than Kaspersky. So these are the two reasons we moved to Kaspersky and removed CrowdStrike.
For the deployment of the server it will mostly take around two or three days for the deployment of the main server, and then it will be able to connect to different endpoints.
It is a continuous process, but for the main server that we deployed, it took two to three days for us including all configurations.
For deployment from the vendor side, only one person is needed for the deployment.
I would rate the pricing a five out of ten; it is neither too cheap nor too expensive.
For using Kaspersky, the first thing is the features it offers, like locking USB, the use cases, and the scalability. It is easily scalable in any type of environment, from small-sized organizations to larger ones with 5,000 or up to 10,000 users.
It is cost-effective in terms of services and features compared to other more expensive EDR solutions like CrowdStrike and Trend Micro.
So, these are the two things I would recommend if any organization wants to deploy it in their environment.
Overall, I would rate the solution a seven out of ten.

We use Kaspersky on around one to two thousand servers and around four hundred workstations. Today, I work with Kaspersky EDR, and we also use Microsoft 365 Business Premium licenses.
Before we implemented Kaspersky here, we had McAfee, so we had a big security improvement with the Kaspersky deployment. We have patch management with Kaspersky under the Windows Update Services.
It is a secure solution with a lot of IT management features. It assists with remote access, remote desktop access, script detection, cryptography, and device control. It offers features that some other solutions in the market do not have, such as Cortex XDR.
Cortex is better in the security features, yet Cortex doesn't have IT management features like Kaspersky. Kaspersky is not an XDR solution. With an XDR solution, we could gain some more time.
I have used Kaspersky for three to four years.
I would rate the stability of Kaspersky as seven out of ten.
Kaspersky Cloud is scalable. The on-premises solution we have is not so scalable since it is limited by server resources. I would rate scalability as six or five out of ten.
It is simple to contact technical support for Kaspersky. We can set up a meeting when we need it. I rate the customer service nine out of ten.
Positive
Before implementing Kaspersky, we used McAfee. We had a big security improvement after switching to Kaspersky.
The initial setup was easy. It is not simple to find the events and correlate them, yet setting it up is easier. For the on-premises one, it is easy to set up.
We used another enterprise called FastHelp. They have specialized teams that helped with the deployment of the solution. Today, I am a security analyst, so I don’t know exactly the other job roles involved in the deployment, but they might be security technicians or network administrators.
Before we implemented Kaspersky here, we had McAfee, so we had a big security improvement with Kaspersky deployment.
Kaspersky has a better price than other marketplace solutions. Due to this, they are growing significantly. I like the price. I'd rate it nine out of ten.
I fully recommend Kaspersky EDR to others.
I'd rate the solution nine out of ten.

My company uses the EDR functionalities of Kaspersky, which are not related to application security. Kaspersky Endpoint Detection and Response is useful for environment scanning and can be deployed on a server to scan for viruses, malware, and hardware. We also use the product for EDR integration with the SIEM solution and get logs from each device.
The most valuable feature of the solution is its centralization capability allowing everything to be done from one device, including deployment, and integrating with the domain controller to do further deployments.
There are certain shortcomings with the UI of the solution. The UI is not at all user-friendly. The product should have an easier UI.
I have experience with Kaspersky Endpoint Detection and Response for two years. I use Kaspersky Endpoint Detection and Response Version 13.
It is a stable solution.
It is a very scalable solution.
The product is used by 2,500 employees in my company.
The product is extensively used in my companies since it is very good.
We can plan to increase the number of users in our company since it is a very scalable product.
The solution's technical support is very helpful and responsive. The documentation of the product also helps a lot.
Five years ago, I used Malwarebytes.
Considering the use cases of Malwarebytes, it was used to protect two servers from ransomware. During the time when we were using Malwarebytes in my previous company, the best solution on Gartner was GravityZone. At my previous company, we chose GravityZone to protect our two servers in a small environment with around 50 employees. Due to the aforementioned reasons, there was a requirement for a small business solution. Kaspersky Endpoint Detection and Response is the best for large environments.
The initial setup of the product is complicated and requires more work and effort from the system administrator. The product should provide domain controller admin access to allow for the maintenance of the network. Every issue we face in Kaspersky Endpoint Detection and Response relates to network and system administrators.
The solution is deployed on-premises.
Steps for the deployment should be followed to configure the network and ensure that all devices are accessible on the network or the same subnet while ensuring that there are no DMZs.
Though the product is not user-friendly, I was involved in the implementation process since I am an integrator.
Yearly payments are to be made toward the licensing costs of the solution.
To those planning to use the solution, I can say that it provides various specific customization and offers many shields for protection, because of which there is a need to be specific about the resources you want to save.
If you have a SIEM solution, then you should be specific when integrating Kaspersky with that SIEM solution and the best logs.
The product is not friendly, and it's not for end users. The product is meant for engineers and security engineers owing to its complex nature.
I rate the overall tool a ten out of ten.

The solution is an antivirus.
The tool is easy to use. It provides good protection. The product doesn't affect the performance of the computers.
The solution must provide better security. The performance can be improved.
I have been using the solution for two and a half years.
The product is stable and reliable. I rate the stability an eight out of ten.
We have 120 users in our organization.
The support is very good.
The initial setup is fairly easy. It took us a few hours to deploy the solution. To deploy the product, we install it on the main server, deploy it to the workstation, and make the updates. After that, the product is fairly independent.
The first deployment was done with an integrator. Then, we did it in-house.
We generally get a license for 36 months. The solution is not cheap, but it is not expensive.
We are not a very large organization, so scalability is not relevant to us. After the first installation, we do not need people to maintain the tool. I will recommend the solution to others. Overall, I rate the product an eight out of ten.
I use the tool for endpoints.
From my point of view, one of the best aspects of Kaspersky Endpoint Detection and Response is its high detection rate, which surpasses many other solutions. Its valuable features include behavior detection, threat prevention, device control, adaptive anomaly control, and centralized protection detection.
One of the main areas where the tool could improve is its integration capabilities. For example, I find it challenging to integrate it with other solutions. It would be helpful if the tool could make it more open to integration with other tools.
I have been working with the product for five years.
The product is scalable.
We transitioned from Symantec to Kaspersky Endpoint Detection and Response for our company. We managed the migration process in parallel with our ongoing operations, and it didn't pose any challenges.
The product's deployment is easy. It can be completed in two to three days. No engineers are required for the deployment. However, I have kept one for the new station.
We have saved about 70 percent in terms of money.
The tool's pricing was high during the last renewal.
I rate the tool an eight out of ten. People should choose a solution that aligns well with their specific environment. For instance, opting for a lightweight agent suitable for virtual setups is crucial if they operate in virtual environments. Conversely, in non-traditional physical environments, a standard agent may suffice. It's essential to keep these considerations in mind when selecting a solution.

I use Kaspersky Endpoint Detection and Response for mobile devices and laptops. I also run it on some of my servers in the data center.
The product's biggest features are reporting and signature-based malware detection. It runs on how the machines are used in a particular environment.
The solution currently works fine for me. The only issue I face with the product is related to the area of patch management, as it is not very effective. If the patch management area can be improved in Kaspersky Endpoint Detection and Response, I need not go for another solution to take care of patch management, like a vulnerability management tool from Sophos or some similar product.
From an improvement perspective, I want to be able to use the product as a patch management tool for my endpoints since it is an area that is not working effectively for me. I am pushed to get a vulnerability management solution to manage the area of patches.
Technical support for the solution could be better because it takes a bit of time to reach out to them through our local channel partner to attend to some of the issues where we need support. It takes the support team an entire week to resolve an issue.
I have been using Kaspersky Endpoint Detection and Response for four years. I use the solution in my company as an end user.
Stability-wise, I rate the solution a nine out of ten.
I mostly operate in a Windows-based environment. The product has been able to meet my requirements, especially the ones related to the endpoints used in our organization, which have increased lately. I run ATS in different parts. I run Windows-based machines for endpoints, and I also run Exchange for emails. Scalability-wise, I rate the solution an eight or nine out of ten.
I rate the technical support a six or seven out of ten.
Neutral
The product's initial setup phase was easy. I rate the initial setup phase of the product a ten out of ten, as it was a very easy process. My company always receives help to improve certain areas from Kaspersky's partner we have in our country.
My company did seek support from a local platinum partner of Kaspersky to help our company with the initial setup phase.
I rate the product price a five on a scale of one to ten, where one is low price and ten is high price.
Previously, I had done some assessments with the EDR solutions provided by Sophos, which, in terms of price, fall under the higher side of the spectrum. I chose Kaspersky Endpoint Detection and Response since it falls under the price range that I wanted.
I rate the overall product an eight out of ten.

We use the solution to enhance malware detection and response capabilities.
The most valuable aspect of the product is its consolidated features. We can easily configure Kaspersky's anti-target attack, streamlining our security measures. The unified agent, which combines antivirus, optimal threat response, and EDR functionalities, is a significant improvement. This integration simplifies management, providing a comprehensive solution with both cloud and on-premise functionality. It ensures effective protection and swift threat response across our network.
There is room for improvement in its user interface. The web GUI needs development to make it more user-friendly and aligned with industry standards.
I have been working with Kaspersky EDR for two years.
I would rate the stability as an eight out of ten.
I would rate the scalability of the product as a seven out of ten. I would recommend Kaspersky EDR for enterprise-level businesses. Its robust functionality, including EDR use cases and versatile prevention rules, makes it particularly well-suited for larger organizations.
Kaspersky's tech support is good. We have local teams in our country, and they are proactive in hiring and sharing knowledge. They provide effective assistance for any EDR solution issues we encounter. I would rate the support as a nine out of ten.
Positive
When comparing Kaspersky EDR to other products like Fidelis Cybersecurity, Fidelis has a good user interface but tends to have issues with high CPU and RAM usage. I have heard feedback from users facing problems with Fidelis's Incident TimeLine feature. While both products have similarities, Kaspersky EDR stands out for its comprehensive functionality and effective threat response.
Setting up Kaspersky EDR can vary in complexity based on hardware. Customers might experience issues like storage or high CPU usage during installation or updates. While the initial installation is generally smooth, upgrading poses challenges, especially when transitioning between different operating systems. Careful testing is essential to prevent errors and compatibility issues caused by overwriting operating system codes.
The price for Kaspersky EDR is on the higher side, likely because of their extensive marketing efforts. However, the cost seems justified as they prioritize customer support, investing in a capable team to handle complex customer situations.
Overall, I would rate Kaspersky EDR as a seven out of ten.

I am affiliated with Kaspersky as a partner and reseller.
One of the most valuable aspects of Endpoint Detection and Response (EDR) solutions is their ability to detect and respond to spam and viruses in their early stages.
There are a few areas where I believe they could make some improvements. First, it would be beneficial if they could optimize the solution to be less resource-intensive, as it currently tends to put a heavy load on our machines and requires specialized servers for deployment. It is worth noting that they have made progress in this area, and the solution is now more manageable on standard server configurations. Enhancing user-friendliness should be a priority. Ideally, the interface should be intuitive enough that administrators and technical support teams don't require extensive training and can quickly adapt to using the solution independently. I must acknowledge that Kaspersky EDR already offers a robust set of features, especially in terms of threat detection and endpoint protection.
I have been working with it for fourteen years.
Kaspersky offers two types of support. The standard support, which is included with the product purchase, tends to have longer response times for issue resolution. If you opt for their premium support, they provide prompt and effective assistance, ensuring quicker problem resolution.
I would say that their pricing is generally competitive and attractive. While the initial purchase cost for EDR may be relatively higher, particularly due to its advanced capabilities, it remains a cost-effective choice when compared to other established products in the same category.
I would rate it eight out of ten because there's always room for improvement in any product or service.