<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Kaspersky Anti Targeted Attack Platform EDR Agent Add-On?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>EDR Agent configuration</strong> – Kaspersky Endpoint Security for Windows without protection components.<br /> <strong>Endpoint telemetry</strong> – processes, open network connections and modified files, sent continuously.<br /> <strong>KATA console management</strong> – run tasks, handle quarantined objects and view reports.<br /> <strong>Response actions</strong> – network isolation, execution prevention rules by path or hash.<br /> <strong>Hunting tasks</strong> – OpenIOC scans and YARA scans across connected hosts.<br /> <strong>Important</strong> – no anti-malware, web or device control; separate EPP required.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Explains where a built-in antivirus stops and why a detection and response layer has to sit on top of it.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Kaspersky Anti Targeted Attack Platform EDR Agent Add-On?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Kaspersky Anti Targeted Attack Platform EDR Agent Add-On extends an existing Anti Targeted Attack Platform installation to Windows computers that are already protected by a third-party endpoint protection platform. Deployment and settings run through Kaspersky Security Center, while alerts, tasks and response actions are handled in the Anti Targeted Attack Platform console; on Kaspersky Endpoint Security 11.2.0 to 11.8.0 this role was filled by the separate Kaspersky Endpoint Agent.<br /><br /> <strong>No EPP replacement</strong> – keep your current antivirus vendor while adding Kaspersky detection.<br /> <strong>One investigation view</strong> – endpoint telemetry joins network sensor data in one console.<br /> <strong>Faster containment</strong> – isolate a suspect host without walking to the desk.<br /> <strong>Retrospective hunting</strong> – rerun OpenIOC and YARA scans when new indicators arrive.<br /> <strong>Staged rollout</strong> – deploy per group with existing Kaspersky Security Center tasks.<br /> <strong>Evidence trail</strong> – alert and task history supports incident reports after attacks.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Kaspersky Anti Targeted Attack Platform EDR Agent Add-On suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">This add-on assumes an organisation that already runs the Anti Targeted Attack Platform and has people who read alerts. Telemetry without an analyst produces a data store, not security, which is what usually rules the product out at the small end.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Occasional</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Own analyst team to work the EDR telemetry</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Partial</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Partial</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Anti Targeted Attack Platform EDR Agent Add-On meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The Swiss reporting obligation applies to operators of critical infrastructure, not to every company. Since 1 April 2025 the revised Information Security Act requires those operators to report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with the full report following within 14 days. The hard part is the 24 hours, and this is where the add-on contributes: the Anti Targeted Attack Platform console holds the process, connection and file telemetry from the affected Windows host, so the initial report can state what was observed and when instead of describing a suspicion. What it does not cover is everything that decides whether the deadline is actually met, because the product files no report, does not judge whether an incident is reportable, and does not replace an on-call rota or a defined escalation path. Coverage also stops at Windows computers that carry the agent, so incidents on macOS, Linux, mobile or unmanaged devices will not appear in that timeline at all. This description is not legal advice, and whether your organisation is subject to the reporting obligation should be clarified with your own legal counsel.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Anti Targeted Attack Platform EDR Agent Add-On meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No software product makes an organisation NIS 2 compliant, because the directive places duties on the organisation rather than on a tool. NIS 2 requires measures in risk analysis and security policies, incident handling, business continuity, supply chain security, security in acquisition and development, procedures to assess the effectiveness of measures, cyber hygiene and training, cryptography, access control and asset management, and multi-factor authentication. This add-on contributes to two of those areas: incident handling, by supplying the endpoint evidence a responder needs to reconstruct an attack, and the detection side of risk management, through isolation and execution prevention that contain a case while it is being worked. It contributes nothing to business continuity, supply chain security, secure development, training, cryptography, access control or multi-factor authentication, and it generates no policy documentation. Since the directive is transposed separately in each member state, the applicable deadlines and the competent authority depend on where your organisation is established.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What should you know about official assessments of Kaspersky?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">In March 2022 the German Federal Office for Information Security (BSI) recommended replacing Kaspersky antivirus software, and when asked again in June 2024 the BSI confirmed that this recommendation still stood. In June 2024 the US Department of Commerce Bureau of Industry and Security issued a Final Determination prohibiting new sales of Kaspersky software in the United States from 20 July 2024 and, from 29 September 2024, prohibiting signature and codebase updates, operation of the Kaspersky Security Network in the US, and resale or integration of the software by third parties. Both measures remain in force. Kaspersky rejects the assessments as politically rather than technically motivated and has stated that it would pursue the legal options available to it. The Swiss position differs: the Federal Office for Cybersecurity (BACS) has issued neither a warning nor a ban, has stated that it warns only where it holds confirmed technical evidence of a security risk, and has said that no misuse of Kaspersky software has been reported in Switzerland, while Kaspersky products are no longer in use in the federal administration. Independent European test laboratories have continued to include Kaspersky products in their comparative tests. In practice this matters most if you sell into the United States, hold public-sector contracts in Germany, or answer supply chain requirements from customers who exclude vendors named in national security assessments; for other buyers it is a documented risk factor to weigh rather than an operational restriction.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="norton-vs-kaspersky-2025"><strong>Norton vs. Kaspersky – Which antivirus program offers the best protection in 2025?</strong><br />Sets Kaspersky detection results against a competing vendor, useful when the vendor question is on the table.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Anti Targeted Attack Platform EDR Agent Add-On help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Partly, and it is worth knowing which half. It answers the endpoint detection block directly: whether EDR telemetry is collected from endpoints, whether processes, network connections and file changes are recorded, whether a compromised host can be isolated, whether execution of specific files can be blocked by path or hash, and whether indicator-based searches using OpenIOC and YARA can be run retrospectively across the estate. It answers none of the items that usually sit in the same section, because it provides no anti-malware protection, no patch or vulnerability management, no disk or removable media encryption, no multi-factor authentication, no mobile device coverage, and no macOS or Linux endpoint coverage, since the agent configuration runs on Windows only. It also does not answer questions on round-the-clock monitoring, because the platform detects but does not staff a response team; the same agent configuration supports Kaspersky Managed Detection and Response, which is the route that closes that particular line. Where several of these gaps appear at once, adding components from the same Kaspersky line is usually cheaper to document than mixing vendors, because one console and one evidence trail are far easier to describe to an auditor than three.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between the built-in agent configuration and the EDR Agent configuration?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The decisive difference is protection: the EDR Agent configuration deliberately ships without protection and control components, which is exactly what makes it installable next to a third-party endpoint protection platform. Both configurations send the same telemetry to the Anti Targeted Attack Platform and both accept the same response actions from its console. Choose the built-in agent when Kaspersky Endpoint Security is already the protection layer on that machine, and the EDR Agent configuration when another vendor holds that role and you only want detection and response on top.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Capability</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Built-in agent</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">EDR Agent</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Anti-malware protection</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Web, device and application control</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Telemetry to the platform</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Isolation and execution prevention</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Runs beside a third-party EPP</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Device status in Kaspersky Security Center</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Normal</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Critical by design</td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The add-on has no standalone value: it requires an existing Kaspersky Anti Targeted Attack Platform, and the target computers must already sit under a Kaspersky Security Center console with Network Agent installed. The EDR Agent configuration runs on Windows only, so macOS and Linux machines in the same estate stay outside the telemetry and outside every response action. Because the protection components are absent by design, machines running the agent are displayed with Critical status in Kaspersky Security Center, which is expected and needs no action but does mean the KSC status view stops working as a quick health check for those devices. The usual follow-up purchase is therefore not more EDR but the layers around it, most often patch management or encryption. One regional restriction is decisive for some buyers: following the US Department of Commerce Final Determination, Kaspersky software cannot lawfully be sold, resold or updated in the United States, so this product is not an option for US sites or US subsidiaries.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="antivirus-programs-windows-2025"><strong>We help you decide. Test: Antivirus program: Best antivirus programs for Windows 2025</strong><br />Helps you pick the endpoint protection platform that has to run alongside the EDR Agent on each Windows machine.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Kaspersky Anti Targeted Attack Platform EDR Agent Add-On</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Why does Kaspersky Security Center show the computer as Critical after the agent is installed?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Because the File Anti-Virus component is not present in this configuration, and Kaspersky Security Center reads its absence as a critical state. This is expected behaviour and requires no action, since protection on that machine is provided by the third-party endpoint protection platform.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can the same agent be used with other Kaspersky detection products?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes. The EDR Agent configuration also supports Kaspersky Managed Detection and Response, the Kaspersky Unified Monitoring and Analysis Platform (KUMA) from Kaspersky Endpoint Security 12.6 for Windows, and the NDR part of the Anti Targeted Attack Platform from version 12.7.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-edr,sec-endpoint,sec-console" data-audience="b2b" data-count="3"> </div>