Skip to main content
TrustRadius
Kaspersky EDR Expert

Kaspersky EDR Expert

Overview

What is Kaspersky EDR Expert?

Kaspersky Endpoint Detection and Response (EDR) Expert provides endpoint protection, advanced detection, threat hunting and investigation capabilities and multiple response options in a single package. It is an EDR solution for IT security teams with more mature incident response processes,…

Read more
Recent Reviews

Kaspersky EDR Expert Review

10 out of 10
March 30, 2024
We have IT guy who likes all these security stuff, so he deployed trial version and during trial period Kaspersky EDR Expert helped us to …
Continue reading
Read all reviews

Awards

Products that are considered exceptional by their customers based on a variety of criteria win TrustRadius awards. Learn more about the types of TrustRadius awards to make the best purchase decision. More about TrustRadius Awards

Reviewer Pros & Cons

View all pros & cons
Return to navigation

Pricing

View all pricing

Kaspersky EDR Expert

$52.30

Cloud
Pricing is for a 3-year commitment, calculated per year. 1 and 2 year licenses also available. per endpoint

Entry-level set up fee?

  • No setup fee

Offerings

  • Free Trial
  • Free/Freemium Version
  • Premium Consulting/Integration Services

Starting price (does not include set up fee)

  • $52.30 3-year commitment, calculated per year per endpoint
Return to navigation

Product Details

What is Kaspersky EDR Expert?

Kaspersky Endpoint Detection and Response (EDR) Expert provides endpoint protection, advanced detection, threat hunting and investigation capabilities and multiple response options in a single package. It is an EDR solution for IT security teams with more mature incident response processes, enabling them to hunt, prioritize, investigate and neutralize complex threats and APT-like attacks.

Key features
  • Advanced detection, including methods based on machine learning
  • Indicator of Compromise (IoC), Indicator of Attack (IoA) and Sandbox detection
  • Monitoring and visualization with drill-down capability
  • Guided investigation
  • Centralized telemetry storage
  • Threat hunting capabilities
  • MITRE ATT&CK mapping
  • Multiple response options
  • Access to Kaspersky Threat Intelligence Portal
  • Single cloud or on-prem console


Kaspersky also describes what they believe are the product's key benefits, and differentiators:


Benefits
  • Single agent with next-gen endpoint security (EPP)
  • Provides tools for defending against complex and advanced threats
  • Allows for proactive threat hunting, not only reacting to incidents
  • Deep investigation helps prevent similar incidents in the future
  • Several response options, automation and customization to best fit the cybersecurity team
  • Reduces required cybersecurity resources through guidance and automation
  • Simple way to upgrade to Native XDR

DIfferentiators
  • Includes next-gen endpoint security (EPP)
  • Guided investigation helps analyze threats quickly and learn on the job
  • Proprietary Indicators of Attack
  • Sandbox with capability to use customer-defined images (on a select range of OS)
  • Threat Intelligence
  • API to send gathered telemetry to third-party systems
  • Supports both cloud and on-premise deployments

Kaspersky EDR Expert Features

  • Supported: Extended prevention - EPP included in the license provides detection and prevention based on Machine Learning. It also includes patch management, encryption and Adaptive Anomaly Control, an automatic system hardening tool.
  • Supported: Advanced detection - Besides Machine Learning and Behavior Analysis, the solution uses IoC and IoA detection and a customizable Sandbox.
  • Supported: MITRE ATT&CK mapping - IoAs and Sandbox detections are mapped to MITRE ATT&CK for the further analysis of the adversary’s Tactics, Techniques and Procedures.
  • Supported: Threat hunting - Real-time automated threat hunting with IoAs, access to Threat Intelligence Portal knowledge base and a flexible Query Builder allow for multiple ways to perform proactive threat hunting
  • Supported: Forensic investigation - Retrospective analysis can be performed over a vast array of telemetry gathered from each endpoint. It is collected in a centralized cloud or on-prem storage, making the data available even if the compromised endpoint is inaccessible or encrypted.
  • Supported: Incident response - Automated, guided and manual ‘one click’ response options are available via the central management console. Options include network isolation, delete file, prevent execution, start process, and get file.

Kaspersky EDR Expert Screenshots

Screenshot of Screenshot of Screenshot of

Kaspersky EDR Expert Video

Kaspersky Expert Security

Kaspersky EDR Expert Integrations

  • VirusTotal
  • Own API for sending telemetry to 3rd party systems
  • syslog
  • Active Directory

Kaspersky EDR Expert Technical Details

Deployment TypesOn-premise, Software as a Service (SaaS), Cloud, or Web-Based
Operating SystemsWindows, Linux
Mobile ApplicationNo
Supported CountriesAll
Supported LanguagesEnglish, Russian

Frequently Asked Questions

Kaspersky Endpoint Detection and Response (EDR) Expert provides endpoint protection, advanced detection, threat hunting and investigation capabilities and multiple response options in a single package. It is an EDR solution for IT security teams with more mature incident response processes, enabling them to hunt, prioritize, investigate and neutralize complex threats and APT-like attacks.

Kaspersky EDR Expert starts at $52.3.

CrowdStrike Falcon, Sophos Intercept X, and SentinelOne Singularity are common alternatives for Kaspersky EDR Expert.

The most common users of Kaspersky EDR Expert are from Mid-sized Companies (51-1,000 employees).

Kaspersky EDR Expert Customer Size Distribution

Consumers0%
Small Businesses (1-50 employees)3%
Mid-Size Companies (51-500 employees)46%
Enterprises (more than 500 employees)51%
Return to navigation

Comparisons

View all alternatives
Return to navigation

Reviews and Ratings

(15)

Attribute Ratings

Reviews

(1-10 of 10)
Companies can't remove reviews or game the system. Here's why
Score 10 out of 10
Vetted Review
Verified User
We're using Kaspersky EDR Expert as endpoint protection, system hardening, exposure management, endpoint detection and response tool. It protects endpoints running Windows and Linux and detects modern threats with low system performance impact and almost no false alarms. Threat Intelligence portal is also very valuable.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
We use it for all of the our workstation and now we are planning to deploy it to servers. We use EDR to get large amount of controls and logs from our hosts. Then we use collected data to determine cybersecurity incidents. Also this product decreases the load to our SIEM-system because the correlation between logs and security events.
Score 10 out of 10
Vetted Review
Verified User
We have IT guy who likes all these security stuff, so he deployed trial version and during trial period Kaspersky EDR Expert helped us to detect some malicious activities, so we decide to keep it and buy commercial license.
Score 1 out of 10
Vetted Review
Verified User
Incentivized
Kaspersky EDR Expert is a new sophisticated EDR system. We used this system to provide endpoint protection, advanced detection, threat hunting and investigation capabilities. It was used by SOC and IT operations for incident response to hunt, prioritize, investigate and neutralize complex threats and APT-like attacks. The business problems we addressed: end-point device security management, end-point protection, threat analysis and investigation, incident process management, protection against APT attacks.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
We use Kaspersky EDR Expert in client computers in our organization because we need a reliable system to protect these machines from malicious attacks and also to control other security aspects in the cliente computers. So far we are happy with the product and recomend it to any company that do not have too many computers to manage, since is a realy easy software to deploy and mantain.
Return to navigation