We have been using Kaspersky EDR Optimum for over 10 years, with the evolution of products reaching EDR now, we can verify the integrated responsiveness and visibility of our environment. Great protection tool on all OS. Very good value for money, with the new licensing, all business plans will now have native EDR.
Pros
Root cause analysis
Create or search for IOCs
Isolate your computer from the network instantly
Cons
Dashboard could be more intuitive and detailed
Likelihood to Recommend
We have been using Kaspersky EDR Optimum for over 10 years, with the evolution of products reaching EDR now, we can verify the integrated responsiveness and visibility of our environment. Great protection tool on all OS. Very good value for money, with the new licensing, all business plans will now have native EDR.
VU
Verified User
Administrator in Information Technology (1001-5000 employees)
We are using Kaspersky EDR Optimum Solution in Hybrid mode, KSC cloud and On-premise, which helps to manage inhouse and roaming users from a single centralized console.
Also, this solution is helping to track threat incidents on our endpoint and respond also.
There are some security control components i.e Device control, web control and application control to reduce the attack surface.
Pros
KEDR Optimum is helping to see threat kill chain formation, which helps to get clear picture of the what exactly attacker was trying to do during attack.
We are crating prevent execution rules to block the threat in our complete infra.
Ioc scan to validate and remove the any active threat entry from our endpoints
Cons
Agent package size is little big, if it can be optimize with lite package would be great
If possible Host Integrity functionality can be added, to take action as quarantine the non-compliance machine to connect our enterprise network
Many times KSC cloud operating slow, if it can optimized for the faster response
Likelihood to Recommend
This is very feature enriched solution, and cost effective. Within a single solution, it offer to mange Endpoint security i.e EPP, EDR , Encryption, Patch management and some device management, It's nice
We have deployed the KSC Administration server on premise and the KES and network agent in all systems. We have been using Kaspersky EDR Optimum for a long time. It is helping us to get complete clarity about threat detection and implement security controls, i.e., Device control, and web control, to reduce the attack surface. I am very satisfied with the solutions.
Pros
Respond on threat to block on pre execution..
Block via Hash Value
Cons
Agent package size can be lighter. (Small)
Can be a single agent not like network agent and KES.
Performance optimization
Likelihood to Recommend
It can implement in any IT infrastructure as well.
With quick responses and automated monitoring of all our devices on the network. Kaspersky EDR Optimum is our active tool against vulnerabilities, malware, and other threats that could hinder the progress of our government institution's activities.
Pros
Vulnerability discoveries
Vulnerability analysis
Quick responses
Cons
Better integration with the web console.
MDR reports with graphs.
Likelihood to Recommend
Kaspersky EDR Optimum is suitable for environments that have high availability of information and data. I can't imagine a corporate scenario that isn't currently needed.
Kaspersky EDR Optimum is the best approach to understand
about what the root cause from our malware detections is. Therefore, lets us
improve the setting to fix the breach based in the knowledge from the source (websites,
devices, misconfigurations, active vulnerabilities, etc) and show to us the
techniques that the malicious actor uses in your operations.
Pros
Identify the source and attack vector.
Draw in simple way the attack chain with details bifurcations (if apply).
Gets hashing from all objects involved in the operation.
Offer functionalities for perform quicks respond the attack.
Cons
Don’t wait the User start a task scan, I think that is most valuable shown scan information (or partially) when doing review the alert.
Doing a recommendation to make specific changes in policies and option to apply it automatically.
Likelihood to Recommend
I’m convinced that the key is guaranteeing the 100% of coverage, with the best configuration possible and without pain or hit at resource consumption and harmonies performance.I would like that the solution detecting, inventorying, and alerting about some host/device unknow or don’t register in KSC. Don’t depend on Device Detection function.
VU
Verified User
Engineer in Information Technology (1001-5000 employees)
We are using Kaspersky EDR Optimum for end point protection on our Corportate Desktops and Notebooks.
Pros
Easy to remote deploy over corporate networks.
Full integration to SandBox Solution on Cloud Providers
Incredible performance over Windows 10 and 11.
IT has integration with Kaspersky Security Center on Cloud.
Cons
In some situation doesn't work seambles update. Specially on Windows 7.
The management of rules and group's polices is a litle hard.
There isn't information about SandBox integration. For example activities detection.
Likelihood to Recommend
Kaspersky EDR Optimum is more appropriate for large computer network, because it has much better securtiy controls than others competitor. For small infraestructure, i choose KSC on cloud, becasuse is really simple its desploy and operation. One important point is use Windows 10 or 11 on the desktops. This scenarios is easier than heterogeneus computer networks.
VU
Verified User
Engineer in Information Technology (1001-5000 employees)
Kaspersky EDR Optimum addresses cybersecurity challenges by providing advanced threat detection, investigation, and response capabilities at the endpoint level. With the help of Kaspersky, we can safeguard over 3000+ assets at The Salvation Army. Their Threat Detection helps us monitor endpoint activities in real-time. They use advanced detection mechanisms, including behavioral analysis, machine learning, and threat intelligence, to identify suspicious activities and potential security threats.
Pros
One of the best Early Threat Detection tools on the market
EDR/MDR portal is user-friendly and allows us to investigate potential threats.
Cons
More coverage on IOT devices
Likelihood to Recommend
Easy deployment with a user-friendly MDR management portal. Kaspersky EDR Optimum scored higher during the attack simulation test than with Ms Defender or other EDR tools.
VU
Verified User
Consultant in Information Technology (5001-10,000 employees)
Kaspersky was our corporate antivirus. As far as we did not want to take any risks, we wanted a powerfull one. No doubt, Kaspersky is a great product, it works fine, although it needs some tunning for some applications, as many other antivirus products. However, we managed to get it working smoothly
Pros
Prevention
Self-update client
AD integration
Cons
Console (not cloud version)
Resource management
Remote connection
Likelihood to Recommend
I managed to get it working properly and with no issues in a mostly Windows Enviroment, both workstations and servers.
Some users, specially developers, complained about resource consumption, but I suppose that is the way it works. From my perspective, it worked pretty well for 99% of the users.
If you have some Russian concerns, maybe it's not the best option for you, although it's a great product
VU
Verified User
Administrator in Information Technology (10,001+ employees)