KasperskyXDR & Advanced Threat Protection

    Anti Targeted Attack

    Anti-APT network detection and response mapped to MITRE ATT&CK.

    Kaspersky Anti Targeted Attack (KATA) builds reliable defences against APT-like threats and targeted attacks without demanding additional IT security resources. It delivers multidimensional threat discovery across network, web, mail, and endpoints, powered by Kaspersky Threat Intelligence and mapped to MITRE ATT&CK, with three tiers of NDR functionality that combine with EDR into native XDR. Faltrox deploys and operates it to cut attacker dwell time.

    Overview

    What Anti Targeted Attack is

    Today’s attackers design unique methods of penetration and compromise, so rapid detection and the fastest appropriate response are critical. Kaspersky Anti Targeted Attack reduces the time to identify and respond to threats, simplifies analysis and incident response, and helps eliminate security gaps and reduce attacker dwell time — while automating manual tasks to free up your security team.

    It brings all potential entry points under control — network, web, mail, PCs, laptops, servers, and virtual machines — combining network traffic analysis, endpoint activity monitoring, a centralised verdict repository, and Global Threat Intelligence. It comes in three levels (KATA, KATA NDR Enhanced, KATA Ultra) offering essential-to-enhanced NDR, advanced sandboxing, and expert EDR with native XDR. Alerts are enriched from over 100 million sensors and mapped to MITRE ATT&CK. Faltrox runs it as the network layer of your detection and response.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Network Traffic

    Traffic monitoring, advanced detection engines, TLS fingerprinting, and IDS-based intrusion detection.

    02

    Web & Mail

    Brings web and mail entry points under control alongside the network for full-surface coverage.

    03

    Endpoints & Servers

    Endpoint activity monitoring across PCs, laptops, servers, and virtual machines (Windows and Linux).

    04

    Unknown Malware

    Advanced sandboxing detonates suspicious objects to catch never-before-seen malware.

    05

    APTs & Targeted Attacks

    Multidimensional discovery counters the sophisticated, persistent threats signature tools miss.

    06

    Shadow IT & Rogue Devices

    Enhanced NDR detects unauthorised devices, ARP spoofing, anomalies, and shadow IT.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Collect

      Network metadata and objects plus endpoint telemetry and objects are collected and normalised into a central repository.

    2. 02

      Discover

      Multiple engines — sandbox, anti-malware, YARA, IDS, DPI, URL reputation, anomaly detection — perform threat discovery.

    3. 03

      Enrich

      Detections are enriched with Kaspersky Threat Intelligence from 100M+ sensors and mapped to MITRE ATT&CK, IoA, and IoC.

    4. 04

      Prioritise & Investigate

      Incidents are prioritised and investigated from the alert, with direct access to the Threat Intelligence portal for context.

    5. 05

      Respond

      A range of centralised response actions — including gateway-level blocking and response on network devices via API — contain the threat.

    Capabilities

    Key capabilities

    Multi-Engine Threat Discovery

    Sandbox, anti-malware, YARA, IDS/DPI, URL reputation, and anomaly detection combine for multidimensional discovery.

    Advanced Sandboxing

    Detonates suspicious objects in a controlled environment to confirm never-before-seen malware.

    MITRE ATT&CK & TI Enrichment

    Enriches alerts with Kaspersky Threat Intelligence and maps them to the ATT&CK framework and IoA analysis.

    Full Network Visibility

    DPI, a network session table, mapping, and inventory deliver full east-west and north-south visibility.

    Network Guided Response

    Automated gateway-level response, ICAP blocking mode, and response on network devices via API Connector.

    Retrospective PCAP Analysis

    Stores raw traffic (PCAP) for retrospective analysis of an incident after new intelligence arrives.

    Anomaly & Shadow IT Detection

    Detects network security risks — unauthorised devices, ARP spoofing — plus anomalies and shadow IT.

    Native XDR with EDR

    KATA Ultra adds expert EDR capabilities and native XDR, unifying network and endpoint detection and response.

    Works with

    Part of the platform

    Kaspersky products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Kaspersky Anti Targeted Attack for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01Is KATA an NDR or an XDR product?

    Both, by tier. It offers essential to enhanced network detection and response (KATA and KATA NDR Enhanced), and KATA Ultra adds expert EDR capabilities to reach native XDR — so you can start at the network layer and combine with EDR for unified network-and-endpoint response.

    02What entry points does it cover?

    All the main ones — network, web, mail, PCs, laptops, servers, and virtual machines — combining network traffic analysis with endpoint activity monitoring under a single centralised repository and view.

    03How does it help with APTs specifically?

    APTs are designed to evade signature tools and dwell undetected. KATA’s multi-engine discovery, advanced sandboxing, anomaly detection, and MITRE ATT&CK mapping — enriched from over 100 million sensors — are built to surface exactly this kind of sophisticated, persistent activity and reduce dwell time.

    04Can it respond automatically?

    Yes — it supports automated gateway-level response with ICAP blocking mode and can act on network devices via its API Connector, so containment is centralised rather than manual.

    05How does Faltrox use it?

    We deploy KATA across your physical and virtual environments, tune the detection engines and sandbox, and run the investigation and response — operating it as the network detection-and-response layer of the managed SOC we provide.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us