Anti Targeted Attack
Anti-APT network detection and response mapped to MITRE ATT&CK.
Kaspersky Anti Targeted Attack (KATA) builds reliable defences against APT-like threats and targeted attacks without demanding additional IT security resources. It delivers multidimensional threat discovery across network, web, mail, and endpoints, powered by Kaspersky Threat Intelligence and mapped to MITRE ATT&CK, with three tiers of NDR functionality that combine with EDR into native XDR. Faltrox deploys and operates it to cut attacker dwell time.
Overview
What Anti Targeted Attack is
Today’s attackers design unique methods of penetration and compromise, so rapid detection and the fastest appropriate response are critical. Kaspersky Anti Targeted Attack reduces the time to identify and respond to threats, simplifies analysis and incident response, and helps eliminate security gaps and reduce attacker dwell time — while automating manual tasks to free up your security team.
It brings all potential entry points under control — network, web, mail, PCs, laptops, servers, and virtual machines — combining network traffic analysis, endpoint activity monitoring, a centralised verdict repository, and Global Threat Intelligence. It comes in three levels (KATA, KATA NDR Enhanced, KATA Ultra) offering essential-to-enhanced NDR, advanced sandboxing, and expert EDR with native XDR. Alerts are enriched from over 100 million sensors and mapped to MITRE ATT&CK. Faltrox runs it as the network layer of your detection and response.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Network Traffic
Traffic monitoring, advanced detection engines, TLS fingerprinting, and IDS-based intrusion detection.
Web & Mail
Brings web and mail entry points under control alongside the network for full-surface coverage.
Endpoints & Servers
Endpoint activity monitoring across PCs, laptops, servers, and virtual machines (Windows and Linux).
Unknown Malware
Advanced sandboxing detonates suspicious objects to catch never-before-seen malware.
APTs & Targeted Attacks
Multidimensional discovery counters the sophisticated, persistent threats signature tools miss.
Shadow IT & Rogue Devices
Enhanced NDR detects unauthorised devices, ARP spoofing, anomalies, and shadow IT.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Collect
Network metadata and objects plus endpoint telemetry and objects are collected and normalised into a central repository.
- 02
Discover
Multiple engines — sandbox, anti-malware, YARA, IDS, DPI, URL reputation, anomaly detection — perform threat discovery.
- 03
Enrich
Detections are enriched with Kaspersky Threat Intelligence from 100M+ sensors and mapped to MITRE ATT&CK, IoA, and IoC.
- 04
Prioritise & Investigate
Incidents are prioritised and investigated from the alert, with direct access to the Threat Intelligence portal for context.
- 05
Respond
A range of centralised response actions — including gateway-level blocking and response on network devices via API — contain the threat.
Capabilities
Key capabilities
Multi-Engine Threat Discovery
Sandbox, anti-malware, YARA, IDS/DPI, URL reputation, and anomaly detection combine for multidimensional discovery.
Advanced Sandboxing
Detonates suspicious objects in a controlled environment to confirm never-before-seen malware.
MITRE ATT&CK & TI Enrichment
Enriches alerts with Kaspersky Threat Intelligence and maps them to the ATT&CK framework and IoA analysis.
Full Network Visibility
DPI, a network session table, mapping, and inventory deliver full east-west and north-south visibility.
Network Guided Response
Automated gateway-level response, ICAP blocking mode, and response on network devices via API Connector.
Retrospective PCAP Analysis
Stores raw traffic (PCAP) for retrospective analysis of an incident after new intelligence arrives.
Anomaly & Shadow IT Detection
Detects network security risks — unauthorised devices, ARP spoofing — plus anomalies and shadow IT.
Native XDR with EDR
KATA Ultra adds expert EDR capabilities and native XDR, unifying network and endpoint detection and response.
Works with
Part of the platform
Kaspersky products this pairs with, and the Faltrox services that operate it.
Kaspersky products
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Kaspersky Anti Targeted Attack for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01Is KATA an NDR or an XDR product?
Both, by tier. It offers essential to enhanced network detection and response (KATA and KATA NDR Enhanced), and KATA Ultra adds expert EDR capabilities to reach native XDR — so you can start at the network layer and combine with EDR for unified network-and-endpoint response.
02What entry points does it cover?
All the main ones — network, web, mail, PCs, laptops, servers, and virtual machines — combining network traffic analysis with endpoint activity monitoring under a single centralised repository and view.
03How does it help with APTs specifically?
APTs are designed to evade signature tools and dwell undetected. KATA’s multi-engine discovery, advanced sandboxing, anomaly detection, and MITRE ATT&CK mapping — enriched from over 100 million sensors — are built to surface exactly this kind of sophisticated, persistent activity and reduce dwell time.
04Can it respond automatically?
Yes — it supports automated gateway-level response with ICAP blocking mode and can act on network devices via its API Connector, so containment is centralised rather than manual.
05How does Faltrox use it?
We deploy KATA across your physical and virtual environments, tune the detection engines and sandbox, and run the investigation and response — operating it as the network detection-and-response layer of the managed SOC we provide.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us