Home > Applications > Kaspersky

KASPERSKY
 
  1. Kaspersky Threat Intelligence

KASPERSKY THREAT INTELLIGENCE – PROACTIVE CYBER THREAT INTELLIGENCE SOLUTION

Kaspersky Threat Intelligence is a comprehensive cybersecurity threat intelligence solution that helps enterprises proactively detect, analyze and prevent modern cyberattacks based on global intelligence data verified by Kaspersky experts.

In the context of increasingly frequent, sophisticated and targeted cyberattacks, Kaspersky Threat Intelligence helps organizations understand who is attacking, how they are attacking and with what objectives, thereby enhancing defense capabilities and incident response effectively.

1. What is Kaspersky Threat Intelligence?

Kaspersky Threat Intelligence is a service that provides in-depth information and analysis on cybersecurity threats, including threat actors, attack infrastructure, malware, Indicators of Compromise (IoC), and attacker Tactics, Techniques and Procedures (TTP).

Instead of only reacting when incidents occur, Kaspersky Threat Intelligence enables enterprises to proactively monitor and identify threats through data collection from:

     Open source and closed source

     Deep web và dark web

     Botnet monitoring system, honeypot, spam trap

     Global data verified by experts

2. Why do enterprises need Kaspersky Threat Intelligence?

The number of cyberattacks is rapidly increasing along with the expansion of cloud computing, remote work, and IoT, making the attack surface increasingly larger.

Kaspersky Threat Intelligence helps enterprises:

     Proactively detect new and previously unknown threats

     Reduce attack surface and exploitation risk

     Early warning of risks that may affect business operations

     Improve cybersecurity investment efficiency

3. Kaspersky Threat Intelligence Platform (TIP)

Kaspersky Threat Intelligence Platform plays a central role in:

     Aggregate threat intelligence from multiple global sources

     Normalize and correlate threat data

     Combine internal data from SIEM, SOAR, SOC with external data

     Provide full context about attacks

     Support quick sharing and action

As a result, security teams can shorten incident detection and response time.

4. Types of Threat Intelligence in Kaspersky Threat Intelligence

Types of Threat Intelligence in Kaspersky Threat Intelligence

4.1. Strategic Threat Intelligence

Provide high-level information on attack trends, cybersecurity risks, and business impact, serving leadership and decision-makers.

4.2. Tactical Threat Intelligence

Analyze threat actor tactics, techniques, and procedures, supporting SOC teams and cybersecurity professionals.

4.3. Technical Threat Intelligence

Includes technical data such as malicious IPs, URLs, C2 servers, hashes, IoCs – easily integrated into existing security systems.

4.4. Operational Threat Intelligence

Collect in-depth intelligence about motives, timing and attack plans from dark web and underground sources.

5. Kaspersky Threat Intelligence solution overview

Kaspersky Threat Intelligence is Kaspersky's official threat intelligence solution suite, built on over 20 years of global cybersecurity research and analysis experience.

All data is:

     Pre-processing with sandbox, heuristic, behavioral analysis

     Verified and enriched by Kaspersky experts

     Continuous real-time updates

6. Main components of Kaspersky Threat Intelligence

Kaspersky Threat Intelligence

6.1. Threat Data Feeds

Threat Data Feeds

Provide real-time threat intelligence (malicious IPs, URLs, hashes), easily integrated with SIEM, firewalls, IDS/IPS, and SOC to automate early detection and response.

Threat Data Feeds2

6.2. CyberTrace

Support threat data analysis, enrichment, and prioritization, helping reduce noise and improve incident investigation efficiency.

6.3. APT Intelligence Reporting

Provide in-depth reports on APT campaigns, including executive summary for leadership and detailed technical analysis for SOC teams.

6.4. Crimeware Intelligence Reporting

Analyze active cybercrime groups, malware campaigns and ransomware.

6.5. Digital Footprint Intelligence

Monitor the organization's digital footprint on the internet, detect data leaks and potential risks.

6.6. ICS Threat Intelligence Reporting

Protect industrial control systems (ICS) from threats targeting energy, manufacturing and critical infrastructure.

 

6.7. Threat Lookup

Threat Lookup

IoC lookup platform and relationships between threat indicators, supporting manual analysis and incident response.

7. Investment efficiency during deployment

     Enhance monitoring and incident response capabilities for SOC

     Optimize and integrate existing security solutions

     Reduce threat detection and response time

     Mitigate targeted attacks

     Provides a comprehensive picture of cybersecurity status

8. Assessments from reputable analyst organizations

     Leader – Frost Radar (Q2/2024)

Leader – Frost Radar Q2.2024

 

     Leader – SPARK Matrix (Q2/2024, Q1/2025)

Leader – SPARK Matrix Q2.2024

Leader – SPARK Matrix Q2.2025

 

KASPERSKY THREAT INTELLIGENCE – PROACTIVE DEFENSE PLATFORM FOR ENTERPRISES

With Kaspersky Threat Intelligence, enterprises can shift from a passive defense model to proactive cybersecurity, ready to deal with increasingly complex threats.

 
 

  1. Kaspersky Unified Monitoring and Analysis Platform (KUMA)

KASPERSKY UNIFIED MONITORING AND ANALYSIS PLATFORM (KUMA) – SIEM PLATFORM FOR CENTRALIZED SECURITY EVENT MONITORING AND ANALYSIS

Kaspersky Unified Monitoring and Analysis Platform (KUMA) is Kaspersky's SIEM platform, designed to help enterprises collect, normalize, correlate and analyze security events centrally in real-time. In the context of increasingly sophisticated cyberattacks and increasingly complex IT infrastructure, KUMA plays a central role in enhancing security monitoring capabilities, early threat detection and optimizing SOC operations for enterprises.

According to Kaspersky, KUMA is a next-generation SIEM solution that supports comprehensive monitoring of IT and OT systems on a unified platform.

1. SIEM market overview and enterprise needs

SIEM market overview and enterprise needs

According to Grand View Research, the global Security Information and Event Management (SIEM) market reached $3.9 billion in 2022. Polaris Market Research recorded the market size at $8.75 billion in 2024 and forecasts growth at a CAGR of approximately 15%, heading toward $26.79 billion by 2032.

Polaris Market Research

The Asia-Pacific region, including Vietnam, is rated by Mordor Intelligence as one of the fastest-growing SIEM markets, thanks to strong digital transformation and the increase in attacks such as ransomware, APT and supply chain attacks.

Global SIEM market demand

2. Why do enterprises need to deploy SIEM?

During IT infrastructure expansion and modernization, enterprises face numerous cybersecurity challenges:

     Increasing Ransomware, APT, phishing, insider threats attacks

     Complex IT infrastructure, combining On-Premise, Hybrid Cloud and Multi-Cloud

     Difficulties in monitoring, analyzing, and investigating security incidents

     Requirements to comply with information security standards and regulations

     Shortage of SOC personnel with deep expertise

SIEM solution enables businesses to centralize security logs and events, analyze data in real-time, support incident investigation and response, and enhance proactive defense capabilities.

3. Introducing Kaspersky Unified Monitoring and Analysis Platform (KUMA)

Kaspersky is a global cybersecurity company, operating in nearly 200 countries and territories, protecting over 400 million users. With over 20 years of experience, Kaspersky provides security solutions for large enterprises, SMBs and individual users.

Kaspersky Unified Monitoring and Analysis Platform (KUMA) is a SIEM platform designed to:

     Collect, process and store security events from various sources

     Normalize and enrich event data

     Real-time and retrospective event correlation

     Detect anomalous behavior across the entire IT infrastructure

     Support automated response through Kaspersky ecosystem and custom scripts

KUMA deeply integrates with solutions such as Kaspersky Security Center, Threat Intelligence Portal, Kaspersky CyberTrace, Kaspersky Endpoint Detection and Response (EDR), and Kaspersky Industrial CyberSecurity for Networks.

4. Kaspersky KUMA SIEM platform architecture

Kaspersky Unified Monitoring and Analysis Platform (KUMA) is built on a modular architecture, allowing flexible deployment from all-in-one to geographically distributed models, suitable for large and complex IT systems.

Kaspersky KUMA SIEM platform architecture

Main components of KUMA SIEM

🔹 KUMA Core

The central component of Kaspersky KUMA SIEM platform, providing unified management interface, data visualization, user management, dashboards and security incident investigation support.

🔹 KUMA Correlator

Perform security event correlation based on predefined rules, supporting real-time incident detection and historical data retrospective scanning.

🔹 KUMA Collector

Collect, normalize, enrich, and filter events from multiple sources, supporting diverse protocols and log formats.

🔹 KUMA Storage

Event storage on ClickHouse platform, supporting hot, cold, and archive storage, ensuring high performance and linear scalability.

🔹 KUMA Agent

Collect events from Windows, Linux operating systems and air-gapped environments.

🔹 KUMA Event Router

KUMA Event Router

Flexible event routing and distribution, optimizing bandwidth and supporting complex deployment scenarios.

5. Key features of Kaspersky SIEM (KUMA)

     High performance, supporting up to 500,000 EPS per node

     Flexible horizontal and vertical scalability

     Multi-tenancy support

     Integration with Threat Intelligence, EDR, SOAR, Active Directory and OT/ICS

     Automatically respond to incidents and enrich data in real time

     Query events using SQL syntax

     Support RESTful API, SSO, LDAP, FreeIPA

     Export reports in multiple formats: HTML, PDF, CSV, Excel

6. Deployment model and system requirements for KUMA SIEM

Kaspersky Unified Monitoring and Analysis Platform (KUMA) supports multiple deployment models:

     All-in-One centralized deployment for small and medium systems

     Deploy distribution for large-scale systems requiring high performance and scalability

The architecture is designed based on EPS targets and minimum 6-month log retention requirements, ensuring long-term stability and scalability.

7. KUMA SIEM in Sonic's cybersecurity solution ecosystem

Kaspersky Unified Monitoring and Analysis Platform (KUMA) is a key component in the cybersecurity solution portfolio distributed by Sonic in Vietnam, helping enterprises build modern SOC systems and proactively address threats.

CONCLUSION

Kaspersky Unified Monitoring and Analysis Platform (KUMA) is a powerful, flexible, and highly scalable SIEM platform suitable for organizations and enterprises with large and complex IT infrastructure. The solution helps centralize security monitoring, accelerate threat detection, optimize SOC operations, and integrate tightly with the Kaspersky security ecosystem as well as third-party solutions.

 

   

  1. Kaspersky Next XDR Expert

KASPERSKY NEXT XDR EXPERT: OPTIMAL XDR SOLUTION FOR ENTERPRISE SECURITY

Kaspersky Next XDR Expert integrates seamlessly with existing security measures, optimizing your security infrastructure effectiveness and enhancing threat detection capabilities with automated response and real-time visibility. This solution provides deep insights into evolving cyber threats targeting your enterprise, with a flexible architecture that can easily scale to meet your needs and ensure continuous protection for critical assets. Kaspersky XDR's superior security measures, including advanced threat detection and automated response, deliver the optimal solution to protect your organization's digital assets - now and in the future.

Kaspersky Next XDR Expert is the most premium product suite in the Kaspersky Next product line, equipped with the most advanced technologies available today and providing comprehensive security visibility for organizations and enterprises.

1. Key features of Kaspersky Next XDR

     Incident management: Effective incident management helps SOC Teams enhance their ability to detect, investigate, and classify alerts, and improve the incident investigation process for coordinated response

     Consolidate multiple alerts from different sources into a single incident.

     Improve the quality of original alerts to generate more accurate detections.

     Orchestrate response across different security products.

     Automation and orchestration

     Establish automated response workflows for events, thereby freeing up time and budget to focus on higher-priority events.

     Build team workflows during incident handling processes.

     Kaspersky Investigate Graph: A visualization tool for detecting hidden threats, this tool allows customers to navigate easily to identify root causes and access necessary information quickly

     Utilize data on incidents, alerts, events, and EDR telemetry

     Enrich information with context from Kaspersky Threat Intelligence. This helps save time and supports building an effective Cyber Kill Chain.

     Log Management & datalake: enables collecting data from multiple sources and real-time analysis to quickly detect incidents

     Threat detection and cross-correlation: aggregates findings and alerts from all sources into the log management component described earlier, enabling near real-time correlation through built-in and custom rules to detect attacks and threats.

     Asset management: provides a centralized asset inventory along with vulnerability assessment and prioritization capabilities. It helps security teams have a comprehensive view of their entire asset system, including endpoints, servers, and network devices. This component allows asset classification based on detailed information such as hardware, operating system, installed software, and network information (IP, MAC, etc.).

     These classifications help accelerate incident response by highlighting incidents related to the most critical assets.

     Classification information can be used in the correlation process to refine detection rules and reduce false alarms.

     Dashboards and reports: alert security teams by aggregating widgets from other components of Kaspersky XDR. Security teams can visualize and analyze data from multiple sources, helping make informed decisions and proactively respond to emerging threats.

     Deployment toolkit: Simplifies product deployment, upgrades, and support for its components. The deployment toolkit includes platform services and command-line interface (CLI)-based utilities

     Integration with Kaspersky products: Ensures smooth and seamless connectivity with products such as Kaspersky Endpoint Security (KES), Kaspersky EDR Expert (KEDR Expert), Kaspersky Anti Targeted Attack (KATA), Kaspersky Threat Intelligence (CTI), and Kaspersky Automated Security Awareness Platform (KASAP). Other integrations, such as SASE (FWaaS), KICS, and KSMG, are expected to be added in the future

     Integration capability with 3rd party tools: Kaspersky XDR stands out with seamless coordination capability with various systems and products

     Data collection: Collect logs and remote monitoring information from various sources, including operating systems, applications, and third-party EDR solutions. With over 200 ready-made connections

     Response and information enrichment: Integrate playbooks to execute responses across third-party solutions such as NGFW, NDR, EDR and DLP

     Open API: Provides documented API allowing customers and integrators to implement custom integration scenarios. This API supports various integration use cases, facilitating seamless communication and data exchange

 

2. Kaspersky Next XDR Expert Architecture

Kaspersky Next XDR Expert includes the following main components:

     Open Single Management Platform (OSMP) - The technology platform on which Kaspersky Next XDR Expert is built. OSMP integrates all solution components and provides interaction between components. OSMP is scalable and supports integration with both Kaspersky applications and third-party solutions.

     OSMP Console - Provides a web interface for OSMP.

     KUMA Console - Provides web interface for Kaspersky Unified Monitoring and Analysis Platform (KUMA).

     KUMA Core - The central component of KUMA. KUMA receives, processes, and stores information security events, then analyzes events using correlation rules. As a result of the analysis process, if the correlation rule conditions are met, KUMA will generate alerts and send them to the Incident Response Platform.

     Incident Response Platform - A component of Kaspersky Next XDR Expert that allows you to create incidents automatically or manually, manage alert and incident lifecycle, assign alerts and incidents to SOC analysts and respond to incidents automatically or manually, including response through playbooks.

     Administration Server (also called Server) - The main component of the customer organization's endpoint protection. Administration Server provides centralized deployment and management of endpoint protection through EPP applications and allows you to monitor endpoint protection status.

     Data Source - Information security hardware and software generate events. After you integrate Kaspersky Next XDR Expert with necessary data sources, KUMA will receive events to store and analyze them.

     Integration - Kaspersky applications and third-party solutions are integrated with OSMP. Through integrated solutions, SOC analysts can enrich the data needed to investigate incidents, then respond to incidents.

 

3. Recommendations

Kaspersky Next XDR Expert solution is a product suite that provides deep insights into evolving cyber threats targeting your enterprise, with a flexible architecture that can easily scale to meet the needs of large organizations and enterprises, ensuring continuous protection for critical assets.

Kaspersky XDR's superior security measures, including advanced threat detection and automated response, provide the optimal solution to protect your organization's digital assets - now and in the future.

 

   

  1. Kaspersky Next EDR Optimum

KASPERSKY NEXT EDR OPTIMUM: COMPREHENSIVE CYBERSECURITY PROTECTION SOLUTION

Kaspersky Next EDR Optimum is the second product in the Kaspersky Next product suite that Kaspersky has newly launched, including all features of Kaspersky Next EDR Foundations, while equipped with other advanced features such as: Data encryption, OS/application vulnerability management and patching, EDR features (rootcause analysis, incident response), Office 365 mail system protection, along with cybersecurity training modules for administrators.

Kaspersky Next EDR Optimum license is calculated per User, 01 User is used for 01 server or workstation and 02 mobile devices.

1. Key features of Kaspersky Next EDR Optimum

Kaspersky Next EDR Optimum provides superior protection features, in addition to comprehensive control capabilities from servers, workstations, mobile devices to cloud services, along with other advanced features such as:

     Centralized management capability for all devices deployed in the system, including:

     Establish centralized antivirus policies, manage all computers in the system.

     Issue remote update/scan commands on workstations, schedule periodic scans/updates. Supports offline updates in internal systems without requiring workstations to connect to the internet

     Establish centralized antivirus policies, manage all computers in the system.

     Issue remote update/scan commands on workstations, schedule periodic scans/updates. Supports offline updates in internal systems without requiring workstations to connect to the internet

     Remote deployment of anti-virus software installation and other vendor software.

     Build different policies for each user group regarding antivirus modes, update schedules, and scan schedules.

     Kaspersky Security Center allows implementation of hierarchical management architecture, with Primary/Secondary modes

     Integrated protection for servers and workstations against malware

Kaspersky with advanced malware detection and processing technology and multi-level integration, provides robust protection capabilities, preventing and eliminating all malicious software.

System monitoring function

Kaspersky continuously monitors system activity, analyzing system behavior to detect suspicious actions.

    

For many years Timeway Trade Limited has been delivering premium design, products and solutions to industries. Let us help you plan and deliver your next project.

Contact us for more information

+65 6337 7883

Copyright © 2024 · All Rights Reserved · Timeway Trade Limited · Website by hawkhost