Home > Applications > Kaspersky
Kaspersky Threat Intelligence is a comprehensive cybersecurity threat intelligence solution that helps enterprises proactively detect, analyze and prevent modern cyberattacks based on global intelligence data verified by Kaspersky experts.
In the context of increasingly frequent, sophisticated and targeted cyberattacks, Kaspersky Threat Intelligence helps organizations understand who is attacking, how they are attacking and with what objectives, thereby enhancing defense capabilities and incident response effectively.
Kaspersky Threat Intelligence is a service that provides in-depth information and analysis on cybersecurity threats, including threat actors, attack infrastructure, malware, Indicators of Compromise (IoC), and attacker Tactics, Techniques and Procedures (TTP).
Instead of only reacting when incidents occur, Kaspersky Threat Intelligence enables enterprises to proactively monitor and identify threats through data collection from:
● Open source and closed source
● Deep web và dark web
● Botnet monitoring system, honeypot, spam trap
● Global data verified by experts
The number of cyberattacks is rapidly increasing along with the expansion of cloud computing, remote work, and IoT, making the attack surface increasingly larger.
Kaspersky Threat Intelligence helps enterprises:
● Proactively detect new and previously unknown threats
● Reduce attack surface and exploitation risk
● Early warning of risks that may affect business operations
● Improve cybersecurity investment efficiency
Kaspersky Threat Intelligence Platform plays a central role in:
● Aggregate threat intelligence from multiple global sources
● Normalize and correlate threat data
● Combine internal data from SIEM, SOAR, SOC with external data
● Provide full context about attacks
● Support quick sharing and action
As a result, security teams can shorten incident detection and response time.
Provide high-level information on attack trends, cybersecurity risks, and business impact, serving leadership and decision-makers.
Analyze threat actor tactics, techniques, and procedures, supporting SOC teams and cybersecurity professionals.
Includes technical data such as malicious IPs, URLs, C2 servers, hashes, IoCs – easily integrated into existing security systems.
Collect in-depth intelligence about motives, timing and attack plans from dark web and underground sources.
Kaspersky Threat Intelligence is Kaspersky's official threat intelligence solution suite, built on over 20 years of global cybersecurity research and analysis experience.
All data is:
● Pre-processing with sandbox, heuristic, behavioral analysis
● Verified and enriched by Kaspersky experts
● Continuous real-time updates
Provide real-time threat intelligence (malicious IPs, URLs, hashes), easily integrated with SIEM, firewalls, IDS/IPS, and SOC to automate early detection and response.
Support threat data analysis, enrichment, and prioritization, helping reduce noise and improve incident investigation efficiency.
Provide in-depth reports on APT campaigns, including executive summary for leadership and detailed technical analysis for SOC teams.
Analyze active cybercrime groups, malware campaigns and ransomware.
Monitor the organization's digital footprint on the internet, detect data leaks and potential risks.
Protect industrial control systems (ICS) from threats targeting energy, manufacturing and critical infrastructure.
IoC lookup platform and relationships between threat indicators, supporting manual analysis and incident response.
● Enhance monitoring and incident response capabilities for SOC
● Optimize and integrate existing security solutions
● Reduce threat detection and response time
● Mitigate targeted attacks
● Provides a comprehensive picture of cybersecurity status
● Leader – Frost Radar (Q2/2024)
● Leader – SPARK Matrix (Q2/2024, Q1/2025)
With Kaspersky Threat Intelligence, enterprises can shift from a passive defense model to proactive cybersecurity, ready to deal with increasingly complex threats.
Kaspersky Unified Monitoring and Analysis Platform (KUMA) is Kaspersky's SIEM platform, designed to help enterprises collect, normalize, correlate and analyze security events centrally in real-time. In the context of increasingly sophisticated cyberattacks and increasingly complex IT infrastructure, KUMA plays a central role in enhancing security monitoring capabilities, early threat detection and optimizing SOC operations for enterprises.
According to Kaspersky, KUMA is a next-generation SIEM solution that supports comprehensive monitoring of IT and OT systems on a unified platform.
According to Grand View Research, the global Security Information and Event Management (SIEM) market reached $3.9 billion in 2022. Polaris Market Research recorded the market size at $8.75 billion in 2024 and forecasts growth at a CAGR of approximately 15%, heading toward $26.79 billion by 2032.
The Asia-Pacific region, including Vietnam, is rated by Mordor Intelligence as one of the fastest-growing SIEM markets, thanks to strong digital transformation and the increase in attacks such as ransomware, APT and supply chain attacks.
During IT infrastructure expansion and modernization, enterprises face numerous cybersecurity challenges:
● Increasing Ransomware, APT, phishing, insider threats attacks
● Complex IT infrastructure, combining On-Premise, Hybrid Cloud and Multi-Cloud
● Difficulties in monitoring, analyzing, and investigating security incidents
● Requirements to comply with information security standards and regulations
● Shortage of SOC personnel with deep expertise
SIEM solution enables businesses to centralize security logs and events, analyze data in real-time, support incident investigation and response, and enhance proactive defense capabilities.
Kaspersky is a global cybersecurity company, operating in nearly 200 countries and territories, protecting over 400 million users. With over 20 years of experience, Kaspersky provides security solutions for large enterprises, SMBs and individual users.
Kaspersky Unified Monitoring and Analysis Platform (KUMA) is a SIEM platform designed to:
● Collect, process and store security events from various sources
● Normalize and enrich event data
● Real-time and retrospective event correlation
● Detect anomalous behavior across the entire IT infrastructure
● Support automated response through Kaspersky ecosystem and custom scripts
KUMA deeply integrates with solutions such as Kaspersky Security Center, Threat Intelligence Portal, Kaspersky CyberTrace, Kaspersky Endpoint Detection and Response (EDR), and Kaspersky Industrial CyberSecurity for Networks.
Kaspersky Unified Monitoring and Analysis Platform (KUMA) is built on a modular architecture, allowing flexible deployment from all-in-one to geographically distributed models, suitable for large and complex IT systems.
The central component of Kaspersky KUMA SIEM platform, providing unified management interface, data visualization, user management, dashboards and security incident investigation support.
Perform security event correlation based on predefined rules, supporting real-time incident detection and historical data retrospective scanning.
Collect, normalize, enrich, and filter events from multiple sources, supporting diverse protocols and log formats.
Event storage on ClickHouse platform, supporting hot, cold, and archive storage, ensuring high performance and linear scalability.
Collect events from Windows, Linux operating systems and air-gapped environments.
Flexible event routing and distribution, optimizing bandwidth and supporting complex deployment scenarios.
● High performance, supporting up to 500,000 EPS per node
● Flexible horizontal and vertical scalability
● Multi-tenancy support
● Integration with Threat Intelligence, EDR, SOAR, Active Directory and OT/ICS
● Automatically respond to incidents and enrich data in real time
● Query events using SQL syntax
● Support RESTful API, SSO, LDAP, FreeIPA
● Export reports in multiple formats: HTML, PDF, CSV, Excel
Kaspersky Unified Monitoring and Analysis Platform (KUMA) supports multiple deployment models:
● All-in-One centralized deployment for small and medium systems
● Deploy distribution for large-scale systems requiring high performance and scalability
The architecture is designed based on EPS targets and minimum 6-month log retention requirements, ensuring long-term stability and scalability.
Kaspersky Unified Monitoring and Analysis Platform (KUMA) is a key component in the cybersecurity solution portfolio distributed by Sonic in Vietnam, helping enterprises build modern SOC systems and proactively address threats.
Kaspersky Unified Monitoring and Analysis Platform (KUMA) is a powerful, flexible, and highly scalable SIEM platform suitable for organizations and enterprises with large and complex IT infrastructure. The solution helps centralize security monitoring, accelerate threat detection, optimize SOC operations, and integrate tightly with the Kaspersky security ecosystem as well as third-party solutions.
Kaspersky Next XDR Expert integrates seamlessly with existing security measures, optimizing your security infrastructure effectiveness and enhancing threat detection capabilities with automated response and real-time visibility. This solution provides deep insights into evolving cyber threats targeting your enterprise, with a flexible architecture that can easily scale to meet your needs and ensure continuous protection for critical assets. Kaspersky XDR's superior security measures, including advanced threat detection and automated response, deliver the optimal solution to protect your organization's digital assets - now and in the future.
Kaspersky Next XDR Expert is the most premium product suite in the Kaspersky Next product line, equipped with the most advanced technologies available today and providing comprehensive security visibility for organizations and enterprises.
● Incident management: Effective incident management helps SOC Teams enhance their ability to detect, investigate, and classify alerts, and improve the incident investigation process for coordinated response
○ Consolidate multiple alerts from different sources into a single incident.
○ Improve the quality of original alerts to generate more accurate detections.
○ Orchestrate response across different security products.
● Automation and orchestration
○ Establish automated response workflows for events, thereby freeing up time and budget to focus on higher-priority events.
○ Build team workflows during incident handling processes.
● Kaspersky Investigate Graph: A visualization tool for detecting hidden threats, this tool allows customers to navigate easily to identify root causes and access necessary information quickly
○ Utilize data on incidents, alerts, events, and EDR telemetry
○ Enrich information with context from Kaspersky Threat Intelligence. This helps save time and supports building an effective Cyber Kill Chain.
● Log Management & datalake: enables collecting data from multiple sources and real-time analysis to quickly detect incidents
● Threat detection and cross-correlation: aggregates findings and alerts from all sources into the log management component described earlier, enabling near real-time correlation through built-in and custom rules to detect attacks and threats.
● Asset management: provides a centralized asset inventory along with vulnerability assessment and prioritization capabilities. It helps security teams have a comprehensive view of their entire asset system, including endpoints, servers, and network devices. This component allows asset classification based on detailed information such as hardware, operating system, installed software, and network information (IP, MAC, etc.).
○ These classifications help accelerate incident response by highlighting incidents related to the most critical assets.
○ Classification information can be used in the correlation process to refine detection rules and reduce false alarms.
● Dashboards and reports: alert security teams by aggregating widgets from other components of Kaspersky XDR. Security teams can visualize and analyze data from multiple sources, helping make informed decisions and proactively respond to emerging threats.
● Deployment toolkit: Simplifies product deployment, upgrades, and support for its components. The deployment toolkit includes platform services and command-line interface (CLI)-based utilities
● Integration with Kaspersky products: Ensures smooth and seamless connectivity with products such as Kaspersky Endpoint Security (KES), Kaspersky EDR Expert (KEDR Expert), Kaspersky Anti Targeted Attack (KATA), Kaspersky Threat Intelligence (CTI), and Kaspersky Automated Security Awareness Platform (KASAP). Other integrations, such as SASE (FWaaS), KICS, and KSMG, are expected to be added in the future
● Integration capability with 3rd party tools: Kaspersky XDR stands out with seamless coordination capability with various systems and products
○ Data collection: Collect logs and remote monitoring information from various sources, including operating systems, applications, and third-party EDR solutions. With over 200 ready-made connections
○ Response and information enrichment: Integrate playbooks to execute responses across third-party solutions such as NGFW, NDR, EDR and DLP
○ Open API: Provides documented API allowing customers and integrators to implement custom integration scenarios. This API supports various integration use cases, facilitating seamless communication and data exchange
Kaspersky Next XDR Expert includes the following main components:
● Open Single Management Platform (OSMP) - The technology platform on which Kaspersky Next XDR Expert is built. OSMP integrates all solution components and provides interaction between components. OSMP is scalable and supports integration with both Kaspersky applications and third-party solutions.
● OSMP Console - Provides a web interface for OSMP.
● KUMA Console - Provides web interface for Kaspersky Unified Monitoring and Analysis Platform (KUMA).
● KUMA Core - The central component of KUMA. KUMA receives, processes, and stores information security events, then analyzes events using correlation rules. As a result of the analysis process, if the correlation rule conditions are met, KUMA will generate alerts and send them to the Incident Response Platform.
● Incident Response Platform - A component of Kaspersky Next XDR Expert that allows you to create incidents automatically or manually, manage alert and incident lifecycle, assign alerts and incidents to SOC analysts and respond to incidents automatically or manually, including response through playbooks.
● Administration Server (also called Server) - The main component of the customer organization's endpoint protection. Administration Server provides centralized deployment and management of endpoint protection through EPP applications and allows you to monitor endpoint protection status.
● Data Source - Information security hardware and software generate events. After you integrate Kaspersky Next XDR Expert with necessary data sources, KUMA will receive events to store and analyze them.
● Integration - Kaspersky applications and third-party solutions are integrated with OSMP. Through integrated solutions, SOC analysts can enrich the data needed to investigate incidents, then respond to incidents.
Kaspersky Next XDR Expert solution is a product suite that provides deep insights into evolving cyber threats targeting your enterprise, with a flexible architecture that can easily scale to meet the needs of large organizations and enterprises, ensuring continuous protection for critical assets.
Kaspersky XDR's superior security measures, including advanced threat detection and automated response, provide the optimal solution to protect your organization's digital assets - now and in the future.
Kaspersky Next EDR Optimum is the second product in the Kaspersky Next product suite that Kaspersky has newly launched, including all features of Kaspersky Next EDR Foundations, while equipped with other advanced features such as: Data encryption, OS/application vulnerability management and patching, EDR features (rootcause analysis, incident response), Office 365 mail system protection, along with cybersecurity training modules for administrators.
Kaspersky Next EDR Optimum license is calculated per User, 01 User is used for 01 server or workstation and 02 mobile devices.
Kaspersky Next EDR Optimum provides superior protection features, in addition to comprehensive control capabilities from servers, workstations, mobile devices to cloud services, along with other advanced features such as:
● Centralized management capability for all devices deployed in the system, including:
○ Establish centralized antivirus policies, manage all computers in the system.
○ Issue remote update/scan commands on workstations, schedule periodic scans/updates. Supports offline updates in internal systems without requiring workstations to connect to the internet
○ Establish centralized antivirus policies, manage all computers in the system.
○ Issue remote update/scan commands on workstations, schedule periodic scans/updates. Supports offline updates in internal systems without requiring workstations to connect to the internet
○ Remote deployment of anti-virus software installation and other vendor software.
○ Build different policies for each user group regarding antivirus modes, update schedules, and scan schedules.
○ Kaspersky Security Center allows implementation of hierarchical management architecture, with Primary/Secondary modes
● Integrated protection for servers and workstations against malware
Kaspersky with advanced malware detection and processing technology and multi-level integration, provides robust protection capabilities, preventing and eliminating all malicious software.
System monitoring function
Kaspersky continuously monitors system activity, analyzing system behavior to detect suspicious actions.
●

For many years Timeway Trade Limited has been delivering premium design, products and solutions to industries. Let us help you plan and deliver your next project.
Contact us for more information
+65 6337 7883
Copyright © 2024 · All Rights Reserved · Timeway Trade Limited · Website by hawkhost