No more typing reviews! Try our Samantha, our new voice AI agent.

Kaspersky Anti Targeted Attack vs Rapid7 InsightIDR comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Apr 9, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Kaspersky Anti Targeted Attack
Average Rating
6.6
Reviews Sentiment
6.1
Number of Reviews
6
Ranking in other categories
Network Traffic Analysis (NTA) (23rd), Network Detection and Response (NDR) (29th)
Rapid7 InsightIDR
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
33
Ranking in other categories
Security Information and Event Management (SIEM) (24th), User Entity Behavior Analytics (UEBA) (11th), Endpoint Detection and Response (EDR) (34th), Threat Deception Platforms (4th), Extended Detection and Response (XDR) (19th)
 

Mindshare comparison

While both are Network Security Systems solutions, they serve different purposes. Kaspersky Anti Targeted Attack is designed for Network Traffic Analysis (NTA) and holds a mindshare of 1.4%, up 0.6% compared to last year.
Rapid7 InsightIDR, on the other hand, focuses on Security Information and Event Management (SIEM), holds 2.2% mindshare, down 2.5% since last year.
Network Traffic Analysis (NTA) Mindshare Distribution
ProductMindshare (%)
Kaspersky Anti Targeted Attack1.4%
Darktrace15.4%
Cisco Secure Network Analytics8.6%
Other74.6%
Network Traffic Analysis (NTA)
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
Rapid7 InsightIDR2.2%
Splunk Enterprise Security7.6%
IBM Security QRadar5.5%
Other84.7%
Security Information and Event Management (SIEM)
 

Featured Reviews

FarkhundAbbas - PeerSpot reviewer
Security Engineer at adcb
The tool provides excellent sandboxing and email security features, but the backup and recovery features are not good
If my primary solution is down, no backup solution is available to restore it. It is one of the biggest weaknesses of the platform. If I need to update the solution, there is no option to pick the events and the logs from it and deploy it in another solution. The backup and recovery features of the product are not good. I need backup. If the tool is down for some time, I cannot get the logs at that particular time.
Prajwal Chougale - PeerSpot reviewer
SPC L2 Analyst at a tech services company with 51-200 employees
Centralized threat hunting has improved alert accuracy and simplifies incident investigations
I would say there are two areas for improvement: the reporting dashboard that provides insights or reports weekly or monthly lacks detailed information about how logs are being ingested. While the details are there, they could be more concise and easier to understand for any level of authority. The second area is alert tuning; compared to Microsoft Sentinel, Rapid7 InsightIDR provides fewer alerts with more static alert functionality and lacks dynamic alerting exposures. There could be improvements to learn from past alert activities for more dynamic alert configurations. These two areas are the main areas for improvement; everything else is good.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The product's deployment phase is easy."
"The most valuable use is detailing metadata collection from the endpoint and network."
"The Kaspersky Anti-Targeted Attack Platform provides visibility into telemetry data, enabling comprehensive monitoring of environmental activities."
"Kaspersky Anti-Targeted Attack Platform is stable and runs all the time."
"The email security feature is really good."
"I feel the anti-ransomware update is one of the tool's valuable features."
"The solution is very easy to use. Its interface is very simple, and you can build IOC's indicators. You can use your rules to detect these attacks because you can leverage threat intelligence. Y"
"I like the tool's user analysis feature."
"The biggest reason why we chose Rapid7 was to gain value in a really quick time. Its deployment doesn't take months. It just takes a few days."
"The incident case management is the most valuable feature. Even though there's always something I find I would like to add to that feature, the ability to quickly sort through all the logs, network and endpoint data, etc., and add it to an incident case as part of the investigation, is nice. Having it automatically timeline that additional data into the original incident timeline, and correlate it to other notable events and activities on the network, results in a huge improvement in our overall confidence that we've quickly traced down the right source of an issue."
"The solution's initial setup is easy."
"Rapid7 InsightIDR is budget-friendly and has a good market position because not everybody can afford to go for LogRhythm or Splunk or QRadar."
"I definitely recommend Rapid7 InsightIDR."
"It gives all the advantages of a SIEM, however, using clever AI, it looks for patterns of behavior rather than just flooding me with all the alerts."
"InsightIDR has allowed us to find potential security issues that we did not know existed, and get remediation quickly."
 

Cons

"In some of the places I have come across, even though they use Kaspersky, the ransomware enters their system."
"The blind spot or gap in the platform is network analysis functionality."
"The backup and recovery features of the product are not good."
"The solution lacks cloud integrations."
"Kaspersky Anti-Targeted Attack Platform is not a good product. We had problems with endpoints and the solution did not detect it. We didn't get any alerts about the attack."
"I think the tool is still not really good enough for integration compared to other products."
"One thing that springs to mind is easier API integration with ITSMs."
"I chose eight out of ten because of the analytical rules; they lack dynamic rules, and also due to the dashboard and reporting part."
"It would be useful to import threat intelligence in YARA format along with known incorrect email addresses.​"
"The solution needs improvement in threat intelligence. Increasing the depth of intelligence to help users understand more about threats is a possibility. My suggestion is to expand access to other websites or resources."
"One of the things that could be better is digital forensics. It is there, but it can be better. They could provide more on the endpoint detection level."
"The product allows us to make only 30 custom rules."
"InsightIDR's integration with other solutions could be improved. Also, I'd like more control from the portal over what's happening on the endpoint side. For example, when I see an attack on an endpoint, I want to be able to stop it from the portal."
"Inability to get access to compliance reports within the solution."
 

Pricing and Cost Advice

"Kaspersky Anti-Targeted Attack Platform is cheap."
"The solution has competitive pricing."
"Kaspersky is one of the cheaper solutions."
"Rapid7 InsightIDR is a cheaply priced product. On a scale of one to ten, where one is very expensive, and ten is very cheap, I rate the product's price at seven or eight."
"Licensing is by endpoint and amount of retention time (at least ours is). Default retention was one year, but we are able to push the retention further if needed. There's also a provide-your-own-S3 option for longer retention if you don't want to pay for the additional retention years in your Rapid7 agreement."
"​Accurately predict your licensing counts as this is a subscription based product.​"
"Licensing is straightforward. If, for some reason, you don’t meet the minimum licensing requirements, there is a third-party managed service that can help."
"The pricing of the solution depends on the user. But there is a yearly licensing cost."
"The team is very willing to work with companies. My suggestion is to call the Rapid7 sales department and see how they can help.​"
"​I am sure that there are cheaper products out there, but none that meet so many of our needs whilst maintaining stability and usability.​"
"The solution has a mid-range price point in the market"
report
Use our free recommendation engine to learn which Network Traffic Analysis (NTA) solutions are best for your needs.
911,493 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
15%
Construction Company
13%
Comms Service Provider
10%
Retailer
9%
Financial Services Firm
10%
Manufacturing Company
9%
Comms Service Provider
8%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise5
Large Enterprise6
 

Questions from the Community

Ask a question
Earn 20 points
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is your experience regarding pricing and costs for Rapid7 InsightIDR?
My experience with pricing, setup costs, and licensing has been very positive; it is cost-effective and offers great value for the money. We bought the licensing through an agent, and the setup was...
What needs improvement with Rapid7 InsightIDR?
I would say there are two areas for improvement: the reporting dashboard that provides insights or reports weekly or monthly lacks detailed information about how logs are being ingested. While the ...
 

Also Known As

Kaspersky Anti Targeted Attack
InsightIDR
 

Overview

 

Sample Customers

Republic of Serbia, Goods.ru, Tael, Insolar
Liberty Wines, Pioneer Telephone, Visier
Find out what your peers are saying about Darktrace, Auvik, SolarWinds and others in Network Traffic Analysis (NTA). Updated: August 2026.
911,493 professionals have used our research since 2012.