Try our new research platform with insights from 80,000+ expert users
Head of Network & Security Department at ssf
Real User
Top 10
A highly stable solution with a good technical support team that requires its users to follow a simple setup phase
Pros and Cons
  • "Stability-wise, I rate the solution a ten out of ten."
  • "Kaspersky Endpoint Detection and Response lacks configuration options."

What is our primary use case?

The solution was good for the use cases for which I used it.

What needs improvement?

Kaspersky Endpoint Detection and Response lacks configuration options. From an improvement perspective, I would like to see the solution offer more configuration options.

For how long have I used the solution?

I have been using Kaspersky Endpoint Detection and Response for two years. I am a customer of the solution.

What do I think about the stability of the solution?

Stability-wise, I rate the solution a ten out of ten.

Buyer's Guide
Kaspersky Endpoint Detection and Response
August 2025
Learn what your peers think about Kaspersky Endpoint Detection and Response. Get advice and tips from experienced pros sharing their opinions. Updated: August 2025.
865,295 professionals have used our research since 2012.

What do I think about the scalability of the solution?

Scalability-wise, I rate the solution a nine out of ten.

Around 400 people in my organization use Kaspersky Endpoint Detection and Response.

How are customer service and support?

The solution's technical support is good. I rate the technical support a ten out of ten.

How would you rate customer service and support?

Positive

How was the initial setup?

I rate the solution's initial setup phase a nine on a scale of one to ten, where one is difficult and ten is easy. The initial setup of the solution was simple.

The solution is deployed on an on-premises model.

The solution's deployment phase was completed in a few days.

Only one person was required to take care of the solution's deployment phase in my company.

What's my experience with pricing, setup cost, and licensing?

I rate the solution's pricing model a seven on a scale of one to ten, where one is cheap, and ten is expensive.

My company just made a single payment towards the costs related to the licensing of the solution.

What other advice do I have?

I would tell those planning to use the solution that Kaspersky Endpoint Detection and Response is a good product.

I rate the overall solution a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Hussain Nogama - PeerSpot reviewer
IT Administrator at TGTC
Real User
Comprehensive features, including application control, device control, and web filtering control
Pros and Cons
  • "Kaspersky EDR is far superior to other products. It gives detailed information about malware, geolocation, and more. Also, the agent itself is very lightweight compared to other products. The packages and updates were quite small in size, just a few KBs."
  • "The main issue was compatibility with the cloud itself. The CPU usage immediately spiked, causing the machines to hang and sometimes even forcing server or computer restarts."

What is most valuable?

Kaspersky EDR is far superior to other products. It gives detailed information about malware, geolocation, and more. Also, the agent itself is very lightweight compared to other products. The packages and updates were quite small in size, just a few KBs. 

And the best part is that when you apply a policy or make any changes, it immediately works. Regardless of the device's location, as long as it's reachable to the server, the policy applies within fractions of seconds. I had hands-on experience with an on-premises server on my premises. Once I applied any policy or made changes, it was assessed immediately, even if the PC was in a different country. As long as my PC was reachable, everything worked fine.

Moreover, the reports Kaspersky EDR generates, like the weekly and monthly reports, were amazing. We fully customized the on-premises server according to our needs, including how to push Windows patches, application updates, and whitelisting. One of the things I really like about Kaspersky is that even as an administrator, it won't allow you to bypass the applied policies.

What needs improvement?

The main issue was compatibility with the cloud itself. The CPU usage immediately spiked, causing the machines to hang and sometimes even forcing server or computer restarts. Within seconds of installing the agent, the CPU usage would become extremely high, rendering the machine practically unusable until we either manually restarted it or initiated a forced restart. We were left with no option but to uninstall the client.

It was the primary issue. When the agent was installed from the cloud portal, the machine became completely unresponsive and disconnected from the network.

I was quite satisfied with Kaspersky products when they were on-premises. The server was downloading the updates and signatures smoothly, and it was fully stable in our network. However, we decided to move to the cloud as we were offered better options, and there was no significant pricing difference. But unfortunately, once we moved to the cloud and deployed the agents on our clients, our clients started facing disconnection issues. We had no choice but to forcefully restart the machines. We tried seeking help from Kaspersky, but we didn't receive any assistance, which led us to switch to another product.

For how long have I used the solution?

We used this solution around 2018. Before that, we were not using EDR; it was just Kaspersky EDR. 

How are customer service and support?

I was disappointed with the cloud support. It didn't meet my expectations, which led me to consider another product. However, I don't have anything negative to say about Kaspersky in general. In fact, on my personal computer and laptop, I still use Kaspersky Endpoint Security. Additionally, for my other clients and places, I still prefer to purchase Kaspersky products.

For the recent support experience, I would rate it less than three, honestly speaking. The recent incident we had with them was not satisfactory. However, when we were on premises and had their support directly, it was fantastic. I would rate it 11 out of 10 back then. The support we received in the past was super nice and excellent.

How would you rate customer service and support?

Negative

How was the initial setup?

The implementation was straightforward. We had everything set up. However, on a few Windows 10 clients, it worked fine, but there was one unusual thing that happened on a Windows 11 client. I did an agent installation for a client, but it was uninstalled by itself. I submitted these logs to my vendor and Kaspersky's technical team, so they need to look into that issue.

We successfully deployed and worked on our own console and control panel, everything on the cloud. This issue only happened with the cloud version, not with on-premises. On-premises, it never happened.

What's my experience with pricing, setup cost, and licensing?

I was satisfied with the pricing of Kaspersky. Even now, if Kaspersky had solved our problem, I would have never jumped to SentinelOne. Honestly, I'm not the kind of person who keeps changing products frequently. Once a product stabilizes in our environment and works well, I feel everything is excellent.

And Kaspersky performed really well when it was on-premises. On my premises, I had a Kaspersky server that efficiently downloaded updates and signatures. Despite new products with signature-less approaches like SentinelOne, I was content with Kaspersky, and it provided a stable environment within our network.

However, there came a time when everyone wanted to upgrade, including our local vendor. They suggested moving to the cloud to remove it from on-premises. We considered this, especially since there was no significant pricing difference, and we could access better options in the cloud. So, we decided to migrate to the cloud.

But, unfortunately, after moving to the cloud and deploying agents on our clients, we encountered unexpected disconnection issues. The clients were suddenly getting disconnected, and we had no option but to forcefully restart the machines. We stopped further deployment and everything related to it. We thought to wait for Kaspersky's help in resolving the issue, but regrettably, we didn't receive any assistance from Kaspersky. Consequently, we had to switch to another product, which was SentinelOne.

Which other solutions did I evaluate?

We were working with SentinelOne. We initially had three options: Core, Control, and Complete. We opted for the Control option, which is the middle one. Core is the basic version, Control is in the middle, and Complete is the top-end version. But besides XDR, we have everything else.

Currently, we are exclusively working with SentinelOne.

Until 2021, Kaspersky was the best product in my environment. But since we moved to the cloud, we had so many troubles. We raised a case with Kaspersky, but they couldn't help. They didn't even reply, and that's why we changed the product. We were forced to switch to SentinelOne. We had been using Kaspersky for about nine or ten years, but that was when it was on-premises. However, when we moved to the cloud, it didn't work as expected, so we switched to SentinelOne. 

We even considered products like Falcon CrowdStrike, but it turned out to be more expensive than our budget allowed. Eventually, we opted for another solution that fit well within our budget constraints.

What other advice do I have?

If Kaspersky EDR is working fine in another environment and for other people, I would say they should stick with it. Kaspersky is a good product, and I honestly believe it is a very good product overall. 

Unfortunately, it didn't work well in my environment, but that might just be my bad luck. If you look at the reviews, especially in the Middle East, you'll see that Kaspersky has received very positive feedback.

Overall, I would rate the solution an eight out of ten. It's a nice product and genuinely a very good one. Kaspersky EDR was super and fulfilled my needs, especially on-premises. It has everything, like application control, device control, web filtering control, and much more. Any Kaspersky product you take, it comes with certain default features that are not available in SentinelOne. To get additional features, you need to switch from Core to Control and then to Complete versions. In my experience, it was fantastic and worked very well in my environment. I didn't face any issues, and I would still love to use this product if they had supported me in my case. Unfortunately, that didn't happen, and I was disappointed as I never expected to receive no support from Kaspersky.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Kaspersky Endpoint Detection and Response
August 2025
Learn what your peers think about Kaspersky Endpoint Detection and Response. Get advice and tips from experienced pros sharing their opinions. Updated: August 2025.
865,295 professionals have used our research since 2012.
Nadeem Syed - PeerSpot reviewer
CEO at Haniya Technologies
Reseller
Top 5Leaderboard
A robust set of features that ensure early detection of threats
Pros and Cons
  • "One of the most valuable aspects of Endpoint Detection and Response (EDR) solutions is their ability to detect and respond to spam and viruses in their early stages."
  • "Enhancing user-friendliness should be a priority."

How has it helped my organization?

I am affiliated with Kaspersky as a partner and reseller.

What is most valuable?

One of the most valuable aspects of Endpoint Detection and Response (EDR) solutions is their ability to detect and respond to spam and viruses in their early stages.

What needs improvement?

There are a few areas where I believe they could make some improvements. First, it would be beneficial if they could optimize the solution to be less resource-intensive, as it currently tends to put a heavy load on our machines and requires specialized servers for deployment. It is worth noting that they have made progress in this area, and the solution is now more manageable on standard server configurations. Enhancing user-friendliness should be a priority. Ideally, the interface should be intuitive enough that administrators and technical support teams don't require extensive training and can quickly adapt to using the solution independently. I must acknowledge that Kaspersky EDR already offers a robust set of features, especially in terms of threat detection and endpoint protection. 

For how long have I used the solution?

I have been working with it for fourteen years.

How are customer service and support?

Kaspersky offers two types of support. The standard support, which is included with the product purchase, tends to have longer response times for issue resolution. If you opt for their premium support, they provide prompt and effective assistance, ensuring quicker problem resolution.

Which solution did I use previously and why did I switch?


What's my experience with pricing, setup cost, and licensing?

I would say that their pricing is generally competitive and attractive. While the initial purchase cost for EDR may be relatively higher, particularly due to its advanced capabilities, it remains a cost-effective choice when compared to other established products in the same category.

What other advice do I have?

I would rate it eight out of ten because there's always room for improvement in any product or service.

Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
Hassam Tariq - PeerSpot reviewer
Team Lead Cybersecurity Operations at a computer software company with 11-50 employees
Reseller
Top 10
A security solution for encryption and protection providing path visibility
Pros and Cons
  • "Kaspersky offers more visible and comprehensive features compared to other products."
  • "It needs improvement in communication between the network and endpoint, as well as between endpoint and server."

What is our primary use case?

Kaspersky Endpoint provides multiple features. For example, it offers encryption, protection against targeted attacks, behavior and ML analysis, and multiple policies are available in Kaspersky. We recommend Kaspersky the most in Pakistan. Its advanced EDR features provide additional capabilities in endpoint security, including complete visibility of the quarantine system.

What is most valuable?

Kaspersky EDR gives complete path visibility of file location. It's allowed to contain the file in the same place. It does not spread the file to other locations or another system.

What needs improvement?

Kaspersky needs improvement in communication between the network and endpoint, as well as between endpoint and server. Sensors often fail to listen to the server due to communication issues resulting in multiple hurdles. Kaspersky needs to prioritize addressing this communication issue. While Kaspersky provides all the necessary functionality, there's room for improvement. Kaspersky should consider adding features to allow us to create use cases in the Sky console. If analytics don't detect anything in the Kaspersky console, the alerts must be configured in Kaspersky Sky so that they trigger when an attack is performed. This would make it easier for us to find any threats.

For how long have I used the solution?

I have been using Kaspersky Endpoint Detection and Response for two years.

What do I think about the stability of the solution?

The product is stable. Some issues with certain parts and connectivity are still unresolved.

We do not face any downtime. To update the license, we remove the previous license and apply the new one. If we fail to remove it, there's an option in Kaspersky called the reserve fee. You can add the reserve and use it to apply for the new license. Once the actual license expires, your reserve is automatically converted.

What do I think about the scalability of the solution?

You need more licenses to install the new sensors. Once you receive the license, enter it into your console, and you can use multiple sensors according to your license.

How are customer service and support?

When you purchase Kaspersky, you can choose to buy the ticketing solution, opt for proper support for the response service, or both options. Otherwise, the response time will be between four to eight hours.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

Kaspersky Endpoint Detection and Response outperforms Symantec in several aspects. Unlike Symantec, Kaspersky offers a single console for managing both media and endpoints. Additionally, Kaspersky provides encryption features, whereas Symantec lacks encryption capabilities in its Endpoint solution. Kaspersky offers more visible and comprehensive features compared to other products.

How was the initial setup?

The initial setup is easy and takes around one or two hours to complete. We have to download our packages.

What other advice do I have?

Overall, I rate the solution an eight out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
Kamran Bhatti - PeerSpot reviewer
Network Engineer at EXORDIUM NETWORKS, INC.
Real User
Top 5
The product saves time and resources, but it does not detect all kinds of threats
Pros and Cons
  • "The advanced detection features are valuable."
  • "The product does not detect zero-day threats."

What is our primary use case?

We've deployed the client at the user’s end. We provide software security.

What is most valuable?

The advanced detection features are valuable. The solution provides reports on users and their devices. We get to know whether the devices are infected. The tool has saved us time and resources. Otherwise, we have to check every PC for viruses.

What needs improvement?

Many viruses change algorithms. The product does not detect zero-day threats. Kaspersky must provide zero-day threat detection. The product must provide a detailed status of the users and their activity on the devices.

For how long have I used the solution?

I have been using the solution for more than a year.

What do I think about the stability of the solution?

The tool is stable.

What do I think about the scalability of the solution?

We have 40 to 50 clients that use the solution.

How was the initial setup?

The solution is deployed on my Windows Server 2019. The initial installation is easy.

What's my experience with pricing, setup cost, and licensing?

The product is cheap.

What other advice do I have?

My recommendation will depend on the number of users and the features other competitors offer. We are partners. Overall, I rate the tool a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer2242911 - PeerSpot reviewer
IT Security team leader at a healthcare company with 10,001+ employees
Real User
Top 5
Integrated with endpoint protection but improvement is needed in stability
Pros and Cons
  • "The product is integrated with endpoint protection. We don't have to implement a separate technology. It provides visibility over the endpoints."
  • "Kaspersky Endpoint Detection and Response needs vast resources on the central node. Not all maintenance tasks are in the GUI, so we often use commands. The lack of documentation for these processes means we frequently reach out to support, open tickets, and run complex CLI commands. It's not the most straightforward process. It should also improve stability."

What is our primary use case?

We use the solution to gather information on how endpoints behave and any events happening. If there's any suspicious activity on a machine, it alerts us. For investigating specific devices, we can refer back to the EDR.

What is most valuable?

The product is integrated with endpoint protection. We don't have to implement a separate technology. It provides visibility over the endpoints. 

What needs improvement?

Kaspersky Endpoint Detection and Response needs vast resources on the central node. Not all maintenance tasks are in the GUI, so we often use commands. The lack of documentation for these processes means we frequently reach out to support, open tickets, and run complex CLI commands. It's not the most straightforward process. It should also improve stability. 

For how long have I used the solution?

I have been working with the product for three years. 

What do I think about the scalability of the solution?

Kaspersky Endpoint Detection and Response is scalable. We have two admins using it. 

How are customer service and support?

Even when we raise a support ticket, the engineers often don't provide direct answers. We have to dig into R&D and experiment; getting a resolution for a support ticket takes time.

How would you rate customer service and support?

Neutral

How was the initial setup?

The tool's deployment was straightforward. It took a week to deploy. 

What's my experience with pricing, setup cost, and licensing?

The tool's pricing is reasonable. 

What other advice do I have?

I rate the product a six out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Kalana Wickramasinghe - PeerSpot reviewer
System Engineer at MIS Security Solutions (Pvt) Ltd
Real User
Top 5Leaderboard
Robust security through advanced threat detection, rapid incident response capabilities and effective endpoint protection
Pros and Cons
  • "It downloads essential security patches that are valuable for my PC."
  • "Incorporating an AI protection tool with the capability to detect and prevent zero-day threats, particularly those with a five-star rating in terms of severity would be beneficial."

What is our primary use case?

It allows me to selectively block certain websites for personal reasons, and I can control the usage of USB drives when connecting external devices to safeguard my computer. Additionally, I have the ability to manage other network devices for enhanced security.

What is most valuable?

It downloads essential security patches that are valuable for my PC. This is particularly useful as Windows doesn't always automatically update immediately.

What needs improvement?

Incorporating an AI protection tool with the capability to detect and prevent zero-day threats, particularly those with a five-star rating in terms of severity would be beneficial.

For how long have I used the solution?

I have been working with it for six months.

What do I think about the stability of the solution?

It provides excellent stability.

What do I think about the scalability of the solution?

The current scalability is insufficient for my needs on my PC. I personally manage HTTP, but it lacks the necessary capability. I believe an upgrade is required.

Which solution did I use previously and why did I switch?

I previously utilized Sophos XDR, but I transitioned to Kaspersky as it offers a more cost-effective solution. I also used ESET, but it didn't meet my requirements.

How was the initial setup?

The initial setup is straightforward and user-friendly.

What about the implementation team?

The deployment process takes approximately thirty minutes.

What was our ROI?

In terms of return on investment, I saved money by protecting my laptops, as universal ransomware poses the most significant threat, and the chosen solution effectively mitigates this risk.

What's my experience with pricing, setup cost, and licensing?

The pricing falls within the average range.

What other advice do I have?

Overall, I would rate it eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
IT Manager Azure Pacific at Talon International
Real User
Top 5
Convenient and provides effective security solutions
Pros and Cons
  • "Kaspersky EDR offers automated response capabilities, enhancing efficiency by enabling quick investigation and response to potential threats on Android devices."
  • "Kaspersky EDR could be improved by adding network detection capabilities to enhance convenience and security."

How has it helped my organization?

Kaspersky EDR has been beneficial for our organization, enhancing threat detection and response capabilities. It helps identify issues such as malware detection, unauthorized downloads, and inappropriate user permissions, enabling swift action to mitigate risks.

What is most valuable?

Kaspersky EDR offers automated response capabilities, enhancing efficiency by enabling quick investigation and response to potential threats on Android devices. It streamlines the process by automatically checking and responding to security issues, potentially improving effectiveness and reducing the need for manual intervention.

What needs improvement?

Kaspersky EDR could be improved by adding network detection capabilities to enhance convenience and security. Detecting and responding to network protocol issues, such as phishing emails or malicious downloads, can be challenging, but integrating network monitoring into EDR tools could significantly improve overall network security.

What's my experience with pricing, setup cost, and licensing?

Overall, I'm satisfied with the price of Kaspersky EDR. It is widely used among our peers and has been effective in detecting and mitigating malware and ransomware threats. However, I have noticed that other EDR tools like Palo Alto EDR offer more advanced AI capabilities and broader threat coverage.

What other advice do I have?

Kaspersky EDR enhances response capabilities by capturing malware or problematic websites on endpoints and providing alerts for quick action to resolve issues.

Kaspersky EDR offers features for threat hunting and vulnerability scanning on endpoints. It identifies unapplied security patches and provides a reporting tool for managing patch deployments efficiently.

Kaspersky EDR offers good integration capabilities, particularly with services like Office 365, which is beneficial for our organization. However, there might be some limitations when integrating with other tools such as NetSuite and Monday.com. Improving integration with tools like SolarWinds could enhance overall cybersecurity management. Looking ahead, prioritizing integration with cloud services would be advantageous as organizations increasingly rely on cloud-based solutions.

I would recommend Kaspersky EDR, especially for organizations operating in the China market. It is a convenient tool that provides effective security solutions, particularly helpful in addressing firewall issues commonly faced in the Chinese market. However, for companies outside of China not facing similar market restrictions, it might be good to consider other solutions as well.

Overall, I would rate Kaspersky EDR as a seven out of ten. It is a useful choice for our organization, although not perfect. It requires a certain skill set to manage security nodes effectively. However, it is relatively easy to use compared to other EDR tools, making it a safer option for less experienced users.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Kaspersky Endpoint Detection and Response Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2025
Buyer's Guide
Download our free Kaspersky Endpoint Detection and Response Report and get advice and tips from experienced pros sharing their opinions.