Latest News
September 22, 2026 | More tests
EDR Test: Kaspersky EDR Expert
In the period from December 2025 to February 2026, AV-TEST conducted an extensive evaluation of Kaspersky EDR Expert, focusing on its Endpoint Detection and Response (EDR) capabilities. The assessment measured the product's effectiveness in countering threats associated with Advanced Persistent Threats (APTs) and modern ransomware, while providing comprehensive attack telemetry for incident investigation. The testing utilized three distinct scenarios, each demonstrating a variety of tactics and techniques employed by sophisticated adversaries.
Scenario 1 - Kematian-Stealer:
This scenario simulates the "Kematian-Stealer", a threat that utilizes in-memory PowerShell execution to evade detection. The attack begins with a phishing email, advances through a registry-based UAC bypass, and concludes with data exfiltration and lateral movement via SMB. Kaspersky demonstrated outstanding visibility across the entire attack chain. It successfully identified all critical stages— including initial access, evasion, and privilege escalation—with comprehensive Tactic, Technique, and Telemetry detections. By accurately tracking command-and-control and data collection phases, Kaspersky proved its strong proficiency in handling evasive, script-based threats.
Scenario 2 – Bizfum Stealer:
The second scenario replicates the "Helldown Ransomware" threat, incorporating destructive impact techniques alongside advanced evasion methods. Kaspersky successfully identified the initial access via malicious files and links, as well as obfuscated command executions. Crucially, the solution detected severe impact activities, specifically "Service Stop" and "Data Encrypted for Impact," while also flagging internal defacement and attempts to inhibit system recovery. These results verify the product's capability to comprehensively track and protect against attacks employing both debugger/virtualization evasion and destructive encryption tactics.
Scenario 3 – Helldown Ransomware Emulation:
This final scenario emulates a complex Advanced Persistent Threat (APT) focused on stealth and lateral propagation. Kaspersky demonstrated robust detection across the entire attack chain, from initial spearphishing to web-based command and control. The solution provided deep visibility into extensive network discovery activities and successfully tracked lateral movement via RDP and compromised domain accounts. By accurately detecting critical events like "OS Credential Dumping" and COM Hijacking, Kaspersky proved its strong capability to defend against sophisticated, multistage network intrusions.
Additionally the solution was tested against three attacks in the default protective mode to measure atumatic reponse capabilities. It blocked all the attacks on the initial steps, demonstrating high efficiency with the automatic response.
Based on the findings across the APT scenarios, Kaspersky EDR Expert demonstrated robust detection and comprehensive visibility. It consistently identified critical attack vectors from initial compromise to destructive impacts and lateral movement. Consequently, Kaspersky EDR Expert earned the AVTEST Approved Advanced Endpoint Detection and Response certification, proving its effectiveness against complex, targeted threats.
