Kaspersky Next XDR Expert

What's new

Kaspersky Next XDR Expert 1.2

Kaspersky Next XDR Expert has several new features and improvements:

  • An updated version of Bootstrap is used in the application. Before you install the new version of Kaspersky Next XDR Expert, update Bootstrap by running the following command:

    ./kdt apply -k <path_to_XDR_updates_archive> -i <path_to_configuration_file> --force-bootstrap

  • Kaspersky Next XDR Expert upgrade from version 1.1 to version 1.2.
  • Optimized Kaspersky Next XDR Expert deployment: improved configuration file and Configuration wizard for a simplified specifying of the installation parameters.
  • Deployment preliminary checks. Before you deploy Kaspersky Next XDR Expert, you can now check if the system requirements are met. Kaspersky Deployment Toolkit (KDT) checks your hardware, operating system, software, and network environment. If at least one requirement is not met, KDT interrupts the deployment and provides you a detailed report.
  • Flexible incident workflow. You can configure an incident workflow and view it in the visual editor.
  • You can now attach files to alerts or incidents. If necessary, you can remove or download the attached files.
  • Customizable incident handling process by using incident types.
  • When creating a playbook, you can configure the playbook algorithm to edit the incident properties or the alert properties.
  • You can export information about all incidents displayed in the incident table to a JSON file. This may be required when you have to provide this information to third parties.
  • AI-based asset scoring. A machine learning-based engine helps you evaluate the processes running on an asset, and define if a particular process is normal or if it is unusual and requires attention from a SOC analyst.
  • Improved the configuration process of the templates for email notifications about events occurring in Kaspersky Next XDR Expert.
  • You can reduce or increase the retention periods of alerts and incidents, depending on your needs. By default, the retention period of alerts and incidents is 360 days.
  • Uninstallation of Kaspersky Next XDR Expert. All created data will also be removed.
  • From a shortcut menu in the alert details window or incident details window, you can now open the Threat hunting page on a new browser tab.
  • In the alert details window or incident details window, you can now search through affected assets and observables.
  • Ability to configure alert aggregation rules through the REST API.
  • When you open the Threat hunting page from the alert details window or incident details window, the search is now performed for the period between the first and the last event of the alert or incident, and not for the last 24 hours.
  • Deployment preliminary checks. Before you deploy Kaspersky Next XDR Expert, you can now check if the system requirements are met. Kaspersky Deployment Toolkit (KDT) checks your hardware, operating system, software, and network environment. If at least one requirement is not met, KDT interrupts the deployment and provides you a detailed report.
  • Open Single Management Platform can now be installed on the Nutanix AHV virtualization platform.
  • OSMP Console optimization: the console windows, login page, and the Dashboard now load faster.
  • You can now switch from the incident details window to the incident-related events on the Threat hunting page.
  • Kaspersky Next XDR Expert now supports the following EPP-applications:
    • Kaspersky Endpoint Security for Windows, versions 12.5, 12.6, 12.7
    • Kaspersky Endpoint Security 12.1 for Linux
    • Kaspersky Endpoint Security 12.1 for Mac
    • Kaspersky Industrial CyberSecurity for Nodes 4.0
    • Kaspersky Endpoint Agent 4.0
  • Kaspersky Next XDR Expert is now compatible with Kaspersky Anti Targeted Attack Platform 7.0.
  • You can now refresh the information in the alert details window and the incident details window by clicking the refresh icon.

Kaspersky Next XDR Expert 1.1

Kaspersky Next XDR Expert has several new features and improvements:

  • An updated version of Bootstrap is used in the application. Before you install the new version of Kaspersky Next XDR Expert, update Bootstrap by running the following command:

    ./kdt apply -k <path_to_XDR_updates_archive> -i <path_to_configuration_file> --force-bootstrap

  • New design of the user interface.
  • Reduced hardware and software requirements.
  • Increased application stability.
  • A new deployment wizard for the simplified configuration of the installation parameters.
  • Addition of predefined playbooks.
  • Kaspersky Next XDR Expert now supports the following EPP-applications:
    • Kaspersky Endpoint Security 12.0 for Mac
    • Kaspersky Industrial CyberSecurity for Nodes 3.2
    • Kaspersky Endpoint Agent 3.16
  • New Dashboard widgets for monitoring responses performed through playbooks.
  • Migration from Kaspersky Security Center to Kaspersky Next XDR Expert, including migration of users and tenants, and the binding of tenants to Administration Servers of Kaspersky Security Center.
  • Kaspersky Next XDR Expert is now compatible with Kaspersky Anti Targeted Attack Platform 6.0.
  • New features and improvements introduced in the August 2024 update of Kaspersky Unified Monitoring and Analysis Platform.