For integration with EDR / NDR (KATA), you must add the relevant component: Endpoint Detection and Response (KATA) or Network Detection and Response (KATA). You can select components for integration with EDR / NDR (KATA) when installing or upgrading the application, as well as using the Change application components task.
Starting with version 12.11 of Kaspersky Endpoint Security for Windows, the EDR (KATA) component has been renamed to Endpoint Detection and Response Expert (on-premise). In this version of the application, the component became universal. This means that the Embedded Agent handles communication not just with Kaspersky Anti Targeted Attack Platform, but also with other Detection and Response solutions by Kaspersky.
Kaspersky Endpoint Security integration with the Kaspersky Endpoint Detection and Response Expert (on-premise) solution will be available soon. Kaspersky Endpoint Detection and Response Expert (on-premise) is an enterprise cybersecurity solution that includes Kaspersky applications that allow an organization to defend against most types of cyber risks and cover the most important threat propagation scenarios. EDR Expert (on-premise) components are deployed on the Open Single Management Platform (OSMP). This functionality is planned to be supported by the end of 2025. Keep track of our Release Notes to be aware of application upgrades and new features.
EDR Optimum, EDR Expert and EDR (KATA) components are not compatible with each other.
To use EDR / NDR (KATA), the following conditions must be met:
Integration with Endpoint Detection and Response (KATA) involves the following steps:
You can select EDR (KATA) and NDR (KATA) components during installation or upgrade, as well as using the Change application components task.
You must restart your computer to finish upgrading the application with the new components.
You need to purchase a separate license for EDR (KATA) and NDR (KATA) (for example, Kaspersky Endpoint Detection and Response (KATA) Add-on).
The functionality becomes available after adding a separate key that covers EDR (KATA) and NDR (KATA) functionality. As a result, multiple keys are added on the computer: a key for Kaspersky Endpoint Security and keys for Kaspersky Endpoint Detection and Response (KATA) and Network Detection and Response (KATA).
Licensing for the stand-alone EDR (KATA) and NDR (KATA) functionality is the same as the licensing of Kaspersky Endpoint Security.
Make sure that both the EDR (KATA) and the NDR (KATA) functionality is included in the license and is running in the local interface of the application.
Kaspersky Anti Targeted Attack Platform requires establishing a trusted connection between Kaspersky Endpoint Security and the Central Node component. To configure a trusted connection, you must use a TLS certificate. You can get a TLS certificate in the Kaspersky Anti Targeted Attack Platform console (see instructions in the Kaspersky Anti Targeted Attack Platform Help). Then you must add the TLS certificate to Kaspersky Endpoint Security (see instructions below).

Adding a TLS certificate to Kaspersky Endpoint Security
By default, Kaspersky Endpoint Security only checks the TLS certificate of Central Node. To make the connection more secure, you can additionally enable the verification of the computer on Central Node (two-way authentication). To enable this verification, you must turn on two-way authentication in Central Node and Kaspersky Endpoint Security settings. To use two-way authentication, you will also need a crypto-container. A crypto-container is a PFX archive with a certificate and a private key. You can get a crypto-container in the Kaspersky Anti Targeted Attack Platform console (see instructions in the Kaspersky Anti Targeted Attack Platform Help).
How to connect a Kaspersky Endpoint Security computer to Central Node using the Web Console
You can also add a TLS certificate locally using the command line.
As a result, the computer is added on the Kaspersky Anti Targeted Attack Platform console. Check the operating status of the components by viewing the Report on status of application components. You can also view the operating status of components in reports in the local interface of Kaspersky Endpoint Security. Endpoint Detection and Response Expert (on-premise) and Network Detection and Response (KATA) components will be added to the list of Kaspersky Endpoint Security components.
You can check the status of components in the Kaspersky Security Center console in computer properties in the Components section. Consider the following when checking the status of the component in the console. If the component is not installed and the functionality is not covered by your license, the console displays the Not supported by license status instead of Not installed.
Starting with Kaspersky Endpoint Security 12.6 for Windows, you can monitor the status of EDR (KATA) component in Kaspersky Security Center Administration Console (MMC). The current status of the component is displayed in computer properties in the Endpoint Sensor status column (Running, Starting, Stopped, Paused, Failed, Unknown). The Web Console does not display the status of the Endpoint Sensor.