Kaspersky targets credential-based attacks with new MDR detection capabilities
Kaspersky has expanded its Managed Detection and Response (MDR) service with new capabilities designed to help organisations detect compromised accounts earlier and give security teams more context when investigating potential cyberattacks.
The update integrates Kaspersky’s Digital Footprint Intelligence (DFI) data into MDR, allowing the service to automatically correlate information about leaked or compromised credentials with security events in real time. The move addresses a growing attack method in which cybercriminals use legitimate credentials to gain access to organisations while attempting to blend in with normal user activity.
According to Kaspersky’s Anatomy of a Cyber World: Global Report by Kaspersky Security Services, attacks involving valid accounts accounted for 25% of initial attack vectors. Because these attacks rely on legitimate credentials rather than software vulnerabilities, they can be difficult for security teams to distinguish from legitimate activity.
By connecting leaked credential intelligence with security events, Kaspersky MDR analysts can identify signs of account compromise, prioritise suspicious incidents and conduct more targeted threat hunting. This is intended to help organisations detect unauthorised account use before it develops into a wider security incident.
The latest MDR release also introduces Asset Status Notifications, which alert administrators when a protected asset requires attention, including issues that could affect telemetry collection or connectivity. This gives security teams greater visibility into potential gaps in monitoring coverage.
For service providers managing multiple customers, Kaspersky has added the ability to set expected host limits for individual tenants, providing more control over how MDR licences are allocated.
The platform now also supports Kaspersky Embedded Systems Security for Linux 4.0, extending MDR coverage to Linux-based embedded environments.
“Kaspersky MDR” is an expert-led service that provides continuous monitoring, threat detection and investigation, with analysts responding to security incidents throughout the incident management process.
Renat Turianov, Kaspersky MDR Product Owner, said the integration of Digital Footprint Intelligence provides analysts with additional context for identifying compromised credentials and investigating potential account misuse.
The changes come as attackers increasingly turn to legitimate credentials and other methods that allow them to evade conventional security controls, making faster identification of suspicious account activity an increasingly important part of enterprise cybersecurity.
Download the FREE Kaspersky Next Enterprise Security Guide here to explore the complete framework for simplifying security operations and building cyber resilience.
Go to TECHTRENDSKE.co.ke for more tech and business news from the African continent and across the world.
Follow us on WhatsApp, Telegram, Twitter, and Facebook, or subscribe to our weekly newsletter to ensure you don’t miss out on any future updates. Send tips to editorial@techtrendsmedia.co.ke


