Kaspersky is expanding its MDR solution with the integration of Digital Footprint Intelligence: leaked credentials are now automatically correlated with security events to help detect account compromises earlier. The update also adds new transparency features and extended platform support for Linux-based embedded systems.

Kaspersky has expanded its Managed Detection and Response (MDR) solution with several new features aimed at speeding up the detection and investigation of cyberthreats. At the center of the update is the new integration of Digital Footprint Intelligence, a service that collects information on leaked credentials. According to the company, this data is now automatically correlated with security events in real time to help identify potential account compromises at an early stage.

The expansion reflects a shift in attacker methods: according to Kaspersky, cybercriminals are increasingly relying on stolen or leaked credentials rather than exploiting software vulnerabilities. The company states that attacks using valid accounts now account for a quarter of all initial attack vectors. Because such activity often resembles regular user behavior, it is considered comparatively difficult to detect.

Digital Footprint Intelligence is a standalone Kaspersky service that monitors organizations’ digital environment and searches, among other things, the dark web and relevant forums for leaked corporate and account credentials. Through the connection to Kaspersky MDR, this information now feeds directly into analysts’ detection workflow, without teams having to cross-reference the two services manually. Kaspersky frames the move as a response to a continuously evolving threat landscape in which attackers increasingly exploit legitimate access paths rather than technical vulnerabilities.

By linking Digital Footprint data with security events in Kaspersky MDR, analysts are meant to be able to connect compromised credentials to ongoing incidents more precisely. This is intended to support both incident prioritization and proactive threat hunting for signs of account takeover. According to Kaspersky, the goal is to detect account misuse earlier and reduce the risk of unauthorized access before it develops into a full-scale attack.

In addition to the Digital Footprint Intelligence integration, Kaspersky is introducing new Asset Status Notifications. These alerts are designed to inform administrators whenever a protected asset requires attention, for example in cases of telemetry collection or connectivity issues. The aim is to surface such disruptions before they affect monitoring. Administrators will also be able to define the expected number of hosts per tenant, which, according to Kaspersky, gives service providers more control over license distribution and management across their customer base.

Kaspersky has also extended platform coverage: MDR now supports Kaspersky Embedded Systems Security for Linux 4.0, extending MDR protection to Linux-based embedded environments. The company states that the current version also includes several minor usability and platform improvements.

“We continue to evolve our MDR solution to help organizations detect complex threats early and respond to them more effectively,” Renat Turianov, MDR Product Owner at Kaspersky, is quoted as saying in the announcement. He adds that the Digital Footprint Intelligence integration gives analysts an additional layer of context to link information about compromised credentials with security events and proactively search for signs of account takeover.

Kaspersky MDR is part of the company’s managed security services portfolio and is aimed at organizations looking to supplement their own detection and response capabilities with external expertise. The service combines automated detection technologies with the work of human analysts who assess suspicious activity and issue recommendations. With the addition of Digital Footprint Intelligence and the new transparency and platform features, Kaspersky says it is expanding the data foundation underlying these analyses. Further information on the solution is available on Kaspersky’s website.

By Carolina Heyder

Carolina Heyder is a business analyst and moderator with extensive experience in the German and international IT market. She has worked for many years at renowned European trade publishers such as WEKA Fachmedien, Vogel IT Medien, Springer, and Aspencore. She creates content for both web and print media and is an expert in front of the microphone and camera. Thanks to her fluency in German, English, and Spanish, as well as her Chilean roots, she brings a global and intercultural perspective to topics such as cybersecurity, artificial intelligence, digital transformation, sustainability, and other key areas of the IT sector.

Leave a Reply

Your email address will not be published. Required fields are marked *

WordPress Cookie Notice by Real Cookie Banner