Kaspersky Enhances Its MDR to Detect Stolen Credential Abuse Earlier

Kaspersky has updated its Managed Detection and Response (MDR) service to incorporate information about leaked credentials directly into security incident analysis. The new version integrates data from Digital Footprint Intelligence (DFI), improves monitoring of protected assets, and extends coverage to certain embedded Linux systems. The goal is to detect attacks using compromised legitimate accounts more quickly, as these can initially be mistaken for normal user activity due to the use of valid access rights.

The key features of the new Kaspersky MDR in 30 seconds

  • Kaspersky integrates Digital Footprint Intelligence into MDR to cross-reference leaked credentials with real-time security events.
  • The company states that valid accounts are involved in 25% of the initial attack vectors analyzed in its global report.
  • The new notifications alert when a protected asset shows telemetry or connectivity issues.
  • Service providers can set host limits per client.
  • MDR now extends its coverage to Kaspersky Embedded Systems Security for Linux 4.0.

The update emphasizes a growing security concern: an attacker doesn’t always need to find a previously unknown vulnerability or develop advanced malware. If they obtain valid credentials, they can attempt to entrance through the same door an employee uses daily.

According to the report Anatomy of a Cyber World: Global Report by Kaspersky Security Services, attacks exploiting valid accounts account for 25% of the initial vectors observed by the company. This data, derived from Kaspersky’s telemetry and services, shouldn’t be automatically extrapolated to global cybersecurity incidents, but it highlights a widely recognized issue in identity defense.

Cross-referencing credential leaks with company activity

The main innovation is connecting two traditionally separate data sources.

Digital Footprint Intelligence collects and analyzes information related to an organization’s external exposure, including compromised credentials detected in leaks and other sources investigated by Kaspersky’s threat intelligence services.

With integration into MDR, this information can automatically correlate with events logged within the protected environment.

This can be especially relevant during investigations. A legitimate login isn’t inherently malicious. But if the credentials for that account appear among data identified as compromised by Kaspersky, the event gains a different context.

The system can use this correlation to help analysts identify potential compromised accounts, prioritize incidents, and direct threat hunting efforts toward users or systems at higher risk.

This doesn’t mean that finding leaked credentials automatically confirms an intrusion. A exposed password may have been changed or belong to an account no longer active. The correlation provides an additional signal to be considered alongside other indicators.

Kaspersky also suggests using this feature for threat hunting, proactively searching for signs of malicious activity that haven’t yet triggered a clear alert.

The company explains that integration enables analysts to look for signs of account abuse before unauthorized access escalates to later stages of an attack.

Greater visibility into assets that stop transmitting data

The second part of the update is less flashy but directly impacts the effectiveness of any detection platform.

An MDR service depends on receiving telemetry from monitored devices. If a device stops communicating due to connectivity issues, misconfiguration, or agent failure, a blind spot appears.

Kaspersky now incorporates Asset Status Notifications, which alert administrators when any protected asset requires attention.

These notifications aim to help identify telemetric or connectivity issues before they reduce monitoring coverage.

This concern is especially critical in large or distributed infrastructures. Having a server registered in a security platform doesn’t guarantee it’s continuously sending all necessary information to detect anomalous activity.

The new version also allows defining the expected number of hosts for each tenant. This feature is particularly useful for service providers managing multiple clients from a single platform, helping control license and system distribution.

Kaspersky has not announced a change to the overall service model. MDR continues to operate as a managed service with 24-hour monitoring, with specialized analysts involved in detection, investigation, and incident response.

Kaspersky extends MDR to new embedded Linux systems

The update also adds support for Kaspersky Embedded Systems Security for Linux 4.0.

This extension allows MDR coverage of embedded Linux environments utilizing this security solution. Embedded systems are found in numerous specialized devices and infrastructure, often with different lifecycle and operational requirements than standard computers.

This broadens the range of devices from which the service can receive data and perform monitoring tasks, though the announced compatibility specifically pertains to Kaspersky’s Embedded Systems Security for Linux 4.0.

The company also notes minor platform and usability improvements, although details weren’t fully disclosed in the announcement.

This update comes as identities become a focal point in enterprise security. Password theft via phishing, specialized malware, database leaks, or credential reuse all enable attackers to gain access without directly attacking applications.

This introduces an additional challenge for detection systems: distinguishing between legitimate account owners and those who possess their credentials.

Authentication logs, location, device details, behavior, and other indicators help flag anomalies. External information indicating that an identity appeared in a leak further enhances this analysis.

Renat Turianov, Kaspersky MDR Product Manager, states that this integration allows for correlating compromised credential information with security events and proactively searching for signs of account compromise.

The practical value depends on the quality and currency of the intelligence, available telemetry, and how signals are combined during investigations. Overall, this update signals a clear shift in detection services: monitoring internal activity alone isn’t enough when credentials might be circulating outside the organization.

FAQs

What new features does Kaspersky MDR include?

It integrates Digital Footprint Intelligence to link leaked credential information with security events. It also adds asset status alerts, host limit management, and support for Kaspersky Embedded Systems Security for Linux 4.0.

What is Digital Footprint Intelligence?

Kaspersky’s intelligence service focused on analyzing an organization’s external digital exposure, including identifying compromised credentials found in data leaks.

Does a leaked credential mean a company has been attacked?

Not necessarily. The appearance of credentials in a leak indicates risk and warrants verification of their validity and further analysis of account activity and security events.

What does MDR mean in cybersecurity?

MDR stands for Managed Detection and Response. It combines monitoring technology with specialized analysts to continuously detect, investigate, and respond to threats.

Scroll to Top