Skip to main content

Kaspersky SIEM updated with AI-driven threat detection and enhanced customization

January 22, 2026

The new version features an AI-enabled mechanism for detecting potential account compromise, enhanced data integrity, and improved customization, empowering organizations with stronger, more flexible security.

According to a recent global survey conducted by Kaspersky, Security Information and Event Management (SIEM) platforms rank among the top three most in-demand cybersecurity solutions for companies planning to establish a Security Operations Center, with 40% of organizations considering it an essential technological component for building an advanced cybersecurity division. In response to this market need, Kaspersky has regularly upgraded its SIEM with new, valuable features designed to enable advanced threat detection capabilities and better compliance with industry standards and regulation. In the latest update the following new key capabilities were added:

Flexible role model for customization

The new system allows users to create, clone, and modify roles to better align with internal workflows and organizational needs. This enhancement offers greater flexibility, enabling companies to tailor the system to their unique structures.

Correlator 2.0 Beta and AI-enabled account theft detection

The fault-tolerant, horizontally scalable Correlator 2.0 is now available in beta mode. This upgrade delivers significant improvements in performance and reduces hardware requirements.

It also introduces advanced features, such as AI-powered detection of account theft, which analyzes login activity, establishes baseline patterns, and identifies abnormal behavior to generate timely alerts for potential account compromises. This feature enhances an organization’s security and operational efficiency.

Backup and restore events for data integrity and compliance

The new functionality supports exporting event data into secure, immutable archive files, safeguarding data during investigations, audits, and regulatory compliance processes - ensuring data remains unaltered.

Background search queries for enhanced user experience

Background search processing allows analysts to initiate low-priority queries that run quietly in the background. This allows users to continue their work without interruption, with search results available immediately upon completion, drastically improving usability and operational efficiency.

“At Kaspersky, our ongoing commitment is to refine and expand the capabilities of our products to stay ahead of evolving cyber threats. By harnessing innovative AI technologies in Kaspersky SIEM, we can streamline complex data analysis and automate essential processes, empowering cybersecurity professionals to concentrate on investigating sophisticated incidents and implementing proactive security measures. These improvements significantly bolster organizational resilience and ensure robust protection against emerging threats,” states Ilya Markelov, Head of Unified Platform Product Line at Kaspersky.

Kaspersky SIEM collects, aggregates, analyzes and stores log data across the entire IT infrastructure, delivering contextual enrichment for cybersecurity teams. The platform leverages a dedicated User and Entity Behavior Analytics (UEBA) ruleset that helps identify deviations from established behavioral patterns, facilitating the timely detection of APTs, targeted attacks, and insider threats. Additionally, the rule mapping on the platform has been regularly updated to align with the latest versions of MITRE ATT&CK.

To learn more about Kaspersky SIEM, please visit the website.

Kaspersky SIEM updated with AI-driven threat detection and enhanced customization

The new version features an AI-enabled mechanism for detecting potential account compromise, enhanced data integrity, and improved customization, empowering organizations with stronger, more flexible security.
Kaspersky logo

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. Innovating the industry with a Cyber Immunity approach, Kaspersky safeguards consumers, businesses, critical infrastructure, and governments from cyberthreats, with over a billion devices protected to date.

Kaspersky ensures Cybersecurity True to Business, focusing on providing clear outcomes, protecting revenue, easing workloads and preventing downtime. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services for organizations of every size, from small businesses to large enterprises, combining proven AI-driven protection technologies with simple management and expert support.

Recognized in independent tests and trusted by millions of individuals worldwide and nearly 200,000 organizations, Kaspersky helps detect threats earlier, respond faster and operate with greater confidence and freedom, protecting what matters most to our clients. Learn more at www.kaspersky.com.

Related Articles Press Releases