Newsroom

Artificial Intelligence against DLL hijacking: new capabilities of Kaspersky SIEM

October 8, 2025, Manila Vibe

Kaspersky has addressed this with a major update to its Kaspersky SIEM, enhancing efficiency and reducing the time needed to manage a cyber incident. It introduces AI to detect DLL hijacking. Given the 74% spike in APT cases last year, this matters more than ever. The system now integrates with Kaspersky’s Digital Footprint Intelligence and MDR services, offering a 360° view of threats and faster response times. Comments from Ilya Markelov, Head of the Unified Platform Product Line at Kaspersky, were carried out as part of the coverage.

The updated Kaspersky SIEM now features AI functionality for detecting signs of dynamic link library (DLL) hijacking, provides integration with Kaspersky Digital Footprint Intelligence (DFI) and Kaspersky Managed Detection and Response (MDR) and enables better capabilities for working with dashboards and reports.

According to the latest Kaspersky MDR analyst report, Advanced Persistent Threats (APTs) significantly affected one in four companies in 2024, representing a remarkable 74% increase compared to 2023. The findings highlight that, despite advancements in automated detection technologies, persistent attackers continue to exploit vulnerabilities and bypass defenses. To address these challenges and enhance threat detection capabilities, Kaspersky has upgraded its Kaspersky SIEM by integrating new and valuable features designed to enhance overall efficiency of cybersecurity systems.

Kaspersky SIEM collects, aggregates, analyzes and stores log data across the entire IT infrastructure, delivering contextual enrichment and actionable threat intelligence insights. In the latest update, this platform was enhanced by the following capabilities:

Enhanced protection against DLL hijacking

Legitimate software loads numerous libraries during operation, which can be exploited by attackers to evade detection and execute cyberattacks. To address this threat, Kaspersky SIEM has introduced a specialized AI-based subsystem that continuously analyzes information about all loaded libraries. In cases of suspected substitution, the system automatically annotates the event, enabling security teams to create incidents for further investigation. To leverage this new functionality, users can simply connect a DLL Hijacking enrichment rule to the collector or correlator, enhancing the system’s ability to detect and respond to potential library substitution threats effectively.

Integration with Digital Footprint Intelligence and Managed Detection and Response

Kaspersky SIEM now offers seamless integration with Kaspersky Digital Footprint Intelligence, enabling users to receive comprehensive analytics related to digital footprint data. This enhancement ensures that user account and password leaks are promptly detected, with automated alerts generated to facilitate immediate response. Incidents identified through this integration can be further investigated within the SIEM system, enhancing overall security posture.

Additionally, the solution now supports automatic incident import from the Managed Detection and Response (MDR) Console directly into the SIEM, streamlining incident processing and analysis for faster and more efficient threat management.

Improved behavioral analysis

Kaspersky SIEM has been further enhanced with the integration of a dedicated User and Entity Behavior Analytics (UEBA) ruleset, specifically designed for the comprehensive detection of anomalies across authentication processes, network activity and process execution on Windows-based workstations and servers. This addition enables Kaspersky SIEM to more effectively analyze deviations from established behavioral patterns, thereby facilitating the timely identification of APTs, targeted attacks and insider threats.

New capabilities for reporting

Dashboards and report templates can now be shared and transferred between Kaspersky SIEM installations, facilitating seamless collaboration and consistency across security environments. This functionality also enables users to receive updates directly from Kaspersky, ensuring that security teams have access to the most current content for comprehensive organizational cybersecurity analysis.

In addition, new data visualization widgets have been introduced, offering advanced capabilities for presenting information. Users can now display data as trends, combine multiple graphs and illustrate relationships between different values, thereby enhancing the clarity and effectiveness of security insights.

Furthermore, a new pre-configured widget has been added, featuring the ability to create refined queries. This is complemented by a drill-down capability, allowing users to navigate from a dashboard into another pre-configured dashboard for more detailed analysis.

Higher availability and scalability

Kaspersky has introduced a distributed Raft-based architecture for its SIEM Core, designed to deliver high availability and resilience. Such an approach ensures continuous operation under heavy loads and allows organizations to scale horizontally with ease.

“At Kaspersky, we are continuously improving our SIEM platform to ensure its detection capabilities against sophisticated threats are consistently enhanced. We aim to reduce the workload on cybersecurity professionals, enabling them to dedicate more time to analyzing complex cyber incidents and implementing preventive measures. Leveraging advanced AI technologies, we automate numerous processes and expedite the analysis of large data volumes. This advancement significantly reinforces organizational security and resilience against emerging threats,” comments Ilya Markelov, Head of Unified Platform Product Line at Kaspersky.

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. With over a billion devices protected to date from emerging cyberthreats and targeted attacks, Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services to protect businesses, critical infrastructure, governments and consumers around the globe. The company’s comprehensive security portfolio includes leading endpoint protection, specialized security products and services, as well as Cyber Immune solutions to fight sophisticated and evolving digital threats. We help nearly 200,000 corporate clients protect what matters most to them. Learn more at www.kaspersky.com.


Acronis Partners with iSecure Networks to Expand Cyber Protection Across the Philippines

Manila, PHILIPPINES – 13 June, 2025 — Acronis, a global leader in cybersecurity and data protection, has announced a strategic partnership with iSecure Networks, Inc. (ISN), appointing the company as a Cloud Distributors in the Philippines. This alliance is set to accelerate the availability of advanced, integrated cyber protection solutions to managed service providers (MSPs) and businesses across the country.

Acronis Drives Cybersecurity Leadership with Over 7.5 Million Attacks Prevented, Continuous Growth, Innovation, and Industry Recognition

SCHAFFHAUSEN, Switzerland – April 15, 2025 – Acronis , a global leader in cybersecurity and data protection, solidifies its position as a cybersecurity leader through significant milestones, a broadened global user base, and new product releases and enhancements. Over the past year, Acronis has prevented more than 7.5 million attacks, demonstrating the proactive defense capabilities of its technologies.

Gen Z’s favorite games used as bait in over 19 million attempted cyberattacks

From April 1, 2024 to March 31, 2025, Kaspersky detected over 19 million attempts to download malicious or unwanted files disguised as popular Gen Z games. With GTA, Minecraft and Call of Duty among the most exploited, it's clear that cybercriminals are actively following gaming trends to reach their targets. To help players stay safe, Kaspersky is launching “Case 404” — an interactive cybersecurity game that teaches Gen Z how to recognize threats and protect their digital worlds while doing what they love: playing.