Kaspersky Updates a Flagship SIEM Platform With Generative AI Capabilities
Kaspersky has released version 4.6 of its Kaspersky Unified Monitoring and Analysis Platform (KUMA), a SIEM platform designed for centralized collection and analysis of cybersecurity events and attack detection.

The update introduces support for external large language models compatible with the OpenAI API, allowing organizations to deploy them either in the cloud or entirely within their own infrastructure without transferring operational data outside the protected environment. KIRA, the platform's AI assistant, can now automatically generate regular expressions from event logs. The release also adds a unified knowledge base containing correlation and normalization rules, accelerates the delivery of ready-to-use detection rule packages for newly emerging threats, and expands integrations with file storage systems and database management systems.
Generative AI Comes to Cybersecurity Operations
The release expands the capabilities of one of Russia's leading SIEM platforms rather than introducing a new product category. It reflects a broader shift toward strengthening existing cybersecurity technologies. For the industry, the update provides another example of how generative AI is being integrated into cybersecurity operations. Automating log analysis and rule creation reduces the workload on security operations centers, speeds up the onboarding of new data sources, and makes the platform easier for junior analysts to use.
The update is unlikely to have a direct impact on everyday users, although it can strengthen the security posture of businesses and government organizations that handle sensitive information. It also supports the continued development of Russia's cybersecurity ecosystem and is particularly relevant for organizations that require all data processing to remain inside a protected environment without sending information to external services.

Faster Delivery of Detection Rules
KUMA is evolving from a SIEM focused primarily on event collection into an intelligent assistant for security analysts. Looking ahead, AI could explain why alerts were triggered, generate investigation queries, prepare incident reports, and recommend response actions.
These capabilities are particularly valuable amid the ongoing shortage of cybersecurity professionals. Automating routine tasks reduces the workload on security operations centers and allows analysts to focus on complex investigations. The platform's flexibility also enables organizations to connect different language models, choose between cloud-based and on-premises deployments, and tailor implementations to industry-specific requirements.
Another significant improvement is the faster delivery of detection rules, reducing the time required to respond to newly emerging threats.
Russia's SIEM market continues to grow as cyberattacks increase and organizations replace foreign products with domestic alternatives. At the same time, the platform's export potential is tied to countries that prioritize local data storage, provided the solution is localized and supported by an appropriate partner ecosystem.

Russian SIEM Platforms Continue to Evolve
Kaspersky released KUMA 2.1 in 2023, introducing updated event storage, support for the 1C enterprise software platform, improved fault tolerance, enhanced threat detection capabilities, and lower hardware requirements.
Later that year, Russian Standard Bank migrated to KUMA, and the platform confirmed compliance with GosSOPKA requirements through a data exchange module integrated with NKTsKKI.
In 2024, version 3.4 introduced the KIRA AI assistant to help analysts, including those new to cybersecurity, analyze security events more efficiently. At the same time, R-Vision launched SIEM 2.0 with expanded analysis and visualization capabilities, highlighting a broader trend toward improving the usability and functionality of Russian cybersecurity platforms.
Development continued throughout 2025 and 2026. KUMA 4.0 migrated its AI assistant to GigaChat 2.0 while strengthening attack detection capabilities. Version 4.2 added scenarios for detecting credential theft and further expanded KIRA's functionality. Over that period, the platform evolved from an event correlation system into a SIEM platform with integrated generative AI and support for external language models.

Verifying the Results
The KUMA 4.6 update reflects the growing adoption of generative AI in the day-to-day operations of security monitoring centers. Among its most significant additions are automatic generation of regular expressions from event logs, support for connecting external language models, and the ability to deploy those models either in the cloud or within a customer's own infrastructure.
Over the next several years, competition among SIEM platforms is likely to shift from core data collection capabilities toward the quality of AI assistants, the depth of knowledge bases, and the level of investigation automation. Future development is expected to focus on automatic generation of correlation rules, automated incident reporting, response recommendations, and deeper integration with SOAR and XDR platforms.
AI will remain an assistive technology rather than a replacement for human expertise. Errors in interpreting security events or configuring detection rules can lead to missed attacks or higher false-positive rates. Human oversight, validation of AI-generated results, and secure local deployment of language models will therefore remain essential.









































