LUCIDTextjet - Print logo

Kaspersky Threat Data Feeds Phishing URL

Short Description

Open HTML

What are the core benefits of Kaspersky Threat Data Feeds Phishing URL?
No console – Data feed managed inside your existing tools.
Phishing indicators – URLs and masks with context for matching.
Open formats – JSON, CSV, OpenIoC and STIX via HTTPS.
SIEM integration – Connectors for QRadar, Splunk and Sentinel.
Rich context – Threat name, popularity, geography and whois data.
Important note – No blocking, your own tools do matching.

Long Description

Open HTML

What is included in Kaspersky Threat Data Feeds Phishing URL?

Phishing URL records – URLs, hosts, domains and masks covering confirmed phishing resources.
Actionable context – Threat type, timestamp, popularity index, geography, IP and whois.
Near real-time updates – New records generated continuously from Kaspersky Security Network data.
Open delivery formats – JSON for enterprise, plus conversion to STIX, OpenIoC and CSV.
HTTPS and TAXII – Token-based TAXII access for the most popular feeds.
Important – No management console, no agent and no built-in reporting.

What are the main benefits of Kaspersky Threat Data Feeds Phishing URL?

Kaspersky Threat Data Feeds Phishing URL is a machine-readable feed of confirmed phishing URLs and URL masks, published as one of more than 25 feeds in the Kaspersky Threat Intelligence range. It has no console and no agent: you download the data over HTTPS or TAXII and your own SIEM, firewall or gateway performs the matching.

Proxy log matching – Check web and mail logs against confirmed phishing URLs.
Faster alert triage – Context fields answer who, what and where per record.
Lower SIEM load – CyberTrace matches events before they reach the SIEM.
Deny list feed – Dynamically updated block lists for firewalls and gateways.
No telemetry required – Kaspersky supplies text data; matching stays on your systems.
Vendor-neutral integration – Connectors for QRadar, Splunk, Sentinel, MISP and Suricata.

Which company size is Kaspersky Threat Data Feeds Phishing URL suitable for?

The deciding factor is not headcount but whether you already operate a system that can consume indicators. A company without a SIEM, next generation firewall or web gateway has nowhere to load the feed and gains nothing from it. Organisations that run a security operations function, or a service provider that does so on their behalf, are the realistic buyers.

RequirementSmall businessMedium-sized companyLarge company
Reporting obligation Switzerland Rarely By sector Often
NIS 2 in the European Union Rarely By sector Often
Security questionnaire from large customers Occasionally Often Standard
SIEM or gateway able to consume indicators ✕ Partial ✓
This product fits ✕ Limited ✓

Does Kaspersky Threat Data Feeds Phishing URL meet the requirements of Swiss cybersecurity legislation?

The Swiss reporting obligation does not apply to every company. Since 1 April 2025 the revised Information Security Act obliges operators of critical infrastructure, among them energy and drinking water suppliers, transport companies, listed hospitals, cloud and data centre providers and cantonal and municipal administrations, to report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further 14 days to complete the report. This feed supports that obligation at one point only: the context attached to each record, including threat type, timestamp, popularity index, top affected countries, resolved IP addresses and whois data, gives an analyst material for the initial assessment of whether a phishing hit is relevant enough to escalate. It does not detect the incident on its own, retains no evidence, and generates no report that could be submitted to BACS, because it has no console and no reporting component at all. It also covers phishing indicators only, so an attack arriving through a malicious attachment, a compromised server or stolen credentials will not appear in this feed. This text is not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal advisers.

Does Kaspersky Threat Data Feeds Phishing URL meet the requirements of European cybersecurity legislation?

No product makes a company compliant with the NIS 2 Directive, because the directive addresses organisational measures rather than software. NIS 2 requires essential and important entities to implement risk analysis and information system security policies, incident handling, business continuity, supply chain security, security in acquisition and development, procedures for assessing the effectiveness of measures, cyber hygiene and training, cryptography, access control and multi-factor authentication. This feed contributes to incident handling, by supplying detection tools with confirmed phishing indicators and enough context to triage an alert, and marginally to the assessment of effectiveness, since matches can be counted per intelligence source. It contributes nothing to business continuity, access control, cryptography, multi-factor authentication, staff training or supply chain governance, and it produces no documentation that an auditor could accept as evidence. Treat it as one input into an existing detection stack rather than as a measure in its own right.

What should you know about official assessments of Kaspersky?

Two official measures are in force and both are worth understanding precisely, because neither covers this product in the way buyers often assume. The German Federal Office for Information Security has warned against the use of Kaspersky virus protection software since 15 March 2022; the warning remains in force and has been regulated under Section 13 of the BSI Act since 6 December 2025. In the United States, the Department of Commerce issued a final determination on 20 June 2024 prohibiting new transactions from 20 July 2024 and signature updates, Kaspersky Security Network operation and resale from 29 September 2024 — but that determination expressly excludes Kaspersky Threat Intelligence products and services, which is the category this feed belongs to. Kaspersky rejects both assessments, states that the German warning was not based on an objective technical analysis of its software, and points to third-party audits and its transparency centres, one of which operates in Zurich. In Switzerland the Federal Office for Cybersecurity has issued no warning and no internal directive on Kaspersky products, and has stated that its technical assessment was not changed by the American ban, although Kaspersky software is no longer in use in the federal administration. In practice this matters most for public sector tenders, for companies with a German parent or German public sector customers, and for supply chain questionnaires that ask about the country of origin of security suppliers; for a privately held Swiss company running the feed inside its own SIEM, it is a procurement question rather than a technical one.

Norton vs. Kaspersky – Which antivirus program offers the best protection in 2025?
A side-by-side look at how the two vendors compare on detection performance and feature scope.

Does Kaspersky Threat Data Feeds Phishing URL help with security questionnaires from large customers?

Partly, and for a narrow set of items. It gives you a documented answer to questions about which commercial threat intelligence sources you subscribe to, how current your indicators are, how phishing indicators reach your detection tooling, and which integrations carry them, since the feed ships with connectors for QRadar, Splunk Enterprise Security, ArcSight ESM, RSA NetWitness, Azure Sentinel, MISP, Suricata and others. It answers nothing about multi-factor authentication, encryption, patch management, backup and restore testing, access control, incident response procedures, staff awareness training, business continuity or supplier risk management, and it provides no certification such as ISO 27001 or SOC 2. It will also prompt a question you may not have faced before, because many questionnaires now ask for the country of origin of security suppliers. To close the technical gaps, the cheaper route is usually to stay inside the same family, adding endpoint and detection coverage from the Kaspersky Next range and Kaspersky CyberTrace for triage, rather than assembling parts from several vendors; where the origin question is a hard requirement in your customer base, no product choice inside the family will resolve it.

What is the difference between Phishing URL Data Feed and Phishing URL Exact Data Feed?

The decisive difference is how records are written and what has to match them. The standard Phishing URL Data Feed uses URL masks, so a single record can cover many related phishing addresses, but masked records need the Kaspersky CyberTrace matching engine to be evaluated correctly. The Phishing URL Exact Data Feed contains exact URLs, hosts and domains instead, and is intended for direct integration into security controls and threat intelligence platforms where masks or CyberTrace cannot be used. Both carry the same context fields. If your SIEM, firewall or platform can only ingest literal indicators, the Exact feed is the one to buy.

PropertyPhishing URL Data FeedPhishing URL Exact Data Feed
Record type URLs and masks Exact URLs, hosts, domains
One record covers several addresses ✓ ✕
Needs CyberTrace matching engine For masks ✕
Direct import into any TI platform Partial ✓
Context fields included ✓ ✓

Which limitations should you know before buying?

This feed blocks nothing on its own. Kaspersky supplies text-based records only and all matching is performed by your tools, so without a SIEM, next generation firewall, proxy or mail gateway to load them into, the data has no effect. The masked records in the standard feed need the Kaspersky CyberTrace matching engine, and the free Community Edition of CyberTrace is capped at 250 events per second and one million loaded indicators across all sources, which the paid edition removes — a follow-up purchase that catches buyers out more often than any other. Coverage is confined to phishing web resources: malicious URLs, ransomware URLs, botnet command and control addresses, file hashes and vulnerabilities are separate feeds in the same range, each bought individually. No regional feature restriction applies to this feed itself, and it sits outside the American prohibition on Kaspersky cybersecurity software, but the German warning and public sector procurement rules described above may still rule the vendor out for some buyers regardless of technical fit.

Best antivirus? Why Windows Defender alone is not enough
Explains where built-in protection stops and why detection layers such as threat intelligence are added on top.

Frequently asked questions about Kaspersky Threat Data Feeds Phishing URL

Does Kaspersky CyberTrace have to be paid for separately?

CyberTrace is available in a free Community Edition, but it processes a maximum of 250 events per second and loads up to one million indicators from all threat intelligence sources combined, and it defaults to demo feeds with lower detection rates. Running commercial feeds such as this one in a production network requires the paid edition, which also adds multi-user and multi-tenancy handling for service providers.

What data does your organisation send to Kaspersky when using this feed?

None for the purpose of matching. Your systems download the feed over HTTPS or TAXII and compare it against your own logs locally, so the URLs and events being checked never leave your infrastructure. This is the main structural difference between a data feed and an endpoint product that reports telemetry back to the vendor.

Can the feed be used to block traffic automatically?

Yes, provided your equipment supports it. The records can be turned into a dynamically updated deny list for a next generation firewall, secure mail gateway or web gateway, or matched through network traffic analysis. The blocking decision and its enforcement remain entirely with your own device.

 

Meta Description

Machine-readable feed of phishing URLs and URL masks with context, delivered in JSON for integration into SIEM, firewalls and web gateways.

Keywords

Kaspersky Threat Data Feeds Phishing URL, Kaspersky, Kaspersky Threat Intelligence, threat intelligence feed, phishing url feed, indicators of compromise, siem integration, url masks

  

   

COMPANY NAME | First Name, Last name | Address | Phone 0000 - 00 00 00 | Email info@kundendomain.com

By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about 
cookies

I agree