LUCIDTextjet - Print logo

Kaspersky Threat Data Feeds Bundle

Short Description

Open HTML

What are the key advantages of Kaspersky Threat Data Feeds Bundle?
No console – Runs inside your existing SIEM, not standalone.
Five bundles – From URL only to Total Security.
Machine readable – JSON, CSV, OpenIoC and STIX formats.
Context included – Threat names, timestamps, geolocation and popularity per record.
Free platform – Kaspersky CyberTrace matches events without SIEM load.
Important note – No endpoint agent, no detection or blocking.

Long Description

Open HTML

What is included in Kaspersky Threat Data Feeds Bundle?

URL feeds – Malicious, phishing, ransomware and botnet C&C URLs in every bundle.
IP reputation feed – Suspect IP addresses, from the URL and IP bundle upwards.
Malicious hash feed – File hashes for Windows, Linux, macOS, Android and iOS.
Actionable context – Threat names, timestamps, geolocation and popularity on each record.
Four delivery formats – JSON, CSV, OpenIoC and STIX over HTTPS or TAXII.
Important – No agent, no console, no blocking; the matching stays yours.

Best antivirus? Why Windows Defender alone is not enough
Why indicator feeds and threat intelligence sit on top of endpoint protection rather than replacing it.

What are the main benefits of Kaspersky Threat Data Feeds Bundle?

Kaspersky Threat Data Feeds Bundle is a subscription to machine-readable indicator feeds that your own SIEM, firewall or threat intelligence platform consumes; it has no console and no agent of its own. Kaspersky supplies only text-based data and the matching is performed by your tools, so the feeds extend the detection coverage of systems you already run.

Alert triage – Context on each indicator speeds up first-line decisions.
Perimeter blocking – Feed URL and IP lists straight into firewalls.
Free matching engine – Kaspersky CyberTrace correlates events and cuts SIEM load.
Vendor independence – CyberTrace also ingests OSINT and other commercial feeds.
Multi-tenant use – One CyberTrace instance can separate several customer environments.
Retrospective search – Historical correlation rechecks past events against current feeds.

Which company size is Kaspersky Threat Data Feeds Bundle suitable for?

Tooling decides this more than headcount does. An organisation without a SIEM, without a firewall that accepts external indicator lists, and without someone who reads alerts gets nothing from a feed subscription at any size. The realistic buyer runs a security operations function already, or is a service provider running one for others.

RequirementSmall businessMedium-sized companyLarge company
Reporting obligation Switzerland Rarely By sector ✓
NIS 2 in the European Union ✕ By sector ✓
Security questionnaire from large customers Occasionally ✓ ✓
Own SIEM and analyst time to consume feeds ✕ Partial ✓
This product fits ✕ With a SIEM ✓

Does Kaspersky Threat Data Feeds Bundle meet the requirements of Swiss cybersecurity legislation?

The obligation applies to operators of critical infrastructure, not to every company: since 1 April 2025 the revised Information Security Act (ISG) requires them to report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further 14 days to complete the report. The feeds help at the discovery step and with the content of that report, because matching your logs against current indicators shortens the gap between a botnet callback and someone noticing it, and the context attached to each record supplies the threat name, timestamps and related indicators the report asks for. What the bundle does not do is detect anything by itself: with no agent, no telemetry and no alerting of its own, it produces nothing inside 24 hours if you have no log collection and nobody on duty. It also covers none of the organisational duties, so incident classification, the decision to report, and the follow-up report stay with your team. This text is not legal advice; whether your organisation falls under the reporting obligation should be clarified with a specialist.

Does Kaspersky Threat Data Feeds Bundle meet the requirements of European cybersecurity legislation?

No product makes a company NIS 2 compliant, because the directive addresses organisational measures and management accountability rather than a list of tools. NIS 2 requires essential and important entities to maintain risk analysis and security policies, incident handling, business continuity and crisis management, supply chain security, vulnerability handling and disclosure, cyber hygiene and training, cryptography, and access control, and to report significant incidents in stages. This subscription contributes to two of those categories: incident handling, by giving your detection tools current indicators and triage context, and vulnerability handling, but only in the Total Security bundle, which is the one that contains the Vulnerability Data Feed. It contributes nothing to business continuity, backup and recovery, supply chain security, encryption, access control or staff training. It also produces no reporting of its own, so any evidence an auditor asks for has to come from the SIEM or platform that consumes the feeds, not from the subscription.

Data loss is expensive: How backups help you avoid outages
Covers the business continuity and recovery measures that indicator feeds do not address at all.

What should you know about official assessments of Kaspersky?

Two authority decisions concern the vendor and both are still in force. Germany’s Federal Office for Information Security (BSI) has warned against the use of Kaspersky virus protection software since 15 March 2022, a warning now placed under section 13 of the BSI Act following the amendment of 6 December 2025; the BSI states that it has made no assessment of other Kaspersky products and that use of them is not prohibited in Germany. In the United States, the Department of Commerce issued a Final Determination in June 2024 prohibiting Kaspersky cybersecurity and anti-virus products, effective 20 July 2024 with signature updates ending 29 September 2024, and that determination expressly excludes Kaspersky threat intelligence, security training and advisory services that are purely informational or educational in nature, which is the category this subscription belongs to. Switzerland has issued neither a warning nor a ban: BACS has stated that no misuse of Kaspersky software has been reported to it in Switzerland and that it warns only where it holds confirmed technical indications. Kaspersky rejects the BSI warning as politically rather than technically grounded, refers to its data processing in Zurich under its Global Transparency Initiative, and in early 2026 formally demanded removal of the warning under section 13 of the BSI Act, reserving legal steps. Published comparative laboratory tests cover Kaspersky’s endpoint products rather than these data feeds, so they carry little weight either way for this product. In practice the assessments matter most if you sell into the public sector, hold contracts with German federal bodies, or answer supply chain questionnaires that ask about vendor country of origin, because there the vendor name can decide the outcome regardless of the technical content of the feed; for a private company with no such exposure, no legal restriction applies in Switzerland.

Norton vs. Kaspersky: Which antivirus program offers the best protection?
Compares the two vendors on independent laboratory detection results for their endpoint products.

Does Kaspersky Threat Data Feeds Bundle help with security questionnaires from large customers?

Yes, but for a narrow set of items only. It answers directly whether you use commercial threat intelligence and from which source, whether indicators are matched against your log data, and how current that indicator data is. It answers partly, if you run CyberTrace, which feeds actually generate detections, because feed usage statistics and the feed intersection matrix show the hit rate per source. It does not answer anything about endpoint protection coverage, patch levels, laptop encryption, multi-factor authentication, access control, backup and recovery testing, awareness training, or a documented incident response process, because the feeds are data rather than controls and a reviewer will score them that way. To close those gaps, moving up within one endpoint vendor’s own family is usually cheaper and produces fewer contradictions in the questionnaire than adding a second security vendor, since most questionnaire items concern endpoint and identity controls rather than intelligence sources.

What is the difference between the URL bundle and the Total Security bundle?

The decisive difference is which indicator types you receive: all five bundles contain the four URL feeds, and each step up adds a new category rather than more of the same data. URL and IP adds IP reputation, URL and IP and Hashes adds file hashes, Expert Security adds APT, crimeware and mobile indicators, and Total Security adds passive DNS, Suricata rules, open source software threats, IoT URLs and vulnerability data. In practice your tooling sets the level: a firewall or proxy can only use URL and IP data, while hash and YARA feeds need a SIEM or threat intelligence platform behind them. Only Total Security includes the Vulnerability Data Feed, which is the single bundle-level fact that changes how you can answer a vulnerability handling question.

Feeds inside the bundleURLURL & IPURL, IP & HashesExpert SecurityTotal Security
Malicious, phishing, ransomware, botnet C&C URLs ✓ ✓ ✓ ✓ ✓
IP reputation ✕ ✓ ✓ ✓ ✓
Malicious hashes ✕ ✕ ✓ ✓ ✓
APT and crimeware indicators, YARA rules ✕ ✕ ✕ ✓ ✓
Mobile malicious hash and mobile botnet ✕ ✕ ✕ ✓ ✓
Passive DNS, Suricata rules, open source threats, IoT URL ✕ ✕ ✕ ✕ ✓
Vulnerability Data Feed ✕ ✕ ✕ ✕ ✓

Which limitations should you know before buying?

The feeds are text only: Kaspersky supplies indicators and your own tools perform the matching, so nothing is detected or blocked unless you already run a SIEM, firewall, proxy or threat intelligence platform able to consume them. No feature is restricted to particular countries, but the vendor’s origin effectively is, because several governments restrict Kaspersky products in public sector procurement, which makes this a procurement question before it is a technical one. The licence covers use for your own infrastructure and your own employees, so passing the indicator data on, reselling it, or building it into a service you offer to your own customers is not included. The most frequent follow-up purchase is the next bundle level up, usually when a firewall-only deployment gains a SIEM and suddenly needs hash data; the second is analyst time, because indicator feeds raise alert volume before they reduce it.

Frequently asked questions about Kaspersky Threat Data Feeds Bundle

Which SIEM systems are supported?

Connectors for HP ArcSight, IBM QRadar and Splunk are included with the subscription. If you use Kaspersky CyberTrace as the matching layer, it additionally offers out-of-the-box integration with LogRhythm, RSA NetWitness and McAfee ESM, plus direct integration with firewalls, gateways and other log sources.

Do you have to use Kaspersky CyberTrace?

No. The feeds can be pulled directly into a SIEM, firewall or threat intelligence platform in JSON, CSV, OpenIoC or STIX over HTTPS or TAXII. CyberTrace, previously named Kaspersky Threat Feed Service, is free and performs the matching outside the SIEM, which is mainly worth it when indicator volume is pushing your SIEM licence or its event rate.

Can a managed service provider use the feeds for its customers?

CyberTrace supports multi-tenancy, so one instance can keep several customer environments separate and use different feeds per tenant. The feed licence itself, however, permits use for your own infrastructure and employees, and distributing or reselling the data to third parties is excluded, so a service provider arrangement has to be agreed with Kaspersky separately.

Can you check the data structure before committing?

Kaspersky supplies documentation and feed samples along with a dedicated technical account manager for the integration. Running the samples through your parser first is the practical way to confirm that the record fields and context you actually want are usable in your environment.

 

Meta Description

Machine-readable threat feeds for your own SIEM or firewall. Five bundle levels in JSON, CSV, OpenIoC or STIX. No endpoint agent included.

Keywords

Kaspersky Threat Data Feeds Bundle, Kaspersky, Kaspersky Threat Intelligence, threat intelligence feeds, indicators of compromise, siem integration, ip reputation, malicious url feed, stix format

  

   

COMPANY NAME | First Name, Last name | Address | Phone 0000 - 00 00 00 | Email info@kundendomain.com

By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about 
cookies

I agree