What are the key advantages of Kaspersky APT Intelligence Reporting?
Portal access – Web subscription, no agent or management console.
Campaign reports – Technical analyses of targeted attack campaigns.
Compromise indicators – IOC sets in openIOC and STIX formats.
Hunting rules – YARA rules usable in your existing tooling.
Coverage mapping – ATT&CK mapping reveals gaps in current detection.
Important note – No protection, no blocking, analyst team required.
APT campaign reports – Technical analyses of targeted attack campaigns as they are found.
Indicators of compromise – IOC sets delivered in openIOC and STIX formats.
YARA rules – Ready-made hunting rules for your own detection tooling.
MITRE ATT&CK mapping – Actor TTPs mapped for gap analysis and detection tuning.
Threat Intelligence Portal – Web access with geo and industry filtering of reports.
Important – No protection agent, no console, nothing is blocked automatically.
Kaspersky APT Intelligence Reporting is a subscription intelligence service rather than protection software: it delivers written analyses of advanced persistent threat campaigns produced by the vendor's GReAT research team. Access runs through the Kaspersky Threat Intelligence Portal, so there is no agent to roll out and no management console to operate.
Non-public investigations – Subscribers see campaigns that are never published openly.
Faster alert triage – Actor context turns an unexplained alert into a named campaign.
Detection gap analysis – ATT&CK mapping shows which actor techniques you cannot see.
Regional relevance – Each report names affected industries and regions.
Two reading levels – Executive summary for management, technical detail for analysts.
Retrospective hunting – Published IOC sets let you search historic log data.
This service suits organisations that already employ someone whose job is to read threat intelligence and act on it. A company without an internal security analyst or a managed security provider will not get value from the subscription, because nothing in it acts on its own.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | By sector |
| NIS 2 in the European Union | Rarely | By sector | ✓ |
| Security questionnaire from large customers | ✓ | ✓ | ✓ |
| Own analyst team or SOC to act on reports | ✕ | Partial | ✓ |
| This product fits | ✕ | Partial | ✓ |
The Swiss reporting obligation applies to operators of critical infrastructure named in the revised Information Security Act, not to every Swiss company. Those operators must report a significant cyber attack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. This service helps with the work before that clock starts: actor profiles, indicators of compromise and YARA rules give analysts the material to recognise a targeted campaign and to describe attacker and method in the notification instead of filing an incomplete one. It does not detect the incident, it does not generate the notification, and it stores none of the log or telemetry data an investigation needs, so meeting the 24-hour deadline still depends entirely on your own monitoring and incident process. Companies outside the named sectors have no reporting duty, but frequently inherit comparable expectations through contracts with operators that do. This text is not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal counsel.
No product makes a company compliant with the NIS 2 Directive, which requires organisational measures from entities in the sectors it covers. Among those measures are risk analysis and information security policies, incident handling, business continuity, supply chain security, vulnerability handling, assessment of the effectiveness of the measures taken, and basic cyber hygiene and training. This subscription contributes to two of them: risk analysis, because reports identify which threat actors target your sector and region, and effectiveness assessment, because ATT&CK mapping shows which techniques your current detection would miss. It contributes nothing to incident handling execution, business continuity, access control, cryptography, supply chain auditing or staff training, and it is not evidence that any measure has been implemented. Treat it as an input to risk analysis, not as a control in its own right.
Two official assessments are relevant and both are still in force. The German Federal Office for Information Security (BSI) issued a formal warning in March 2022 against the use of Kaspersky antivirus software and confirmed in 2026 that it maintains the warning and that its stated reasons have not changed. The United States Department of Commerce issued a Final Determination in June 2024 prohibiting Kaspersky from supplying antivirus software and cybersecurity products or services to US persons, with the main prohibitions effective from 29 September 2024; that determination expressly excludes Kaspersky Threat Intelligence products and services, security training and purely informational or advisory services, which is the category this subscription falls into. Kaspersky describes the assessments as political rather than technically substantiated, operates a transparency centre in Zurich where source code can be reviewed, and has publicly demanded that the BSI withdraw its warning. Switzerland has issued no comparable warning: BACS does not publish product recommendations and has stated that no misuse of Kaspersky software in Switzerland has been reported to it. Independent laboratory testing covers Kaspersky protection products rather than this reporting service, so published test scores are not a useful signal here in either direction. In practice this matters most if you sell into the German public sector, operate under a German group IT policy, or answer supplier questionnaires that ask whether any vendor is subject to an official warning; for a Swiss company without that exposure it is a documentation question rather than a blocker.
Partly, and only in one narrow area. It answers items asking whether you maintain an external threat intelligence source, whether you track threat actors relevant to your sector and region, whether detection coverage is assessed against MITRE ATT&CK, and whether a process exists for ingesting external indicators of compromise. It answers nothing about endpoint protection, EDR, log retention, patch management, encryption, multi-factor authentication, backup, vulnerability scanning, incident response readiness, awareness training or certifications, and it produces no artefact you can attach as proof that a control is implemented. One restriction is easy to overlook: the product terms prohibit disclosure of the information contained in the reports, so report content cannot be forwarded to a customer or quoted in a tender document. Close the larger gaps within the same family first, since Kaspersky Threat Data Feeds, Threat Lookup and Digital Footprint Intelligence run on the same Threat Intelligence Portal and are usually cheaper to add than a second vendor with its own contract, security review and integration work.
The decisive difference is the threat category each subscription covers, not the depth or the delivery method. APT Intelligence Reporting covers state-linked and other highly targeted espionage campaigns, Crimeware Intelligence Reporting covers financially motivated malware campaigns aimed largely at financial institutions, and ICS Intelligence Reporting covers threats against industrial and operational technology environments. All three are separate subscriptions delivered through the same Kaspersky Threat Intelligence Portal, so buying one does not give access to the others. This listing covers the APT reporting subscription only.
| Criterion | APT Intelligence Reporting | Crimeware Intelligence Reporting | ICS Intelligence Reporting |
|---|---|---|---|
| Threat focus | Targeted espionage campaigns | Financially motivated malware | Industrial and OT threats |
| Typical reader | SOC and CTI analysts | Financial sector teams | Industrial operators |
| Delivery | Threat Intelligence Portal | Threat Intelligence Portal | Threat Intelligence Portal |
| Included in this listing | ✓ | ✕ | ✕ |
The most common misunderstanding is the biggest one: this subscription protects nothing. There is no agent, no scanning, no blocking and no management console, so it has to sit alongside endpoint protection, logging and a detection tool that can actually consume the indicators and YARA rules. Without an analyst or a managed security provider to read the reports and load the indicators into a SIEM or EDR platform, the subscription produces reading material and no measurable outcome. A regional point matters for international groups: because Kaspersky threat intelligence is expressly excluded from the United States prohibition while Kaspersky protection products are not, a Swiss group with a US subsidiary can subscribe to this service but cannot standardise on Kaspersky endpoint products across the whole group. Finally, the product terms restrict disclosure of report content, which rules out passing reports to customers, auditors or the public as part of your own reporting.
Reports are accessed through the Kaspersky Threat Intelligence Portal, with filtering by region and industry. Each report opens with an executive summary written for management, followed by the technical analysis with the associated indicators of compromise and YARA rules.
No. The product terms prohibit disclosure of the information contained in the reports, so the content cannot be shared outside the subscribing organisation. Check the current terms before planning to use any report material in a tender or audit response.
No. Indicators are supplied in the standard openIOC and STIX formats and the rules are standard YARA, so they can be loaded into the SIEM, EDR or hunting tooling you already run, whichever vendor supplies it.
Subscription reports on targeted attack campaigns, with indicators of compromise and YARA rules for your own tooling. Not protection software.
Kaspersky APT Intelligence Reporting, Kaspersky, Kaspersky Threat Intelligence, threat intelligence subscription, apt reports, threat actor profiles, indicators of compromise, yara rules, cyber threat intelligence
By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about cookies