<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Kaspersky Threat Data Feeds?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>Network indicator feeds</strong> – Malicious, phishing and botnet C&amp;C URLs with masks and hosts.<br /><strong>IP reputation feed</strong> – Suspicious and malicious IP addresses with threat context.<br /><strong>Malicious hash feeds</strong> – File hashes covering Windows, Linux, macOS, Android and iOS.<br /><strong>APT and Crimeware IOC</strong> – Hash, URL, IP and YARA indicators from Kaspersky research.<br /><strong>Specialist data feeds</strong> – Passive DNS, IoT URLs, Suricata rules, vulnerability and open source data.<br /><strong>Important</strong> – No agent, no console; your tools do the matching and blocking.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Kaspersky Threat Data Feeds?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Kaspersky Threat Data Feeds is a subscription to machine-readable indicator lists that you download over HTTPS and load into your own SIEM, firewall or threat intelligence platform. Kaspersky documentation also refers to the same service as Kaspersky Threat Intelligence Data Feeds, and the matching tool that goes with it, Kaspersky CyberTrace, was previously called Kaspersky Threat Feed Service.<br /><br /><strong>Faster alert triage</strong> – Context on each record shows which alerts deserve escalation.<br /><strong>Lower SIEM load</strong> – CyberTrace matches events externally instead of inside the SIEM.<br /><strong>Blocklists for firewalls</strong> – Dynamic deny lists feed NGFW, proxy and mail gateways.<br /><strong>Vendor neutral formats</strong> – JSON, CSV, STIX and OpenIoC avoid tool lock-in.<br /><strong>Ready made connectors</strong> – QRadar, ArcSight, Splunk, MISP, Sentinel and Suricata are supported.<br /><strong>Nothing leaves your network</strong> – Kaspersky supplies text only; matching happens on your side.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Kaspersky Threat Data Feeds suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The deciding factor is not headcount but whether someone in your organisation already operates a SIEM, a threat intelligence platform or a next generation firewall with dynamic deny lists. Without one of those, the feeds have nothing to match against and produce no output at all.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Sometimes</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">SIEM, TIP or NGFW already in operation</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Partial</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Limited</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Threat Data Feeds meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The reporting obligation under the revised Information Security Act applies to operators of critical infrastructure, among them energy and drinking water utilities, transport companies, listed hospitals, cloud and data centre providers, and cantonal and communal administrations. Since 1 April 2025 these organisations must report a qualifying cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further 14 days to complete the report. Kaspersky Threat Data Feeds supports that deadline in one specific way: each record carries context such as the threat name, timestamps, resolved IP addresses and geolocation, which is the material an analyst needs to describe what was observed and when. It does not detect the incident for you, it produces no incident timeline, no forensic evidence and no report form, and it stores no case history, so the report itself is still assembled from your SIEM, your endpoint tooling or an incident response provider. It also covers none of the organisational duties, such as naming responsible persons or maintaining an escalation process. This text is not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal advisers.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Threat Data Feeds meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No software product makes an organisation compliant with the NIS 2 Directive, because the directive addresses management responsibility and processes rather than tooling. NIS 2 requires essential and important entities to put in place risk analysis and security policies, incident handling, business continuity and crisis management, supply chain security, vulnerability handling and disclosure, procedures to assess the effectiveness of measures, cyber hygiene and training, cryptography, access control, asset management and multi-factor authentication. Kaspersky Threat Data Feeds contributes to three of those categories: incident handling, through indicator matching and alert prioritisation; vulnerability handling, through the Vulnerability Data Feed; and supply chain security, through the Open Source Software Threats Data Feed used inside a build pipeline. It contributes nothing to access control, multi-factor authentication, cryptography, business continuity, backup, staff training, asset inventory or policy documentation, and it protects no endpoint, server or mailbox. Treat it as one input to a detection process that must already exist.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What should you know about official assessments of Kaspersky?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Two official measures are relevant and both are still in force. Germany's Federal Office for Information Security (BSI) has warned against the use of Kaspersky antivirus software since 15 March 2022 and recommends replacing it with alternative products; following the German NIS 2 implementation act that took effect on 6 December 2025, the warning is now issued under Section 13 BSIG. The BSI states that the warning concerns the antivirus software portfolio and that it has made no statement about other products in the range. In the United States, the Department of Commerce (BIS) issued a Final Determination on 20 June 2024 prohibiting Kaspersky from providing antivirus and cybersecurity products or services to US persons, with the full effect from 29 September 2024; that determination expressly does not apply to Kaspersky Threat Intelligence products and services, Kaspersky Security Training, or consulting and advisory services that are purely informational or educational in nature. Kaspersky's own position is that the BSI warning is not justified and was not based on a technical analysis of its software, and it points to its Global Transparency Initiative, under which threat-related data from European users has been processed in two Zurich data centres since November 2018 and source code reviews are offered at its Transparency Centres. Practically, this matters most to public sector buyers, defence and critical infrastructure suppliers, and any company whose customers impose country-of-origin rules on security vendors; a private Swiss company with no such contractual requirements is affected differently from a cantonal administration. One technical detail belongs in this decision: the feeds are text files that you download, and Kaspersky states that matching must be performed by your own tools, so no software from the vendor runs on your systems and no telemetry is returned to Kaspersky through this product.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="norton-vs-kaspersky-2025"><strong>Norton vs. Kaspersky – Which antivirus program offers the best protection in 2025?</strong><br />A side-by-side look at how the two vendors compare on detection quality, features and practical use.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Threat Data Feeds help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Partly, and only in the detection section. It gives you a documented answer to questions such as whether you subscribe to commercial threat intelligence, whether indicators of compromise are matched against your log data, whether you monitor open source components used in development, and whether you receive structured vulnerability information. The feed usage statistics in CyberTrace also let you show which sources actually produced detections, which is more convincing than naming a supplier. It answers none of the following, and questionnaires ask about all of them: endpoint and server protection, EDR or managed detection, patch management, disk encryption, multi-factor authentication, privileged access control, backup and restore testing, log retention periods, awareness training, an incident response retainer, and certification against ISO 27001 or similar. Be aware that many enterprise and public sector questionnaires now include a vendor origin or authority warning question, which this product does not remove; see the section above. The cheapest route to closing the technical gaps is usually to stay in one family rather than mixing vendors, so pair the feeds with a Kaspersky Next tier for endpoint and EDR coverage and with CyberTrace or a SIEM for the matching layer, instead of buying a second intelligence subscription.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between the URL Bundle and the Total Security Feeds Bundle?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The single decisive difference is that the URL Bundle only tells you about dangerous web addresses, while the Total Security Feeds Bundle adds file-level and adversary-level intelligence. Kaspersky publishes five bundles: URL, URL &amp; IP, URL &amp; IP &amp; Hashes, Expert Security and Total Security. The Expert Security bundle is the point at which APT, Crimeware and mobile threat indicators appear, and the Total Security bundle adds passive DNS, Suricata rules, IoT URLs, vulnerability data and open source threat data on top. If your use case is a firewall or proxy deny list, the URL Bundle is sufficient; if your use case is SOC investigation and attribution, the lower bundles will leave you without hashes and YARA rules. The table below compares three of the five.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Feeds inside the bundle</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">URL</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">URL + IP + Hashes</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Total Security</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Malicious, phishing, ransomware and botnet C&amp;C URL</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">IP reputation</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Malicious hashes</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">APT and Crimeware IOC, including YARA</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Mobile malicious hash and mobile botnet</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Passive DNS, Suricata rules, IoT URL, vulnerability, open source</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The most common cause of a follow-up purchase is the matching layer: the feeds are raw indicator files, and something has to compare them against your logs. Kaspersky CyberTrace exists in a free community version for this, but the paid edition adds the research graph, indicator database and multi-tenancy that service providers usually end up needing. On regional availability, the US prohibition issued by the Department of Commerce excludes Kaspersky Threat Intelligence products from its scope, but Kaspersky wound down its US operations from July 2024, so US-based entities of an international group should confirm supply before standardising on the feeds; the German BSI warning applies to the antivirus portfolio and is a procurement question rather than a technical one in Switzerland and most of the European Union. Feed coverage is uneven across bundles, and the indicators that investigators most often want, APT and Crimeware hashes with YARA rules, sit in the two highest bundles only. Finally, update intervals differ per feed rather than being uniformly real time: URL feeds refresh roughly every 10 to 20 minutes, botnet C&amp;C and vulnerability data hourly, and open source threat data every few hours.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Explains why a single protection layer leaves gaps and what a layered setup adds in practice.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Kaspersky Threat Data Feeds</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Threat Data Feeds replace antivirus or EDR?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No. The feeds contain no protection engine, install nothing on a workstation or server, and block nothing by themselves. They supply indicators to security controls you already run, so an endpoint or EDR product remains a separate purchase.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="antivirus-programs-windows-2025"><strong>We help you decide. Test: Antivirus program: Best antivirus programs for Windows 2025</strong><br />A comparison of current Windows antivirus products to help you pick the protection layer the feeds sit on top of.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Do I need Kaspersky CyberTrace to use the feeds?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Not strictly. Any tool that can consume JSON, CSV, STIX or OpenIoC will work, including QRadar, ArcSight, Splunk, Azure Sentinel, MISP, ThreatConnect, EclecticIQ and Suricata. CyberTrace is Kaspersky's own matching engine and is worth considering mainly because it performs the correlation outside the SIEM, which keeps event licence consumption and indexing load down.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Is any of our data sent to Kaspersky when we use the feeds?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Kaspersky states that it supplies text-based feeds only and that threat matching is performed by the customer's own tools. The data flow is a one-way download over HTTPS, so your log data and detection results stay inside your infrastructure.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-edr,compliance-ch-isg,compliance-nis2" data-audience="b2b" data-count="3"> </div>