<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Kaspersky Threat Data Feeds Malicious URL?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>Malicious URL masks</strong> – URL masks covering malicious websites and web pages.<br /> <strong>Actionable context</strong> – Threat names, timestamps, geolocation, resolved IP addresses, popularity.<br /> <strong>JSON delivery</strong> – Enterprise feeds output JSON, retrieved over TAXII with token.<br /> <strong>Format conversion tool</strong> – Converts JSON to STIX, OpenIoC, Snort, CSV, plain text.<br /> <strong>Out-of-the-box integrations</strong> – QRadar, ArcSight, Splunk, Sentinel, MISP, Suricata and more.<br /> <strong>Important</strong> – No agent, no console, no matching engine is included.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="antivirus-programs-windows-2025"><strong>We help you decide. Test: Antivirus program: Best antivirus programs for Windows 2025</strong><br />Compares protection products for Windows endpoints, which this feed enriches but does not replace.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Kaspersky Threat Data Feeds Malicious URL?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Kaspersky Threat Data Feeds Malicious URL is a subscription to one indicator feed from the Kaspersky Threat Data Feeds portfolio, which Kaspersky documentation also lists under the name Kaspersky Threat Intelligence Data Feeds. There is no console and no agent: you point your SIEM, firewall, web gateway or threat intelligence platform at the feed, and your own tools carry out the matching.<br /><br /> <strong>Earlier detection</strong> – Kaspersky states feed indicators appear before comparable OSINT sources.<br /> <strong>Lower SIEM load</strong> – CyberTrace matches events locally instead of inside your SIEM.<br /> <strong>Automatic blocking</strong> – Dynamically updated deny lists feed next generation firewalls directly.<br /> <strong>Faster alert triage</strong> – Context lets analysts rank alerts without opening separate lookups.<br /> <strong>Vendor neutral data</strong> – Text only feed, no Kaspersky software on your systems.<br /> <strong>Portfolio expansion</strong> – The portfolio holds over 25 feeds using identical delivery.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Kaspersky Threat Data Feeds Malicious URL suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The decisive question is not headcount but whether you already run a system that can consume indicators. Without a SIEM, a threat intelligence platform, a next generation firewall or a secure web gateway, the feed has nothing to match against and delivers no value.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<thead>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
</thead>
<tbody>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rare</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Out of scope</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">In scope</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Occasionally</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Standard</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">SIEM or threat intelligence platform in operation</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Partial</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Partial</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Threat Data Feeds Malicious URL meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The reporting obligation introduced by the revised Information Security Act applies to operators of critical infrastructure, among them energy and drinking water suppliers, transport companies, listed hospitals, cloud and data centre providers, and cantonal and communal administrations, with exemptions for smaller organisations set out in the Cybersecurity Ordinance. Since 1 April 2025 those organisations must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, and complete the report within a further 14 days. The feed supports this deadline in one narrow way: matching proxy, firewall and mail gateway logs against known malicious URLs shortens the time between the first suspicious connection and the moment someone can say what was contacted, which is exactly the information a 24-hour initial report needs. It does not cover the rest of the obligation, because it detects nothing on the endpoint itself, produces no incident record, has no case management, and cannot generate the report. You still need a SIEM or an incident process to turn a feed match into a documented finding, and a protection product on the affected system to establish what actually executed. This text is not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal counsel.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Threat Data Feeds Malicious URL meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No product creates compliance with the NIS 2 Directive, because the directive addresses organisational risk management rather than any single tool. NIS 2 requires categories of measures including risk analysis, incident handling, business continuity, supply chain security, security in the acquisition and maintenance of network and information systems, cyber hygiene and training, and access control. This feed maps to a narrow slice of incident handling, specifically the detection and enrichment step, by supplying indicators that a SIEM or gateway can match against live traffic. It contributes nothing to business continuity, access control, training, or governance, and it is not a supply chain security measure in itself. Buyers assessing NIS 2 readiness should treat the feed as an input to a detection process that must already exist, not as a measure that closes a requirement.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What should you know about official assessments of Kaspersky?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Two official measures are relevant and both are still in force. In March 2022 the German Federal Office for Information Security (BSI) issued a public warning against the use of Kaspersky antivirus software, reasoning that antivirus software holds deep intervention rights and therefore requires trust in the manufacturer; the warning is now regulated under Section 13 BSIG and the BSI confirmed in early 2026 that it maintains it. In June 2024 the US Department of Commerce issued a Final Determination prohibiting Kaspersky from supplying antivirus software and cybersecurity products in the United States, with resale and integration by US persons prohibited from 29 September 2024. One detail matters directly for this product: the US determination explicitly excludes Kaspersky Threat Intelligence products and services from the prohibition, and Kaspersky stated at the time that the decision does not affect its ability to sell threat intelligence offerings in the United States. Kaspersky's own position is that these measures reflect the geopolitical situation rather than a technical evaluation of its products. Switzerland has taken no comparable step: BACS does not issue recommendations on individual products and has stated that no misuse of Kaspersky software has been reported to it. Practically, this affects buyers in public sector procurement, buyers with US group entities, and buyers whose large customers exclude Russian-origin suppliers by contract. A technical distinction is worth noting when you assess it: the BSI warning concerns software installed on your systems, whereas this product is a text-based indicator feed with matching performed by your own tools, so the deployment model the warning is built on does not apply in the same way.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="norton-vs-kaspersky-2025"><strong>Norton vs. Kaspersky – Which antivirus program offers the best protection in 2025?</strong><br />Sets Kaspersky against an alternative vendor if the origin question is a factor in your decision.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Threat Data Feeds Malicious URL help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Partly, and only on a small number of items. It gives you a documented answer to questions about the use of external threat intelligence, about indicator sources feeding your monitoring, and about automated blocking of known malicious destinations at the perimeter, because you can name a commercial feed, its update cadence and the control it feeds. It answers nothing on endpoint protection, patch status, encryption, backup, access control, logging retention, incident response procedures or supplier governance, and it produces no report you can attach as evidence, since it emits indicators rather than findings. There is a second, less obvious gap: some questionnaires ask for the country of origin of security suppliers, and a Russian-origin vendor will trigger a follow-up question regardless of the product type, so plan for that answer rather than being surprised by it. To close the technical gaps, adding further feeds from the same Kaspersky Threat Data Feeds portfolio is usually cheaper than adding a second intelligence vendor, because delivery, format and integration stay identical; the reporting and endpoint gaps, however, need a protection product and a SIEM, not more feeds.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between Malicious URL Data Feed and Malicious URL Exact Data Feed?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The decisive difference is the indicator format and therefore what your tooling has to be capable of. This product, the mask-based feed, ships URL masks and is designed for matching through Kaspersky CyberTrace or through network traffic analysis in a next generation firewall or gateway. The Exact variant ships exact URLs, hosts and domains, and exists precisely for the case where masks and the CyberTrace matching engine cannot be used, such as direct import into a SIEM or a third-party threat intelligence platform. If your platform can only ingest literal indicators, the mask feed will underperform and the Exact feed is the correct purchase.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<thead>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Property</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Malicious URL Data Feed</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Malicious URL Exact Data Feed</th></tr>
</thead>
<tbody>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Indicator format</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">URL masks</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Exact URLs and hosts</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Matching engine needed</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Designed for CyberTrace</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Not required</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Direct import into a TIP</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Limited</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Typical placement</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Firewall and NTA</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">SIEM and gateways</td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">This is not a protection product and cannot block anything on its own: it is a list of indicators, and every detection or block happens inside equipment you already own and operate. The mask format is the most common source of disappointment, because platforms that only accept literal URLs will not match masks correctly and need the Exact variant instead. On regional availability, the feed itself is not region-limited in the way vendors sometimes restrict features to the United States and United Kingdom, but the surrounding legal position differs by market: the US prohibition on Kaspersky cybersecurity software does not extend to threat intelligence products, while the German BSI warning against Kaspersky antivirus software remains in force, so buyers with US or German group entities should confirm internal policy before purchase rather than after. Finally, demo feeds exist but deliver lower detection rates than the commercial version, so a demo evaluation will understate real coverage.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Explains why perimeter indicator matching still needs a protection layer on the endpoint itself.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Kaspersky Threat Data Feeds Malicious URL</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Is Kaspersky CyberTrace required to use this feed?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Not strictly, but the mask-based feed is designed around it. CyberTrace performs the parsing and matching outside your SIEM and forwards only confirmed hits with context, which is the intended way to use masks; a next generation firewall or gateway doing network traffic analysis can also consume them. Platforms that cannot handle masks need the Exact variant instead.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Is a demo version available for evaluation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Kaspersky provides demo feeds for a number of its data feeds, and demo access to the TAXII server is available to registered users of the Threat Intelligence Portal with a dedicated token. Demo feeds have lower detection rates than their commercial counterparts, so treat them as an integration test rather than a coverage test.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-edr,compliance-ch-isg,compliance-nis2" data-audience="b2b" data-count="3"> </div>