<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Kaspersky Threat Data Feeds Suricata Rules?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>Suricata rule set</strong> – Roughly 5,000 IDS rules in Suricata compliant format.<br /> <strong>Daily rule updates</strong> – New and revised signatures published every single day.<br /> <strong>Threat category coverage</strong> – APT, botnet C&amp;C, crimeware, DNS tunnelling, ransomware, exploits.<br /> <strong>Detection name context</strong> – Each alert carries the Kaspersky detection name for triage.<br /> <strong>Certificate based delivery</strong> – Feed retrieved over HTTPS using an issued digital certificate.<br /> <strong>Important</strong> – No console, no agent and no detection engine included.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Kaspersky Threat Data Feeds Suricata Rules?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Kaspersky Threat Data Feeds Suricata Rules is a subscription rule feed rather than an installed product: it supplies signatures that your own Suricata, IDS, IPS or next generation firewall loads and executes. There is no Kaspersky management console and no agent, so policy, tuning and alert handling stay entirely inside the network security tooling you already operate.<br /><br /> <strong>Vendor independent deployment</strong> – Works with any Suricata compatible engine you already operate.<br /> <strong>No software installation</strong> – Text based rules only, no Kaspersky binaries on hosts.<br /> <strong>Faster alert triage</strong> – Detection names point analysts straight to the malware family.<br /> <strong>Tested before release</strong> – Rules pass a dedicated testing infrastructure to limit false positives.<br /> <strong>Network layer detection</strong> – Targets network threats that standard controls do not catch.<br /> <strong>Proven rule origin</strong> – The same rules Kaspersky uses in its own infrastructure.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Kaspersky Threat Data Feeds Suricata Rules suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The decisive question is not headcount but whether you already run a network sensor and have someone who reads its alerts. A rule feed produces alerts, not decisions, so an organisation without an IDS, IPS or NGFW in operation cannot use this product at all, regardless of size.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Usually</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Occasional</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Frequent</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Standard</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">IDS, IPS or NGFW already in operation</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Partial</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Partial</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Threat Data Feeds Suricata Rules meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The reporting obligation under the revised Information Security Act has applied since 1 April 2025 and affects operators of critical infrastructure, including energy and water utilities, transport operators, listed hospitals, data centres and cantonal and municipal administrations. Affected organisations must submit an initial report to the Federal Office for Cybersecurity (BACS) within 24 hours of discovering a cyberattack, with up to 14 days to complete missing details. This feed supports the detection half of that duty: alerts on botnet command and control traffic, DNS tunnelling or ransomware activity give you a timestamped technical observation and a named detection you can put into the initial report, which is usually the hardest part to produce inside a single day. It does not cover the rest of the obligation at all, because the feed contains no reporting workflow, no incident case management, no log retention and no escalation process, and it produces nothing whatsoever if you have no network sensor to run the rules on. Whether your organisation falls under the obligation and how you satisfy it in practice is a legal question, and this description is not legal advice.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Threat Data Feeds Suricata Rules meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No product makes an organisation compliant with the NIS 2 Directive, because the directive addresses management responsibility, risk analysis and organisational process rather than any single tool. NIS 2 requires categories of measure including risk analysis and information system security policies, incident handling, business continuity and crisis management, supply chain security, security in acquisition and development, vulnerability handling, and the use of cryptography and access control. This feed maps to a narrow slice of incident handling and detection: it raises alerts on malicious network traffic and supplies the detection context an analyst needs to classify what was seen. It contributes nothing to business continuity, backup, access control, cryptography, vulnerability handling, supplier assessment or staff training, and it provides no evidence of management oversight, which is the measure category buyers most often underestimate.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What should you know about official assessments of Kaspersky?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Germany's Federal Office for Information Security has warned against the use of Kaspersky virus protection software since 15 March 2022, and that warning is still in force, now governed by Section 13 of the amended BSI Act since 6 December 2025. The scope matters for this specific product: the warning addresses Kaspersky's antivirus software portfolio, and the authority's own FAQ states that no assessment was issued regarding other Kaspersky products. Separately, the United States Bureau of Industry and Security prohibited new sales of Kaspersky products in the United States from 20 July 2024 and added Kaspersky entities to the Entity List. Kaspersky rejects the German assessment as politically rather than technically motivated, and points out that its data feeds are text only, with all threat matching performed by the customer's own tools rather than by Kaspersky software. Switzerland has taken no comparable step: BACS has confirmed that no internal directive or prohibition on Kaspersky software exists, and that decisions rest with the individual federal office when contracts expire. Standard antivirus laboratory test results are not a useful reference point for this product, since a rule feed is not submitted to consumer detection testing. In practice this affects public sector tenders, organisations with a German parent or subsidiary, and buyers whose customers apply country of origin criteria in supplier reviews, while purely private organisations without such constraints face no legal restriction in Switzerland.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="norton-vs-kaspersky-2025"><strong>Norton vs. Kaspersky: Which antivirus program offers the best protection?</strong><br />A direct comparison of both vendors covering detection performance and the practical criteria buyers use to choose between them.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Threat Data Feeds Suricata Rules help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Partially, and only within one question block. It gives you a documented answer to items asking whether network intrusion detection is in place, whether you subscribe to an external threat intelligence source, how often detection content is updated, which you can answer with daily, and whether you can detect command and control and ransomware traffic by category. It answers none of the remaining blocks: endpoint protection, EDR and response actions, patch management, multi-factor authentication, disk encryption, backup and restore testing, log retention periods, access control reviews and staff awareness training all sit outside this product. One item deserves specific attention: many supplier questionnaires now ask about the country of origin of security vendors, and this product will not help you there and may create follow-up questions instead. The cheapest way to close the intelligence-side gaps is to extend within the same Kaspersky Threat Data Feeds family rather than mixing intelligence vendors, but the endpoint, backup and access control gaps cannot be closed inside this family and require separate products regardless.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="data-loss-backups-avoid-outages"><strong>Data loss is expensive: How backups help you avoid outages</strong><br />Explains why backup and restore testing is a separate requirement that detection tooling cannot satisfy on its own.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between the Suricata Rules Data Feed and the Sigma Rules Data Feed?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The decisive difference is where the rules execute. Suricata rules inspect live network traffic inside an IDS, IPS or NGFW, so they detect what crosses the wire and need a sensor positioned to see that traffic. Sigma rules describe detection logic for log and event data and therefore run inside a SIEM or log platform, detecting what your systems recorded rather than what they transmitted. The two are complementary rather than alternatives, and buyers choose based on which platform they already operate. Kaspersky publishes rule counts and update frequency for the Suricata feed but not for the Sigma feed, so the lower two rows are left unstated rather than estimated.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Property</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Suricata Rules Data Feed</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Sigma Rules Data Feed</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Detection runs on</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Network traffic</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Log and event data</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Platform required</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">IDS, IPS or NGFW</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">SIEM or log platform</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Rule format</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Suricata</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Sigma</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Published rule count</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Around 5,000</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Not published</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Published update frequency</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Daily</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Not published</td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The most important limitation is regional rather than technical: Kaspersky products cannot be sold into the United States following the prohibition effective 20 July 2024, so organisations with United States entities or United States federal customers should clarify their position before purchasing. Technically, the feed ships in detection mode by default, meaning rules alert rather than block, and converting to prevention is a decision you take and tune inside your own IPS with the operational risk that carries. Around 5,000 rules will produce alerts that someone has to read, so the feed generates work rather than removing it, and organisations without analyst capacity typically abandon it within weeks. Integration is not automatic either: the feed is delivered as text over HTTPS against an issued certificate and must be fetched, filtered and compiled into your engine, commonly using Kaspersky Feed Utility or CyberTrace, which is a small project rather than a setting. Finally, this product protects no endpoint, no mailbox and no server workload, and the follow-up purchase it most often triggers is endpoint protection that buyers wrongly assumed was included.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Covers why endpoint protection remains a separate requirement alongside network-level detection.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Kaspersky Threat Data Feeds Suricata Rules</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does any Kaspersky software have to be installed to use this feed?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No. Kaspersky supplies text based feeds only, and all threat matching is performed by your own tools. This is the reason the feed is used by organisations that would not deploy Kaspersky endpoint software.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does the feed work with next generation firewalls and PCAP tools?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes. Kaspersky states the rules are intended for network security appliances including intrusion detection and prevention systems, next generation firewalls and other network security or PCAP processing tools, provided they consume Suricata format rules.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">How are the rules delivered and kept current?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">After the order, Kaspersky issues a digital certificate that authorises download over an HTTPS based service. Kaspersky Feed Utility or CyberTrace then downloads, filters and compiles the daily updates so your engine always loads the current rule set.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-edr,compliance-ch-isg,compliance-supplier" data-audience="b2b" data-count="3"> </div>