<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Kaspersky Threat Data Feeds Whitelisting?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>Whitelisting Data Feed</strong> – Systematic, continuously updated knowledge of legitimate software.<br /> <strong>Machine-readable formats</strong> – Delivered as JSON, CSV, OpenIoC or STIX files.<br /> <strong>HTTPS and TAXII delivery</strong> – Pulled by your own systems on a schedule.<br /> <strong>SIEM and TIP support</strong> – QRadar, ArcSight, Splunk, MISP and other platforms supported.<br /> <strong>Vetted source data</strong> – Aggregated from Kaspersky Security Network and research teams.<br /> <strong>Important</strong> – No console, no agent and no blocking function included.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Kaspersky Threat Data Feeds Whitelisting?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Kaspersky Threat Data Feeds Whitelisting is a subscription to one feed within the Kaspersky Threat Intelligence family, and it delivers data about known-legitimate software rather than software itself. There is no management console: the feed is downloaded by your own SIEM, threat intelligence platform or Kaspersky CyberTrace, and the matching happens there.<br /><br /> <strong>Fewer false positives</strong> – Known-good objects are filtered before analysts see them.<br /> <strong>Faster alert triage</strong> – Analysts stop re-analysing files already proven non-malicious.<br /> <strong>Lower SIEM workload</strong> – Fewer events reach the correlation and storage layer.<br /> <strong>Text-only delivery</strong> – No executable code runs inside your infrastructure.<br /> <strong>Vendor-neutral integration</strong> – Usable without any Kaspersky endpoint product installed.<br /> <strong>Supports application control</strong> – Feeds allowlist decisions in third-party solutions and services.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Kaspersky Threat Data Feeds Whitelisting suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">This is a security operations product, not a small-business product. It only pays off if someone in your organisation already runs a system that ingests indicator data and matches it against events. A company without a SIEM or threat intelligence platform has nothing to feed it into.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Sometimes</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Own SIEM or threat intelligence platform</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Sometimes</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Limited</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Threat Data Feeds Whitelisting meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No single security product meets the requirements of the revised Information Security Act (ISG) on its own. Since 1 April 2025, operators of critical infrastructure in Switzerland must report qualifying cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further 14 days to complete a first report that was necessarily incomplete. The 24-hour deadline is a triage problem before it is a reporting problem, and this is where the feed contributes: removing files already proven legitimate from the alert queue shortens the time analysts need to decide whether an event is a reportable incident. What the feed does not do is detect the attack, generate the report, record who discovered what and at which time, or retain evidence for the follow-up submission — those come from your monitoring platform, your endpoint protection and your documented incident process. This text is general product information and not legal advice; whether your organisation falls under the reporting obligation should be clarified with qualified legal counsel.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Threat Data Feeds Whitelisting meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No product creates NIS 2 compliance, and any vendor claiming otherwise is describing a marketing position rather than the directive. The NIS 2 Directive requires essential and important entities to implement risk-management measures covering incident handling, network and information system security, supply chain security, business continuity, and the reporting of significant incidents. This feed touches one narrow part of that: it improves the signal-to-noise ratio in security monitoring, so that events worth escalating are easier to separate from routine activity. It contributes nothing to incident handling workflows, access control, encryption, continuity planning, staff training or supplier risk assessment, and it generates no audit trail by itself. Treat it as an input that improves a detection capability you already operate, not as a measure you can present on its own.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What should you know about official assessments of Kaspersky?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">In Switzerland, the Federal Office for Cybersecurity (BACS) does not issue recommendations for or against individual products and has published no warning concerning Kaspersky; it has stated that it would inform the public if it received confirmed evidence of misuse. In Germany, the Federal Office for Information Security (BSI) has warned against the use of Kaspersky virus protection software since 15 March 2022. That warning is still in force in 2026, it relates specifically to antivirus software rather than to Kaspersky's full portfolio, and Kaspersky has publicly disputed it, pointing to its Swiss data storage, its transparency centres and the absence of any confirmed incident, and signalling legal steps in early 2026 if the warning is not withdrawn. In the United States, the Department of Commerce issued a Final Determination on 20 June 2024 prohibiting Kaspersky from supplying antivirus software and cybersecurity products to US persons, with resale, integration and licensing prohibited from 29 September 2024. One detail in that determination matters directly here: it explicitly does not apply to Kaspersky Threat Intelligence products and services that are purely informational in nature, which is the category this feed belongs to. In practice this affects three groups of buyers — organisations with US entities or US-person contractual obligations, German public sector bodies and organisations that follow BSI guidance, and any supplier whose large customers screen vendor country of origin in procurement. Independent detection tests from the AV laboratories cover Kaspersky's endpoint engines and say nothing about a text data feed, so they are not a useful signal for this product either way. The decision is yours to make against your own contractual and sector requirements.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="norton-vs-kaspersky-2025"><strong>Norton vs. Kaspersky – Which antivirus program offers the best protection in 2025?</strong><br />A side-by-side look at how the two vendors compare on detection performance and features.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Threat Data Feeds Whitelisting help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Partly, and only in one section of a typical questionnaire. It gives you a concrete answer to items asking whether you use external threat intelligence sources, whether your monitoring uses reputation data from a source outside your own environment, and whether you take active steps to reduce alert fatigue in triage. It answers nothing else. Questions about endpoint protection coverage, patch status, encryption of mobile devices, backup and restore testing, multi-factor authentication, access reviews, log retention periods, incident response times and staff awareness training are all untouched, and so is any question asking you to produce evidence or reports, because this product generates none. There is also a question type where the feed can work against you: some questionnaires ask you to declare the country of origin of your security suppliers, and a Russian-headquartered vendor will require an explanation regardless of how the product is delivered. If the gaps are what you actually need to close, a broader Kaspersky Threat Intelligence subscription covering malicious indicator feeds and reporting will usually cost less and cause fewer integration problems than assembling equivalent coverage from several vendors.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between the Whitelisting Data Feed and the malicious indicator feeds?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The decisive difference is direction: the Whitelisting Data Feed tells your systems what is known to be safe, while the malicious feeds tell them what is known to be dangerous. That means the whitelisting feed cannot detect anything on its own — it can only suppress noise generated by something else. Buyers who purchase it expecting detection coverage have bought the wrong feed. Both are delivered in the same machine-readable formats and both require a matching engine on your side, so the integration work is the same either way.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Property</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Whitelisting Data Feed</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Malicious indicator feeds</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">What the records describe</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Legitimate software</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Malicious objects</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Primary purpose</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Suppress false positives</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Raise detections</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Usable alone as a detection source</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Delivery formats</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">JSON, CSV, STIX</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">JSON, CSV, STIX</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Requires your own matching engine</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The most common follow-up purchase is the matching layer itself: the feed is text data, and something has to compare it against your event stream, which in practice means an existing SIEM, a threat intelligence platform, or Kaspersky CyberTrace as a separate component. The second is scope — this feed reduces noise but adds no detection, so a security operations centre buying it in isolation still needs the malicious indicator feeds to gain coverage. On regional availability, the US Final Determination against Kaspersky expressly excludes purely informational threat intelligence products, but a US entity in your group should still confirm its own position before you deploy, and organisations following German BSI guidance will need an internal justification even though that warning addresses antivirus software rather than data feeds. Finally, Kaspersky's current public feed overview promotes a different subset of its 25-plus feeds and does not list the whitelisting feed by name, so confirm the exact current package with your distributor before you plan an integration around it.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Explains where built-in protection leaves gaps and which layers a company still has to add itself.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Kaspersky Threat Data Feeds Whitelisting</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does this feed replace application control or allowlisting software?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No. Application control software enforces a policy on an endpoint and blocks what is not permitted. This feed supplies reference data about legitimate software that such a system, or a third-party service, can consult when making that decision. The enforcement component remains something you buy and operate separately.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What happens if a legitimate file is not in the feed?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Nothing is blocked, because the feed does not block. An unlisted file simply receives no known-good confirmation, so it stays in the queue and is handled by your normal analysis process. In-house applications, custom scripts and freshly compiled binaries will routinely fall into this category, which is worth accounting for when you estimate how much triage volume the feed will actually remove.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-edr,compliance-supplier,compliance-ch-isg" data-audience="b2b" data-count="3"> </div>