What are the key advantages of Kaspersky APT & Crimeware Intelligence Reporting?
Portal delivered – Accessed through a web portal, no agent installed.
Two tracks – APT and crimeware reports in one bundle.
Ready indicators – IoCs, YARA and Suricata rules with every report.
Actor profiles – TTPs mapped to the MITRE ATT&CK framework.
Archive access – All earlier private reports remain available while subscribed.
Important note – Contains no protection, detection or blocking function.
APT report track – Ongoing Kaspersky investigations into targeted and state-sponsored campaigns.
Crimeware report track – Analysis of ransomware and financially motivated malware campaigns.
Threat actor profiles – Aliases, malware families and TTPs mapped to MITRE ATT&CK.
Machine readable indicators – IoCs in openIOC and STIX, plus YARA and Suricata rules.
Portal and API – Filterable report archive with RESTful API for workflow integration.
Important – No agent, no console and no protection or blocking function.
Kaspersky APT & Crimeware Intelligence Reporting is an intelligence service that bundles the two report tracks Kaspersky previously sold on their own as Kaspersky APT Intelligence Reporting and Kaspersky Crimeware Intelligence Reporting. It is consumed entirely through the Kaspersky Threat Intelligence Portal, so there is nothing to install and no management console to run.
Pre-disclosure visibility – Technical detail on campaigns before public reporting appears.
Detection engineering input – Ready YARA and Suricata rules your analysts deploy directly.
Faster triage context – Attribution and TTP mapping shorten investigation of unclear alerts.
Relevance filtering – Filter by targeted industry, country, actor and release date.
Retrospective archive access – All previously issued private reports remain available while subscribed.
Board level summaries – Each report opens with an executive summary for management.
The deciding factor is not headcount but whether anyone in the organisation reads threat reports as part of their job. Intelligence has no automated effect: IoC lists, YARA rules and actor profiles only change your security posture once an analyst loads them into a detection platform.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rare | By sector | Often |
| NIS 2 in the European Union | Rare | By sector | Usually |
| Security questionnaire from large customers | Occasional | ✓ | ✓ |
| Own SOC or security analyst | ✕ | Partial | ✓ |
| This product fits | ✕ | Limited | ✓ |
The Swiss reporting obligation applies to operators of critical infrastructure, not to every company: the revised Information Security Act names organisations such as energy and drinking water suppliers, transport companies, listed hospitals, cloud and data centre providers, and cantonal and communal administrations. Those operators must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovering it, with a further period to complete the initial report. This service supports precisely those first 24 hours, because actor profiles, IoCs and MITRE ATT&CK mapping let an analyst establish whether observed activity matches a known campaign, which is the classification a first report calls for. What it does not do is detect the attack, retain logs or produce the report: the service holds no telemetry from your environment and generates no evidence trail, so detection and logging must come from an endpoint, EDR or SIEM product. Report content is additionally marked under the Traffic Light Protocol and onward disclosure is prohibited, so findings may inform your report while the reports themselves stay internal. This text is a purchasing aid and not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal counsel.
No product makes a company NIS 2 compliant, because the directive addresses organisational measures, governance and management accountability rather than a software feature list. NIS 2 requires essential and important entities to establish risk analysis and information security policies, incident handling, business continuity and backup, supply chain security, vulnerability handling and disclosure, procedures to assess whether measures are effective, cyber hygiene and training, cryptography, and access control including multi-factor authentication. This service contributes to three of those categories: risk analysis, because reports can be filtered by targeted industry and country; incident handling, because attribution and TTP mapping speed up classification; and vulnerability handling, because reports describe exploits observed in live campaigns. It contributes nothing to business continuity, backup, cryptography, access control, multi-factor authentication, asset management or staff training, and it neither detects nor contains an incident. Buyers who need those categories covered should treat this as an addition to a protection and detection stack rather than a replacement for one.
The United States Department of Commerce issued a Final Determination on 20 June 2024 that barred Kaspersky from entering new agreements with US persons from 20 July 2024 and from supplying anti-virus signature and codebase updates in the United States from 29 September 2024, and added three Kaspersky entities to the Entity List. Germany's Federal Office for Information Security has warned against the use of Kaspersky virus protection software since 15 March 2022. Both measures are still published and in force. Kaspersky rejects both, describes the US decision as a reflection of the geopolitical climate rather than an evaluation of its products, has said it will pursue the legal options open to it, and has stated publicly that the determination does not affect its ability to sell threat intelligence offerings and training in the United States. Two distinctions matter when assessing this particular product: both measures are directed at anti-virus and protection software rather than at intelligence reporting, and neither constitutes a Swiss or EU-wide sales ban, so the service is sold normally in Switzerland and the European Union. In practice the measures affect you if you hold US federal contracts, sell into the US public sector, or answer supply chain requirements from customers who exclude Russian-headquartered vendors by policy; where none of those apply, the choice rests on technical and commercial grounds.
Partly, and only within one section of a typical questionnaire. It answers items on external threat intelligence sources, use of a recognised threat framework, threat actor awareness for your sector and region, and whether detection logic is updated from external intelligence, since YARA and Suricata rules are delivered with the reports. It answers nothing on endpoint protection coverage, EDR deployment and log retention, patch levels, disk encryption, multi-factor authentication, backup and recovery testing, incident response arrangements or certification such as ISO 27001, and those items make up the bulk of most questionnaires. One point regularly catches buyers out: report content is TLP-marked and disclosure is prohibited, so you can state that you subscribe to a commercial intelligence service, but you cannot attach the reports themselves as evidence. To close the operational gaps, moving up within the Kaspersky Threat Intelligence family is usually cheaper than adding a second vendor, since the wider Threat Intelligence bundles add Threat Lookup, cloud sandboxing and Digital Footprint Intelligence, while the Kaspersky Next line covers the endpoint, EDR and reporting items questionnaires actually ask about.
The single decisive difference is industrial coverage. Kaspersky APT & Crimeware Intelligence Reporting contains the APT and Crimeware tracks only, while Kaspersky APT & Crimeware & Industrial Intelligence Reporting adds the ICS Threat Intelligence Reporting track with MRTI. Everything else, including actor profiles, MITRE ATT&CK mapping and machine readable indicators, is the same in both. If your environment includes production lines, building control, energy or water technology, the industrial bundle is the correct starting point, because ICS vulnerability analysis cannot be added to the smaller bundle later without changing product.
| Scope | APT & Crimeware | APT & Crimeware & Industrial |
|---|---|---|
| APT Intelligence Reporting | ✓ | ✓ |
| Crimeware Intelligence Reporting | ✓ | ✓ |
| ICS Threat Intelligence Reporting with MRTI | ✕ | ✓ |
| Actor profiles and MITRE ATT&CK mapping | ✓ | ✓ |
| Suited to OT and control networks | ✕ | ✓ |
This is an intelligence service, not a security product: it detects nothing, blocks nothing and installs nothing, so it only returns value once someone on your side reads and applies the reports. The industrial track is not part of this bundle, and buying ICS coverage afterwards means changing to the larger bundle rather than adding a component, which is the most common follow-up purchase in this category. Report content is marked under the Traffic Light Protocol and onward disclosure is prohibited, which rules out passing report material to customers or filing it in audit documentation. On regional availability, the US prohibition described above is the first thing to check if you operate in the United States, while in Switzerland and the European Union the service is sold without restriction. Reports are written for analysts, so an organisation without a SOC, a managed security provider or at least one dedicated security engineer will not get value out of IoC lists and YARA rules.
No. The service is delivered through the Kaspersky Threat Intelligence Portal and works independently of which vendor supplies your endpoint protection. Because indicators are issued in standard formats, they can be loaded into a third-party EDR or SIEM without a Kaspersky agent anywhere in the environment.
Reports are available as PDF, indicators of compromise in openIOC and STIX, and detection logic as YARA and Suricata rules. Consolidated master YARA and master IoC downloads cover all reports at once, and a RESTful API is available for automated retrieval.
Yes. Retrospective access to all previously issued private reports is provided for the duration of the subscription. The archive can be filtered by targeted industry, geolocation, threat actor, release date and report type.