What are the key advantages of Kaspersky Threat Data Feeds - APT IOC?
No Console – Data subscription consumed by your existing SIEM.
Four Feeds – APT hash, IP, URL and YARA indicators.
SIEM Connectors – ArcSight, QRadar and Splunk connectors are included.
Retrospective Hunting – YARA rules search files already on disk.
Open Formats – JSON output converts to STIX, OpenIOC and CSV.
Important note – No agent, console or blocking function included.
Download: Kaspersky Threat Data Feeds APT IOC
APT Hash Data Feed – Hashes of malicious artefacts used in APT campaigns.
APT IP Data Feed – IP addresses tied to targeted attack infrastructure.
APT URL Data Feed – Web addresses used in advanced persistent threat campaigns.
APT Yara Data Feed – YARA rules for hunting targeted attack files locally.
SIEM Connectors – Included connectors for ArcSight, QRadar and Splunk.
Important – No agent, console or blocking function is included.
Kaspersky Threat Data Feeds - APT IOC is a subscription to four machine-readable indicator feeds covering advanced persistent threat campaigns. There is no console and no management model of its own: the data is pulled over HTTPS and consumed by the SIEM, threat intelligence platform or firewall you already operate.
GReAT Research Origin – Indicators produced by Kaspersky's targeted attack research team.
Machine Readable Formats – JSON output with conversion to STIX, OpenIOC and CSV.
Retrospective Threat Hunting – YARA rules find targeted attack files already stored.
Faster Alert Triage – Vetted indicators cut noise when correlating SIEM events.
Vendor Neutral Use – Works with third-party SIEMs, firewalls and IDS systems.
Authenticated Delivery – HTTPS download secured with a Kaspersky client certificate.
The deciding factor is not headcount but whether someone reads the alerts. Feed data only becomes useful once a SIEM or threat intelligence platform is in operation and a person or service provider triages the matches it generates.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rare | By sector | By sector |
| NIS 2 in the European Union | Rare | By sector | ✓ |
| Security questionnaire from large customers | ✓ | ✓ | ✓ |
| SIEM or threat intelligence platform in operation | ✕ | Sometimes | ✓ |
| This product fits | ✕ | With SOC or MSSP | ✓ |
The reporting obligation applies to operators of critical infrastructure, not to every company: since 1 April 2025 the amended Information Security Act requires them to report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with the remaining details following within 14 days. APT IOC supports that deadline in one narrow way, because a feed match gives the analyst the campaign name and indicator context needed to describe the incident in the initial report instead of filing it as an unclassified event. It does not detect anything by itself; it only evaluates log data your existing systems already forward. It supplies no incident timeline, no forensic evidence, no case handling and no reporting workflow, so the 14-day follow-up still has to be assembled from your SIEM, endpoint tooling and incident documentation. It also does nothing to establish whether your organisation falls within one of the sectors covered. This text is a product description and not legal advice; whether the reporting obligation applies to your organisation should be clarified with qualified legal counsel.
No product creates NIS 2 compliance, because the directive addresses organisational measures rather than software features. NIS 2 requires essential and important entities to maintain risk analysis and security policies, incident handling, business continuity and crisis management, supply chain security, vulnerability handling and disclosure, and procedures to assess whether the measures actually work. APT IOC contributes to incident handling, by adding targeted-attack indicators and context to the detection layer, and it contributes to effectiveness assessment only in the sense that feed matches show where monitoring produces results. It does nothing for continuity, backup, crisis management, access control, staff training or the governance duties the directive places on management bodies. Supply chain security is likewise untouched, since the feed describes external attacker infrastructure and says nothing about the security posture of your own suppliers.
In June 2024 the US Department of Commerce Bureau of Industry and Security issued a Final Determination prohibiting Kaspersky from entering new agreements with US persons from 20 July 2024, and from providing signature and codebase updates or operating the Kaspersky Security Network in the United States from 29 September 2024. Reselling and integrating Kaspersky cybersecurity software in the US is prohibited under the same determination, and three Kaspersky entities were added to the Entity List. The measure remains in force. The German Federal Office for Information Security issued a warning in 2022 recommending replacement of Kaspersky antivirus software; it is a recommendation and not a sales ban, and Germany has not prohibited sales. Kaspersky's own position is that the US determination was based on the geopolitical climate rather than an evaluation of its products, and the company has stated that the decision does not affect its ability to sell threat intelligence offerings and trainings in the US. Kaspersky also processes threat-related data from European users in two Zurich data centres and operates a Transparency Centre there where authorised partners can review code and detection rules. In practical terms this matters most to organisations with US entities or US government contracts, and to suppliers whose customers apply country-of-origin rules in procurement; for other buyers in Switzerland and the European Union, sale and use are not restricted.
Partly, and only in a narrow band. It gives a documented answer to the items asking whether you subscribe to commercial threat intelligence, whether external indicators are correlated against your log data, whether you can detect targeted attacks rather than only commodity malware, and whether you can search retrospectively for known attacker artefacts, which the YARA feed makes possible against stored files. It answers nothing on endpoint protection coverage, patch status, disk encryption, multi-factor authentication, backup and restore times, access reviews, awareness training or supplier management, and those items appear on almost every questionnaire. To close the feed-side gaps, staying inside the same family is usually the cheaper route: the Expert Security and Total Security bundles add the Crimeware IOC and Mobile Threat feed sets, and Total Security adds Passive DNS, Suricata rules, open source software threats, IoT URL and vulnerability data. The endpoint, patching and encryption items cannot be answered with feed data at all and need an endpoint product such as the Kaspersky Next line instead.
The decisive difference is the attacker being described: APT IOC covers indicators from targeted, campaign-driven intrusions attributed to advanced persistent threat actors, while Crimeware IOC covers financially motivated commodity crime such as banking trojans and ransomware operations. That difference changes who benefits, because APT indicators are low-volume and high-consequence, whereas crimeware indicators are high-volume and hit far more often in an average network. APT IOC is also the only one of the two that includes a dedicated IP feed. Both are contained in the Expert Security and Total Security bundles, so buying both separately is worth checking against a bundle. If your SOC currently sees mainly generic malware alerts and has never worked a targeted intrusion, Crimeware IOC will usually produce more matches per month.
| Feed content | APT IOC | Crimeware IOC |
|---|---|---|
| Hash feed | ✓ | ✓ |
| URL feed | ✓ | ✓ |
| IP feed | ✓ | ✕ |
| YARA rules | ✓ | ✓ |
| Contained in Expert Security bundle | ✓ | ✓ |
| Contained in Total Security bundle | ✓ | ✓ |
APT IOC delivers data, not protection: there is no agent, no console and no blocking function, so a SIEM, threat intelligence platform or firewall must already be running before the subscription produces anything usable. On regional availability, the US Department of Commerce prohibition restricts Kaspersky cybersecurity products for US persons, so organisations with US subsidiaries or US contracts should verify their position before feeding this data into systems operated there, while sale and use in Switzerland and the European Union are unaffected. The APT feeds are published in JSON, and STIX, OpenIOC, Snort, CSV and plain text are produced through a Kaspersky conversion tool, which means one scripted step in most ingest pipelines; TAXII delivery is confirmed for the most popular feeds only, so it should be checked for the APT set before you design around it. Use of the data is limited to protecting your own infrastructure and your own employees, and passing feed content to third parties is not permitted, which rules out a service provider reusing one subscription across client tenants. The most common follow-up purchase is the paid Kaspersky CyberTrace edition, which removes the event and indicator processing limits of the free community version.
Kaspersky sends a digital certificate by encrypted email within five working days of the order, and the feeds are then downloaded through an HTTPS-based service using that certificate for client authorisation. There is no installer and nothing is deployed on endpoints.
Connectors for HP ArcSight, IBM QRadar and Splunk are included with the Threat Data Feeds subscription. For other SIEMs and log sources, Kaspersky CyberTrace acts as the matching layer and accepts feeds in JSON, STIX, XML and CSV.
Yes. Any platform that can ingest the JSON output, or one of the converted formats, can consume the feeds directly. CyberTrace is optional and mainly serves to perform the indicator matching outside the SIEM, which reduces the event volume the SIEM has to correlate itself.