What are the key advantages of Kaspersky Threat Data Feeds Bundle?
No console – Runs inside your existing SIEM, not standalone.
Five bundles – From URL only to Total Security.
Machine readable – JSON, CSV, OpenIoC and STIX formats.
Context included – Threat names, timestamps, geolocation and popularity per record.
Free platform – Kaspersky CyberTrace matches events without SIEM load.
Important note – No endpoint agent, no detection or blocking.
Download: Kaspersky Threat Data Feeds Bundle
URL feeds – Malicious, phishing, ransomware and botnet C&C URLs in every bundle.
IP reputation feed – Suspect IP addresses, from the URL and IP bundle upwards.
Malicious hash feed – File hashes for Windows, Linux, macOS, Android and iOS.
Actionable context – Threat names, timestamps, geolocation and popularity on each record.
Four delivery formats – JSON, CSV, OpenIoC and STIX over HTTPS or TAXII.
Important – No agent, no console, no blocking; the matching stays yours.
Kaspersky Threat Data Feeds Bundle is a subscription to machine-readable indicator feeds that your own SIEM, firewall or threat intelligence platform consumes; it has no console and no agent of its own. Kaspersky supplies only text-based data and the matching is performed by your tools, so the feeds extend the detection coverage of systems you already run.
Alert triage – Context on each indicator speeds up first-line decisions.
Perimeter blocking – Feed URL and IP lists straight into firewalls.
Free matching engine – Kaspersky CyberTrace correlates events and cuts SIEM load.
Vendor independence – CyberTrace also ingests OSINT and other commercial feeds.
Multi-tenant use – One CyberTrace instance can separate several customer environments.
Retrospective search – Historical correlation rechecks past events against current feeds.
Tooling decides this more than headcount does. An organisation without a SIEM, without a firewall that accepts external indicator lists, and without someone who reads alerts gets nothing from a feed subscription at any size. The realistic buyer runs a security operations function already, or is a service provider running one for others.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | ✓ |
| NIS 2 in the European Union | ✕ | By sector | ✓ |
| Security questionnaire from large customers | Occasionally | ✓ | ✓ |
| Own SIEM and analyst time to consume feeds | ✕ | Partial | ✓ |
| This product fits | ✕ | With a SIEM | ✓ |
The obligation applies to operators of critical infrastructure, not to every company: since 1 April 2025 the revised Information Security Act (ISG) requires them to report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further 14 days to complete the report. The feeds help at the discovery step and with the content of that report, because matching your logs against current indicators shortens the gap between a botnet callback and someone noticing it, and the context attached to each record supplies the threat name, timestamps and related indicators the report asks for. What the bundle does not do is detect anything by itself: with no agent, no telemetry and no alerting of its own, it produces nothing inside 24 hours if you have no log collection and nobody on duty. It also covers none of the organisational duties, so incident classification, the decision to report, and the follow-up report stay with your team. This text is not legal advice; whether your organisation falls under the reporting obligation should be clarified with a specialist.
No product makes a company NIS 2 compliant, because the directive addresses organisational measures and management accountability rather than a list of tools. NIS 2 requires essential and important entities to maintain risk analysis and security policies, incident handling, business continuity and crisis management, supply chain security, vulnerability handling and disclosure, cyber hygiene and training, cryptography, and access control, and to report significant incidents in stages. This subscription contributes to two of those categories: incident handling, by giving your detection tools current indicators and triage context, and vulnerability handling, but only in the Total Security bundle, which is the one that contains the Vulnerability Data Feed. It contributes nothing to business continuity, backup and recovery, supply chain security, encryption, access control or staff training. It also produces no reporting of its own, so any evidence an auditor asks for has to come from the SIEM or platform that consumes the feeds, not from the subscription.
Two authority decisions concern the vendor and both are still in force. Germany’s Federal Office for Information Security (BSI) has warned against the use of Kaspersky virus protection software since 15 March 2022, a warning now placed under section 13 of the BSI Act following the amendment of 6 December 2025; the BSI states that it has made no assessment of other Kaspersky products and that use of them is not prohibited in Germany. In the United States, the Department of Commerce issued a Final Determination in June 2024 prohibiting Kaspersky cybersecurity and anti-virus products, effective 20 July 2024 with signature updates ending 29 September 2024, and that determination expressly excludes Kaspersky threat intelligence, security training and advisory services that are purely informational or educational in nature, which is the category this subscription belongs to. Switzerland has issued neither a warning nor a ban: BACS has stated that no misuse of Kaspersky software has been reported to it in Switzerland and that it warns only where it holds confirmed technical indications. Kaspersky rejects the BSI warning as politically rather than technically grounded, refers to its data processing in Zurich under its Global Transparency Initiative, and in early 2026 formally demanded removal of the warning under section 13 of the BSI Act, reserving legal steps. Published comparative laboratory tests cover Kaspersky’s endpoint products rather than these data feeds, so they carry little weight either way for this product. In practice the assessments matter most if you sell into the public sector, hold contracts with German federal bodies, or answer supply chain questionnaires that ask about vendor country of origin, because there the vendor name can decide the outcome regardless of the technical content of the feed; for a private company with no such exposure, no legal restriction applies in Switzerland.
Yes, but for a narrow set of items only. It answers directly whether you use commercial threat intelligence and from which source, whether indicators are matched against your log data, and how current that indicator data is. It answers partly, if you run CyberTrace, which feeds actually generate detections, because feed usage statistics and the feed intersection matrix show the hit rate per source. It does not answer anything about endpoint protection coverage, patch levels, laptop encryption, multi-factor authentication, access control, backup and recovery testing, awareness training, or a documented incident response process, because the feeds are data rather than controls and a reviewer will score them that way. To close those gaps, moving up within one endpoint vendor’s own family is usually cheaper and produces fewer contradictions in the questionnaire than adding a second security vendor, since most questionnaire items concern endpoint and identity controls rather than intelligence sources.
The decisive difference is which indicator types you receive: all five bundles contain the four URL feeds, and each step up adds a new category rather than more of the same data. URL and IP adds IP reputation, URL and IP and Hashes adds file hashes, Expert Security adds APT, crimeware and mobile indicators, and Total Security adds passive DNS, Suricata rules, open source software threats, IoT URLs and vulnerability data. In practice your tooling sets the level: a firewall or proxy can only use URL and IP data, while hash and YARA feeds need a SIEM or threat intelligence platform behind them. Only Total Security includes the Vulnerability Data Feed, which is the single bundle-level fact that changes how you can answer a vulnerability handling question.
| Feeds inside the bundle | URL | URL & IP | URL, IP & Hashes | Expert Security | Total Security |
|---|---|---|---|---|---|
| Malicious, phishing, ransomware, botnet C&C URLs | ✓ | ✓ | ✓ | ✓ | ✓ |
| IP reputation | ✕ | ✓ | ✓ | ✓ | ✓ |
| Malicious hashes | ✕ | ✕ | ✓ | ✓ | ✓ |
| APT and crimeware indicators, YARA rules | ✕ | ✕ | ✕ | ✓ | ✓ |
| Mobile malicious hash and mobile botnet | ✕ | ✕ | ✕ | ✓ | ✓ |
| Passive DNS, Suricata rules, open source threats, IoT URL | ✕ | ✕ | ✕ | ✕ | ✓ |
| Vulnerability Data Feed | ✕ | ✕ | ✕ | ✕ | ✓ |
The feeds are text only: Kaspersky supplies indicators and your own tools perform the matching, so nothing is detected or blocked unless you already run a SIEM, firewall, proxy or threat intelligence platform able to consume them. No feature is restricted to particular countries, but the vendor’s origin effectively is, because several governments restrict Kaspersky products in public sector procurement, which makes this a procurement question before it is a technical one. The licence covers use for your own infrastructure and your own employees, so passing the indicator data on, reselling it, or building it into a service you offer to your own customers is not included. The most frequent follow-up purchase is the next bundle level up, usually when a firewall-only deployment gains a SIEM and suddenly needs hash data; the second is analyst time, because indicator feeds raise alert volume before they reduce it.
Connectors for HP ArcSight, IBM QRadar and Splunk are included with the subscription. If you use Kaspersky CyberTrace as the matching layer, it additionally offers out-of-the-box integration with LogRhythm, RSA NetWitness and McAfee ESM, plus direct integration with firewalls, gateways and other log sources.
No. The feeds can be pulled directly into a SIEM, firewall or threat intelligence platform in JSON, CSV, OpenIoC or STIX over HTTPS or TAXII. CyberTrace, previously named Kaspersky Threat Feed Service, is free and performs the matching outside the SIEM, which is mainly worth it when indicator volume is pushing your SIEM licence or its event rate.
CyberTrace supports multi-tenancy, so one instance can keep several customer environments separate and use different feeds per tenant. The feed licence itself, however, permits use for your own infrastructure and employees, and distributing or reselling the data to third parties is excluded, so a service provider arrangement has to be agreed with Kaspersky separately.
Kaspersky supplies documentation and feed samples along with a dedicated technical account manager for the integration. Running the samples through your parser first is the practical way to confirm that the record fields and context you actually want are usable in your environment.