What are the core benefits of Kaspersky Threat Data Feeds?
No console – Feeds run inside your existing SIEM tools.
25+ feeds – URL, IP, hash, APT and vulnerability indicators.
Fast updates – URL feeds refresh every 10 to 20 minutes.
Open formats – JSON, CSV, STIX and OpenIoC over HTTPS.
Context included – Threat names, geolocation, timestamps and popularity data.
Important note – No endpoint protection; matching needs your own tools.
Download: Kaspersky Threat Data Feeds
Network indicator feeds – Malicious, phishing and botnet C&C URLs with masks and hosts.
IP reputation feed – Suspicious and malicious IP addresses with threat context.
Malicious hash feeds – File hashes covering Windows, Linux, macOS, Android and iOS.
APT and Crimeware IOC – Hash, URL, IP and YARA indicators from Kaspersky research.
Specialist data feeds – Passive DNS, IoT URLs, Suricata rules, vulnerability and open source data.
Important – No agent, no console; your tools do the matching and blocking.
Kaspersky Threat Data Feeds is a subscription to machine-readable indicator lists that you download over HTTPS and load into your own SIEM, firewall or threat intelligence platform. Kaspersky documentation also refers to the same service as Kaspersky Threat Intelligence Data Feeds, and the matching tool that goes with it, Kaspersky CyberTrace, was previously called Kaspersky Threat Feed Service.
Faster alert triage – Context on each record shows which alerts deserve escalation.
Lower SIEM load – CyberTrace matches events externally instead of inside the SIEM.
Blocklists for firewalls – Dynamic deny lists feed NGFW, proxy and mail gateways.
Vendor neutral formats – JSON, CSV, STIX and OpenIoC avoid tool lock-in.
Ready made connectors – QRadar, ArcSight, Splunk, MISP, Sentinel and Suricata are supported.
Nothing leaves your network – Kaspersky supplies text only; matching happens on your side.
The deciding factor is not headcount but whether someone in your organisation already operates a SIEM, a threat intelligence platform or a next generation firewall with dynamic deny lists. Without one of those, the feeds have nothing to match against and produce no output at all.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | Often |
| NIS 2 in the European Union | Rarely | By sector | Often |
| Security questionnaire from large customers | Sometimes | Often | ✓ |
| SIEM, TIP or NGFW already in operation | ✕ | Partial | ✓ |
| This product fits | ✕ | Limited | ✓ |
The reporting obligation under the revised Information Security Act applies to operators of critical infrastructure, among them energy and drinking water utilities, transport companies, listed hospitals, cloud and data centre providers, and cantonal and communal administrations. Since 1 April 2025 these organisations must report a qualifying cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further 14 days to complete the report. Kaspersky Threat Data Feeds supports that deadline in one specific way: each record carries context such as the threat name, timestamps, resolved IP addresses and geolocation, which is the material an analyst needs to describe what was observed and when. It does not detect the incident for you, it produces no incident timeline, no forensic evidence and no report form, and it stores no case history, so the report itself is still assembled from your SIEM, your endpoint tooling or an incident response provider. It also covers none of the organisational duties, such as naming responsible persons or maintaining an escalation process. This text is not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal advisers.
No software product makes an organisation compliant with the NIS 2 Directive, because the directive addresses management responsibility and processes rather than tooling. NIS 2 requires essential and important entities to put in place risk analysis and security policies, incident handling, business continuity and crisis management, supply chain security, vulnerability handling and disclosure, procedures to assess the effectiveness of measures, cyber hygiene and training, cryptography, access control, asset management and multi-factor authentication. Kaspersky Threat Data Feeds contributes to three of those categories: incident handling, through indicator matching and alert prioritisation; vulnerability handling, through the Vulnerability Data Feed; and supply chain security, through the Open Source Software Threats Data Feed used inside a build pipeline. It contributes nothing to access control, multi-factor authentication, cryptography, business continuity, backup, staff training, asset inventory or policy documentation, and it protects no endpoint, server or mailbox. Treat it as one input to a detection process that must already exist.
Two official measures are relevant and both are still in force. Germany's Federal Office for Information Security (BSI) has warned against the use of Kaspersky antivirus software since 15 March 2022 and recommends replacing it with alternative products; following the German NIS 2 implementation act that took effect on 6 December 2025, the warning is now issued under Section 13 BSIG. The BSI states that the warning concerns the antivirus software portfolio and that it has made no statement about other products in the range. In the United States, the Department of Commerce (BIS) issued a Final Determination on 20 June 2024 prohibiting Kaspersky from providing antivirus and cybersecurity products or services to US persons, with the full effect from 29 September 2024; that determination expressly does not apply to Kaspersky Threat Intelligence products and services, Kaspersky Security Training, or consulting and advisory services that are purely informational or educational in nature. Kaspersky's own position is that the BSI warning is not justified and was not based on a technical analysis of its software, and it points to its Global Transparency Initiative, under which threat-related data from European users has been processed in two Zurich data centres since November 2018 and source code reviews are offered at its Transparency Centres. Practically, this matters most to public sector buyers, defence and critical infrastructure suppliers, and any company whose customers impose country-of-origin rules on security vendors; a private Swiss company with no such contractual requirements is affected differently from a cantonal administration. One technical detail belongs in this decision: the feeds are text files that you download, and Kaspersky states that matching must be performed by your own tools, so no software from the vendor runs on your systems and no telemetry is returned to Kaspersky through this product.
Partly, and only in the detection section. It gives you a documented answer to questions such as whether you subscribe to commercial threat intelligence, whether indicators of compromise are matched against your log data, whether you monitor open source components used in development, and whether you receive structured vulnerability information. The feed usage statistics in CyberTrace also let you show which sources actually produced detections, which is more convincing than naming a supplier. It answers none of the following, and questionnaires ask about all of them: endpoint and server protection, EDR or managed detection, patch management, disk encryption, multi-factor authentication, privileged access control, backup and restore testing, log retention periods, awareness training, an incident response retainer, and certification against ISO 27001 or similar. Be aware that many enterprise and public sector questionnaires now include a vendor origin or authority warning question, which this product does not remove; see the section above. The cheapest route to closing the technical gaps is usually to stay in one family rather than mixing vendors, so pair the feeds with a Kaspersky Next tier for endpoint and EDR coverage and with CyberTrace or a SIEM for the matching layer, instead of buying a second intelligence subscription.
The single decisive difference is that the URL Bundle only tells you about dangerous web addresses, while the Total Security Feeds Bundle adds file-level and adversary-level intelligence. Kaspersky publishes five bundles: URL, URL & IP, URL & IP & Hashes, Expert Security and Total Security. The Expert Security bundle is the point at which APT, Crimeware and mobile threat indicators appear, and the Total Security bundle adds passive DNS, Suricata rules, IoT URLs, vulnerability data and open source threat data on top. If your use case is a firewall or proxy deny list, the URL Bundle is sufficient; if your use case is SOC investigation and attribution, the lower bundles will leave you without hashes and YARA rules. The table below compares three of the five.
| Feeds inside the bundle | URL | URL + IP + Hashes | Total Security |
|---|---|---|---|
| Malicious, phishing, ransomware and botnet C&C URL | ✓ | ✓ | ✓ |
| IP reputation | ✕ | ✓ | ✓ |
| Malicious hashes | ✕ | ✓ | ✓ |
| APT and Crimeware IOC, including YARA | ✕ | ✕ | ✓ |
| Mobile malicious hash and mobile botnet | ✕ | ✕ | ✓ |
| Passive DNS, Suricata rules, IoT URL, vulnerability, open source | ✕ | ✕ | ✓ |
The most common cause of a follow-up purchase is the matching layer: the feeds are raw indicator files, and something has to compare them against your logs. Kaspersky CyberTrace exists in a free community version for this, but the paid edition adds the research graph, indicator database and multi-tenancy that service providers usually end up needing. On regional availability, the US prohibition issued by the Department of Commerce excludes Kaspersky Threat Intelligence products from its scope, but Kaspersky wound down its US operations from July 2024, so US-based entities of an international group should confirm supply before standardising on the feeds; the German BSI warning applies to the antivirus portfolio and is a procurement question rather than a technical one in Switzerland and most of the European Union. Feed coverage is uneven across bundles, and the indicators that investigators most often want, APT and Crimeware hashes with YARA rules, sit in the two highest bundles only. Finally, update intervals differ per feed rather than being uniformly real time: URL feeds refresh roughly every 10 to 20 minutes, botnet C&C and vulnerability data hourly, and open source threat data every few hours.
No. The feeds contain no protection engine, install nothing on a workstation or server, and block nothing by themselves. They supply indicators to security controls you already run, so an endpoint or EDR product remains a separate purchase.
Not strictly. Any tool that can consume JSON, CSV, STIX or OpenIoC will work, including QRadar, ArcSight, Splunk, Azure Sentinel, MISP, ThreatConnect, EclecticIQ and Suricata. CyberTrace is Kaspersky's own matching engine and is worth considering mainly because it performs the correlation outside the SIEM, which keeps event licence consumption and indexing load down.
Kaspersky states that it supplies text-based feeds only and that threat matching is performed by the customer's own tools. The data flow is a one-way download over HTTPS, so your log data and detection results stay inside your infrastructure.