What are the key advantages of Kaspersky Threat Data Feeds IoT URL?
Feed subscription – Text data only, no console or agent.
IoT coverage – URL masks for malware infecting IoT devices.
Context fields – Protocol, port, popularity, geography and file hashes.
Format choice – JSON, CSV, OpenIoC and STIX are supported.
SIEM integration – Delivered over HTTPS or TAXII to your tools.
Important note – No blocking; your own tools perform matching.
Download: Kaspersky Threat Data Feeds IoT URL
IoT URL records – URL masks covering sites that distribute IoT malware.
Threat context – Threat type, download protocol and destination port per record.
Timing and popularity – First seen and last seen dates plus usage frequency.
Geographic data – Top 100 attack source countries and IP addresses.
Related file hashes – Names and hashes of files launched from each URL.
Important – No console, no agent and no blocking function.
Kaspersky Threat Data Feeds IoT URL is one feed from the Kaspersky Threat Intelligence portfolio, delivered as machine-readable text rather than as installed software, so it has no management console and no endpoint agent. Kaspersky markets the same intelligence to device manufacturers under the name Kaspersky IoT Threat Data Feed, which is the term many buyers still search for.
Honeypot sourcing – Traps simulating unprotected IoT devices collect the samples.
Near real-time updates – Records are generated automatically and delivered continuously.
Four delivery formats – JSON, CSV, OpenIoC and STIX over HTTPS or TAXII.
Existing tool reuse – Works with SIEM, NGFW, proxy and IDS platforms.
Perimeter deny lists – Supplies gateways and firewalls with high-trust indicators.
Alert prioritisation – Context shortens triage of network alerts in SOC work.
The deciding factor is not headcount but whether you already run a system that can match indicators against your own network events. A company without a SIEM, next generation firewall or threat intelligence platform has nothing to load this feed into, so the subscription produces no detections at all.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | ✓ |
| NIS 2 in the European Union | ✕ | By sector | ✓ |
| Security questionnaire from large customers | Rare | ✓ | ✓ |
| Own SIEM, NGFW or TIP to match indicators | ✕ | Partial | ✓ |
| This product fits | ✕ | Partial | ✓ |
The Swiss reporting obligation applies to operators of critical infrastructure named in the revised Information Security Act, not to companies in general, so most SMEs are not directly affected. Since 1 April 2025 those operators must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further 14 days to complete the report. The feed supports that deadline in one narrow way: when an infected router or camera has contacted a known distribution URL, the record supplies the protocol, the port, the first seen and last seen dates and the hashes of the files served, which is the kind of detail an initial report needs and which otherwise has to be reconstructed by hand under time pressure. What the feed does not do is detect the incident on its own, retain logs, produce reporting evidence, or block anything, and the 24-hour clock starts from your own detection, which depends entirely on the tools consuming the feed. Nothing in this product creates or discharges a reporting obligation. This is not legal advice, and whether your organisation falls under the reporting obligation should be clarified with qualified legal counsel.
No product makes a company compliant with the NIS 2 Directive, because the directive addresses organisational measures and processes rather than software features. NIS 2 requires entities within its scope to take measures covering risk analysis and information system security policies, incident handling, business continuity and crisis management, supply chain security, security in acquisition and development, and procedures for assessing whether those measures work. This feed contributes to incident handling and to detection only, by giving network security controls indicators that recognise IoT malware infrastructure, and to a lesser degree to the assessment of measures, because match rates over time show whether perimeter filtering is working. It contributes nothing to business continuity, crisis management, supply chain security, secure development, access control, staff training or asset inventory, and it produces no governance documentation of any kind. Whether an organisation falls within the directive's scope is determined by sector and size, so the first question for a buyer is whether the obligation applies at all.
On 20 June 2024 the United States Department of Commerce, through its Bureau of Industry and Security, issued a Final Determination prohibiting Kaspersky from supplying anti-virus software and cybersecurity products and services to US persons, with resale, integration and licensing prohibited from 29 September 2024. The determination expressly excludes Kaspersky Threat Intelligence products and services from the prohibition, and this feed belongs to that category. Separately, the German Federal Office for Information Security has warned against the use of Kaspersky virus protection software since 15 March 2022; that warning remains in force, and the authority states that it made no statements about other products in the Kaspersky portfolio. Kaspersky rejects the German warning as not based on an objective technical analysis, denies ties to the Russian government, and points out that its feeds are delivered as text only, with all matching performed by the customer's own tools rather than by Kaspersky software running inside the customer network. In practice this matters most for public sector tenders, for organisations whose large customers exclude the vendor by name rather than by product, and for groups with US entities or US-person staff, since the US prohibition reaches US persons worldwide. The distinction between installed protection software and a text-based intelligence feed is the point on which most of these assessments turn, and it is worth putting in writing before a procurement discussion.
Partly, and only on a small number of items. It gives you a concrete answer to questions about external threat intelligence sources, about enrichment of security monitoring with indicators of compromise, and about detection of connections to known malicious infrastructure, because you can name the source, the delivery format and the systems that consume it. It answers nothing about endpoint protection, patch levels, encryption, backup, access control, staff awareness training, incident response procedures, log retention periods or vendor risk management, and it produces no report you can attach as evidence, since the reporting comes from whichever SIEM or firewall ingests the data. It also does not by itself demonstrate that IoT and OT devices on your network are inventoried, which is a common follow-up question once you claim IoT threat coverage. Where these gaps need closing, adding further feeds from the same Kaspersky Threat Intelligence portfolio or moving to a platform that both stores and reports on matches is usually cheaper and easier to document than combining several vendors, because one supplier assessment then covers the whole intelligence layer.
The decisive difference is scope: the IoT URL feed covers only web resources used to download malware that infects IoT devices such as routers, IP cameras and similar embedded hardware, while the Malicious URL feed covers malicious web resources generally and is not device specific. Both are supplied as URL masks and both are intended for the same integration points, so they are complementary rather than alternatives. For the Malicious URL feed, Kaspersky also offers an exact-URL variant; no equivalent exact variant is listed for the IoT feed. If your concern is unmanaged devices on branch or production networks, the IoT feed is the targeted choice; if you want broad web threat coverage for user traffic, it is the wrong feed on its own.
| Property | IoT URL Data Feed | Malicious URL Data Feed |
|---|---|---|
| Threat focus | IoT malware downloads | Malicious web resources |
| Device specific | ✓ | ✕ |
| Indicator form | URL masks | URL masks |
| Exact-URL variant available | ✕ | ✓ |
| Integration into SIEM, NGFW, gateways | ✓ | ✓ |
This is data, not protection: Kaspersky supplies text-based feeds and the matching against your network events has to be performed by your own tools, so the subscription produces nothing without a SIEM, next generation firewall, proxy or threat intelligence platform to load it into. The most common follow-up cost is the matching layer itself, because the free Community Edition of Kaspersky CyberTrace cannot be used with commercial data feeds and is capped at 250 events per second and one million loaded records; a licence key is required for use with commercial feeds or in an enterprise network, though a SIEM with suitable built-in capabilities can consume the feed without CyberTrace at all. On regional availability, the US prohibition on Kaspersky cybersecurity and anti-virus products applies to US persons worldwide, including foreign branches of US-organised entities, but Kaspersky Threat Intelligence products and services are excluded from it, which is the relevant carve-out for this feed and worth confirming with your own counsel for any group structure that touches the United States. The feed also covers only URLs used to distribute IoT malware; it does not cover vulnerabilities in IoT or industrial devices, which are separate feeds, and it does not protect, patch or manage the devices themselves.
No. It covers URLs used to download malware onto IoT devices. Vulnerability information is supplied by separate feeds in the same portfolio, the Vulnerability Data Feed and the ICS Vulnerability Data Feed.
Yes. Kaspersky states that its Threat Data Feeds can also be handled by a SIEM using its own built-in capabilities. CyberTrace is one way to reduce SIEM load, not a requirement.
Kaspersky uses honeypots and other traps that simulate unprotected IoT devices, alongside its own research and analysis systems, and screens each indicator through automated filtering and sandbox analysis before release.
keys.express and keys.discount are online platforms for product keys. The product keys available in our shops for Windows and other software are inexpensive, secure, legal and come with an activation guarantee.
Below you will find the most important legal information about our products.
We offer exclusively unused and non-activated product keys. The keys have never been redeemed for activation and are fully available to the purchaser for the first-time activation of the respective product. A key that has already been redeemed could no longer be used for a new activation and is therefore not offered by us.
Trading in these product keys is permissible in the European Union and in Switzerland under current case law, provided that the necessary conditions are met. These conditions are as follows:
This trade is legally permissible because the underlying license was already placed on the market with the consent of the rightholder within the EU/EEA or Switzerland in return for appropriate remuneration. As a result, the so-called principle of exhaustion has taken effect, which permits the resale of individual product keys — in particular those originating from volume license agreements. Microsoft or the respective software provider has already received appropriate remuneration for this.
keys.express and keys.discount ensure that the aforementioned conditions are met and that the lawful use of the software is guaranteed. The requirements arising from European legislation are also observed in Switzerland.
Important note: The acquisition of a product key through the transmission of a combination of numbers and letters in digital form does not, in itself, constitute a license for the lawful use of the program. The license only arises from the respective installation and the associated acceptance of the manufacturer's terms of use.
Further information can be found here: