What are the key advantages of Kaspersky Threat Data Feeds Malicious Hashes?
No console – The feed runs inside your existing security tools.
Hash coverage – MD5 plus optional SHA1 and SHA256.
Extra context – Threat name, first seen, popularity, MITRE tactics.
Format support – JSON, CSV, OpenIoC and STIX over HTTPS.
Ready connectors – QRadar, Splunk, Azure Sentinel, ArcSight, Suricata.
Important note – No agent, no console, no blocking included.
Malicious file hashes – MD5 per record, with optional SHA1 and SHA256.
Threat context – Kaspersky threat name, file type, file size, common filenames.
Timing and spread – First seen, last seen and a five-level popularity index.
Attack mapping – MITRE ATT&CK tactic and technique pairs per object.
Distribution data – Top ten hosting IP addresses and download URLs.
Important – No console, no agent and no blocking on its own.
Kaspersky Threat Data Feeds Malicious Hashes is a threat intelligence subscription, not a protection product: it delivers a continuously updated set of malicious file hashes with context that your own SIEM, firewall or gateway consumes. Kaspersky also markets the same catalogue as Kaspersky Threat Intelligence Data Feeds, and the feed itself is documented as Malicious Hash Data Feed, so both names refer to this data set.
Faster alert triage – Analysts see the threat name instead of an unknown hash.
Fewer false positives – Indicators are filtered against a large legitimate-file database.
Near real-time updates – New records arrive without waiting for OSINT publication.
Reuse of existing tools – No new platform, the feed enters your current stack.
Free matching engine – Kaspersky CyberTrace Community Edition matches feeds at no cost.
Retrospective hunting – Old file hashes can be rechecked against newer feed records.
This feed only produces value if something in your infrastructure already collects file hashes from logs or network traffic and can match them. Without a SIEM, a next generation firewall or a mail and web gateway that ingests indicator lists, there is nothing to feed the data into.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | ✓ |
| NIS 2 in the European Union | Rarely | By sector | ✓ |
| Security questionnaire from large customers | Rarely | Often | ✓ |
| SIEM, NGFW or gateway able to ingest indicators | ✕ | Partial | ✓ |
| This product fits | ✕ | Limited | ✓ |
In Switzerland the reporting obligation under the revised Information Security Act applies to operators of critical infrastructure, not to every company, so most SMEs are not directly affected. Affected operators must report a significant cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. Within that window the feed helps in one specific way: a file hash pulled from your logs can be resolved to a Kaspersky threat name, a first seen date and MITRE ATT&CK tactics, which is exactly the substance a first report needs instead of the phrase unknown binary. What the feed does not do is detect the file, produce the log in the first place, keep an incident record or submit anything to BACS; those come from your endpoint protection, your log management and your own process. It also covers no mobile or ICS objects, so an operator with those environments still has a gap. This text is not legal advice; whether your organisation falls under the reporting obligation should be clarified with a qualified adviser.
No product creates NIS 2 compliance, because the directive addresses organisational risk management rather than a shopping list of tools. NIS 2 requires measure categories including risk analysis and security policies, incident handling, business continuity, supply chain security, security in acquisition and development, cryptography and access control, basic cyber hygiene and staff training. This feed contributes to one of them, incident handling, by shortening the step between a suspicious file hash and a named, dated and classified threat. It does not contribute to continuity planning, cryptography, access control, training or policy documentation, and it produces no audit evidence by itself since it is a data set rather than a reporting system. Supply chain security is only partially served here, because software supply chain indicators sit in the separate Open Source Software Threats Data Feed.
Two official measures are in force. The German Federal Office for Information Security issued a warning against Kaspersky antivirus software on 15 March 2022; it remains active and is now regulated under Section 13 of the German BSI Act following the amendment that took effect on 6 December 2025. In the United States, the Bureau of Industry and Security prohibited new Kaspersky sales from 20 July 2024 and the delivery of updates from 29 September 2024, and added Kaspersky entities to the Entity List. Kaspersky states that these decisions rest on the company's country of origin rather than on a published technical finding about its products, and it has publicly pressed for the German warning to be withdrawn. Switzerland has taken no equivalent step: BACS has issued neither a warning nor a ban, and the products are sold and updated normally in Switzerland, the European Union and the United Kingdom. In practice this matters most if you sell into German or other European public-sector contracts, if you have United States operations, or if a large customer's supplier questionnaire asks about vendors of Russian origin. For a private Swiss company with no public-sector exposure, no restriction applies.
Partly, and only for a narrow set of items. It answers questions on whether you subscribe to commercial threat intelligence, whether indicators of compromise are matched against your log data, in which formats intelligence is consumed, and how quickly new indicators reach your controls. It answers nothing about endpoint protection, patch management, encryption, multi-factor authentication, backup and restore, log retention periods, access control or awareness training, and it produces no certificate or attestation you can attach. It also gives no evidence of coverage for mobile devices or industrial systems. If a questionnaire exposes gaps beyond hash matching, the cheaper route is usually to widen within the same family, for example adding IP Reputation, URL or Vulnerability feeds, or moving to a broader Kaspersky Threat Intelligence subscription, rather than mixing feed vendors and then having to reconcile different context formats.
The decisive difference is scope of objects, and the feeds do not overlap: buying malicious hashes alone leaves mobile and industrial systems uncovered. Malicious Hash Data Feed targets prevalent and emerging malware on desktop and server files, Mobile Malicious Hash Data Feed covers objects infecting Android and iPhone devices, and ICS Hash Data Feed covers files used against industrial control systems and the IT systems integrated into them. All three share the same record structure, so no separate parsing work is needed if you add one later. Kaspersky also publishes demo versions of these feeds, which carry a lower detection rate than the commercial versions and are intended for evaluation rather than production.
| Property | Malicious Hash | Mobile Malicious Hash | ICS Hash |
|---|---|---|---|
| Objects covered | Prevalent malware | Mobile malware | ICS malware |
| Platforms | Desktop and server | Android and iPhone | ICS and linked IT |
| MD5, SHA1 and SHA256 | ✓ | ✓ | ✓ |
| Popularity index and threat name | ✓ | ✓ | ✓ |
| Included in this listing | ✓ | ✕ | ✕ |
The most important limitation is that this is data, not defence: it detects nothing, blocks nothing and has no console, so it is worthless without a SIEM, next generation firewall or gateway that already ingests indicator lists. Regional availability is restricted in one market, the United States, where the Bureau of Industry and Security prohibition covers new sales and updates; sale and updates in Switzerland, the European Union and the United Kingdom are unaffected. If you match feeds with Kaspersky CyberTrace rather than inside your SIEM, the free Community Edition is capped at 250 events per second and one million records across all intelligence sources, which is the point where follow-up purchases most often become necessary. Matching directly inside a SIEM avoids that licence but typically costs SIEM performance. Finally, hashes only identify files that have already been seen and classified, so this feed adds nothing against a genuinely unique binary built for one target.
No. The feed is a standalone threat intelligence subscription and does not require a Kaspersky endpoint product. It is consumed by whichever SIEM, firewall or gateway you already run, regardless of vendor.
The Malicious Hash Data Feed with extra context is provided in JSON. Across the Kaspersky Threat Data Feeds catalogue, JSON, CSV, OpenIoC and STIX are supported, delivered over HTTPS, TAXII or an agreed alternative mechanism.
Kaspersky publishes ready-made integrations for IBM QRadar, Splunk Enterprise Security, ArcSight ESM, RSA NetWitness, Azure Sentinel, Anomali ThreatStream, ThreatConnect, EclecticIQ, ThreatQ, MISP, Cisco Firepower, Suricata, McAfee Web Gateway and Maltego, plus a REST API for anything not on that list.
Records are aggregated from Kaspersky Security Network telemetry contributed by over 400 million voluntary participants, web crawlers, botnet research, spam traps, honeypots and sinkholes, passive DNS from hosting providers and ISPs, OSINT and vendor partnerships. Each indicator passes automated screening and sandbox analysis before release.
keys.express and keys.discount are online platforms for product keys. The product keys available in our shops for Windows and other software are inexpensive, secure, legal and come with an activation guarantee.
Below you will find the most important legal information about our products.
We offer exclusively unused and non-activated product keys. The keys have never been redeemed for activation and are fully available to the purchaser for the first-time activation of the respective product. A key that has already been redeemed could no longer be used for a new activation and is therefore not offered by us.
Trading in these product keys is permissible in the European Union and in Switzerland under current case law, provided that the necessary conditions are met. These conditions are as follows:
This trade is legally permissible because the underlying license was already placed on the market with the consent of the rightholder within the EU/EEA or Switzerland in return for appropriate remuneration. As a result, the so-called principle of exhaustion has taken effect, which permits the resale of individual product keys — in particular those originating from volume license agreements. Microsoft or the respective software provider has already received appropriate remuneration for this.
keys.express and keys.discount ensure that the aforementioned conditions are met and that the lawful use of the software is guaranteed. The requirements arising from European legislation are also observed in Switzerland.
Important note: The acquisition of a product key through the transmission of a combination of numbers and letters in digital form does not, in itself, constitute a license for the lawful use of the program. The license only arises from the respective installation and the associated acceptance of the manufacturer's terms of use.
Further information can be found here: