What are the core benefits of Kaspersky Threat Data Feeds Malicious URL?
No console – Data feed only, your tools perform matching.
URL masks – Covers malicious links and web resources with context.
SIEM integration – Ready-made connectors for QRadar, Splunk and Sentinel.
Open formats – JSON output, convertible to STIX, CSV or Snort.
Blocklist ready – Dynamic deny lists for next generation firewalls.
Important note – No scanning engine or endpoint protection included.
Malicious URL masks – URL masks covering malicious websites and web pages.
Actionable context – Threat names, timestamps, geolocation, resolved IP addresses, popularity.
JSON delivery – Enterprise feeds output JSON, retrieved over TAXII with token.
Format conversion tool – Converts JSON to STIX, OpenIoC, Snort, CSV, plain text.
Out-of-the-box integrations – QRadar, ArcSight, Splunk, Sentinel, MISP, Suricata and more.
Important – No agent, no console, no matching engine is included.
Kaspersky Threat Data Feeds Malicious URL is a subscription to one indicator feed from the Kaspersky Threat Data Feeds portfolio, which Kaspersky documentation also lists under the name Kaspersky Threat Intelligence Data Feeds. There is no console and no agent: you point your SIEM, firewall, web gateway or threat intelligence platform at the feed, and your own tools carry out the matching.
Earlier detection – Kaspersky states feed indicators appear before comparable OSINT sources.
Lower SIEM load – CyberTrace matches events locally instead of inside your SIEM.
Automatic blocking – Dynamically updated deny lists feed next generation firewalls directly.
Faster alert triage – Context lets analysts rank alerts without opening separate lookups.
Vendor neutral data – Text only feed, no Kaspersky software on your systems.
Portfolio expansion – The portfolio holds over 25 feeds using identical delivery.
The decisive question is not headcount but whether you already run a system that can consume indicators. Without a SIEM, a threat intelligence platform, a next generation firewall or a secure web gateway, the feed has nothing to match against and delivers no value.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rare | By sector | Often |
| NIS 2 in the European Union | Out of scope | By sector | In scope |
| Security questionnaire from large customers | Occasionally | Often | Standard |
| SIEM or threat intelligence platform in operation | ✕ | Partial | ✓ |
| This product fits | ✕ | Partial | ✓ |
The reporting obligation introduced by the revised Information Security Act applies to operators of critical infrastructure, among them energy and drinking water suppliers, transport companies, listed hospitals, cloud and data centre providers, and cantonal and communal administrations, with exemptions for smaller organisations set out in the Cybersecurity Ordinance. Since 1 April 2025 those organisations must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, and complete the report within a further 14 days. The feed supports this deadline in one narrow way: matching proxy, firewall and mail gateway logs against known malicious URLs shortens the time between the first suspicious connection and the moment someone can say what was contacted, which is exactly the information a 24-hour initial report needs. It does not cover the rest of the obligation, because it detects nothing on the endpoint itself, produces no incident record, has no case management, and cannot generate the report. You still need a SIEM or an incident process to turn a feed match into a documented finding, and a protection product on the affected system to establish what actually executed. This text is not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal counsel.
No product creates compliance with the NIS 2 Directive, because the directive addresses organisational risk management rather than any single tool. NIS 2 requires categories of measures including risk analysis, incident handling, business continuity, supply chain security, security in the acquisition and maintenance of network and information systems, cyber hygiene and training, and access control. This feed maps to a narrow slice of incident handling, specifically the detection and enrichment step, by supplying indicators that a SIEM or gateway can match against live traffic. It contributes nothing to business continuity, access control, training, or governance, and it is not a supply chain security measure in itself. Buyers assessing NIS 2 readiness should treat the feed as an input to a detection process that must already exist, not as a measure that closes a requirement.
Two official measures are relevant and both are still in force. In March 2022 the German Federal Office for Information Security (BSI) issued a public warning against the use of Kaspersky antivirus software, reasoning that antivirus software holds deep intervention rights and therefore requires trust in the manufacturer; the warning is now regulated under Section 13 BSIG and the BSI confirmed in early 2026 that it maintains it. In June 2024 the US Department of Commerce issued a Final Determination prohibiting Kaspersky from supplying antivirus software and cybersecurity products in the United States, with resale and integration by US persons prohibited from 29 September 2024. One detail matters directly for this product: the US determination explicitly excludes Kaspersky Threat Intelligence products and services from the prohibition, and Kaspersky stated at the time that the decision does not affect its ability to sell threat intelligence offerings in the United States. Kaspersky's own position is that these measures reflect the geopolitical situation rather than a technical evaluation of its products. Switzerland has taken no comparable step: BACS does not issue recommendations on individual products and has stated that no misuse of Kaspersky software has been reported to it. Practically, this affects buyers in public sector procurement, buyers with US group entities, and buyers whose large customers exclude Russian-origin suppliers by contract. A technical distinction is worth noting when you assess it: the BSI warning concerns software installed on your systems, whereas this product is a text-based indicator feed with matching performed by your own tools, so the deployment model the warning is built on does not apply in the same way.
Partly, and only on a small number of items. It gives you a documented answer to questions about the use of external threat intelligence, about indicator sources feeding your monitoring, and about automated blocking of known malicious destinations at the perimeter, because you can name a commercial feed, its update cadence and the control it feeds. It answers nothing on endpoint protection, patch status, encryption, backup, access control, logging retention, incident response procedures or supplier governance, and it produces no report you can attach as evidence, since it emits indicators rather than findings. There is a second, less obvious gap: some questionnaires ask for the country of origin of security suppliers, and a Russian-origin vendor will trigger a follow-up question regardless of the product type, so plan for that answer rather than being surprised by it. To close the technical gaps, adding further feeds from the same Kaspersky Threat Data Feeds portfolio is usually cheaper than adding a second intelligence vendor, because delivery, format and integration stay identical; the reporting and endpoint gaps, however, need a protection product and a SIEM, not more feeds.
The decisive difference is the indicator format and therefore what your tooling has to be capable of. This product, the mask-based feed, ships URL masks and is designed for matching through Kaspersky CyberTrace or through network traffic analysis in a next generation firewall or gateway. The Exact variant ships exact URLs, hosts and domains, and exists precisely for the case where masks and the CyberTrace matching engine cannot be used, such as direct import into a SIEM or a third-party threat intelligence platform. If your platform can only ingest literal indicators, the mask feed will underperform and the Exact feed is the correct purchase.
| Property | Malicious URL Data Feed | Malicious URL Exact Data Feed |
|---|---|---|
| Indicator format | URL masks | Exact URLs and hosts |
| Matching engine needed | ✓ | ✕ |
| Designed for CyberTrace | ✓ | Not required |
| Direct import into a TIP | Limited | ✓ |
| Typical placement | Firewall and NTA | SIEM and gateways |
This is not a protection product and cannot block anything on its own: it is a list of indicators, and every detection or block happens inside equipment you already own and operate. The mask format is the most common source of disappointment, because platforms that only accept literal URLs will not match masks correctly and need the Exact variant instead. On regional availability, the feed itself is not region-limited in the way vendors sometimes restrict features to the United States and United Kingdom, but the surrounding legal position differs by market: the US prohibition on Kaspersky cybersecurity software does not extend to threat intelligence products, while the German BSI warning against Kaspersky antivirus software remains in force, so buyers with US or German group entities should confirm internal policy before purchase rather than after. Finally, demo feeds exist but deliver lower detection rates than the commercial version, so a demo evaluation will understate real coverage.
Not strictly, but the mask-based feed is designed around it. CyberTrace performs the parsing and matching outside your SIEM and forwards only confirmed hits with context, which is the intended way to use masks; a next generation firewall or gateway doing network traffic analysis can also consume them. Platforms that cannot handle masks need the Exact variant instead.
Kaspersky provides demo feeds for a number of its data feeds, and demo access to the TAXII server is available to registered users of the Threat Intelligence Portal with a dedicated token. Demo feeds have lower detection rates than their commercial counterparts, so treat them as an integration test rather than a coverage test.