What are the core benefits of Kaspersky Threat Data Feeds Phishing URL?
No console – Data feed managed inside your existing tools.
Phishing indicators – URLs and masks with context for matching.
Open formats – JSON, CSV, OpenIoC and STIX via HTTPS.
SIEM integration – Connectors for QRadar, Splunk and Sentinel.
Rich context – Threat name, popularity, geography and whois data.
Important note – No blocking, your own tools do matching.
Download: Kaspersky Threat Data Feeds Phishing URL
Phishing URL records – URLs, hosts, domains and masks covering confirmed phishing resources.
Actionable context – Threat type, timestamp, popularity index, geography, IP and whois.
Near real-time updates – New records generated continuously from Kaspersky Security Network data.
Open delivery formats – JSON for enterprise, plus conversion to STIX, OpenIoC and CSV.
HTTPS and TAXII – Token-based TAXII access for the most popular feeds.
Important – No management console, no agent and no built-in reporting.
Kaspersky Threat Data Feeds Phishing URL is a machine-readable feed of confirmed phishing URLs and URL masks, published as one of more than 25 feeds in the Kaspersky Threat Intelligence range. It has no console and no agent: you download the data over HTTPS or TAXII and your own SIEM, firewall or gateway performs the matching.
Proxy log matching – Check web and mail logs against confirmed phishing URLs.
Faster alert triage – Context fields answer who, what and where per record.
Lower SIEM load – CyberTrace matches events before they reach the SIEM.
Deny list feed – Dynamically updated block lists for firewalls and gateways.
No telemetry required – Kaspersky supplies text data; matching stays on your systems.
Vendor-neutral integration – Connectors for QRadar, Splunk, Sentinel, MISP and Suricata.
The deciding factor is not headcount but whether you already operate a system that can consume indicators. A company without a SIEM, next generation firewall or web gateway has nowhere to load the feed and gains nothing from it. Organisations that run a security operations function, or a service provider that does so on their behalf, are the realistic buyers.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | Often |
| NIS 2 in the European Union | Rarely | By sector | Often |
| Security questionnaire from large customers | Occasionally | Often | Standard |
| SIEM or gateway able to consume indicators | ✕ | Partial | ✓ |
| This product fits | ✕ | Limited | ✓ |
The Swiss reporting obligation does not apply to every company. Since 1 April 2025 the revised Information Security Act obliges operators of critical infrastructure, among them energy and drinking water suppliers, transport companies, listed hospitals, cloud and data centre providers and cantonal and municipal administrations, to report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further 14 days to complete the report. This feed supports that obligation at one point only: the context attached to each record, including threat type, timestamp, popularity index, top affected countries, resolved IP addresses and whois data, gives an analyst material for the initial assessment of whether a phishing hit is relevant enough to escalate. It does not detect the incident on its own, retains no evidence, and generates no report that could be submitted to BACS, because it has no console and no reporting component at all. It also covers phishing indicators only, so an attack arriving through a malicious attachment, a compromised server or stolen credentials will not appear in this feed. This text is not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal advisers.
No product makes a company compliant with the NIS 2 Directive, because the directive addresses organisational measures rather than software. NIS 2 requires essential and important entities to implement risk analysis and information system security policies, incident handling, business continuity, supply chain security, security in acquisition and development, procedures for assessing the effectiveness of measures, cyber hygiene and training, cryptography, access control and multi-factor authentication. This feed contributes to incident handling, by supplying detection tools with confirmed phishing indicators and enough context to triage an alert, and marginally to the assessment of effectiveness, since matches can be counted per intelligence source. It contributes nothing to business continuity, access control, cryptography, multi-factor authentication, staff training or supply chain governance, and it produces no documentation that an auditor could accept as evidence. Treat it as one input into an existing detection stack rather than as a measure in its own right.
Two official measures are in force and both are worth understanding precisely, because neither covers this product in the way buyers often assume. The German Federal Office for Information Security has warned against the use of Kaspersky virus protection software since 15 March 2022; the warning remains in force and has been regulated under Section 13 of the BSI Act since 6 December 2025. In the United States, the Department of Commerce issued a final determination on 20 June 2024 prohibiting new transactions from 20 July 2024 and signature updates, Kaspersky Security Network operation and resale from 29 September 2024 — but that determination expressly excludes Kaspersky Threat Intelligence products and services, which is the category this feed belongs to. Kaspersky rejects both assessments, states that the German warning was not based on an objective technical analysis of its software, and points to third-party audits and its transparency centres, one of which operates in Zurich. In Switzerland the Federal Office for Cybersecurity has issued no warning and no internal directive on Kaspersky products, and has stated that its technical assessment was not changed by the American ban, although Kaspersky software is no longer in use in the federal administration. In practice this matters most for public sector tenders, for companies with a German parent or German public sector customers, and for supply chain questionnaires that ask about the country of origin of security suppliers; for a privately held Swiss company running the feed inside its own SIEM, it is a procurement question rather than a technical one.
Partly, and for a narrow set of items. It gives you a documented answer to questions about which commercial threat intelligence sources you subscribe to, how current your indicators are, how phishing indicators reach your detection tooling, and which integrations carry them, since the feed ships with connectors for QRadar, Splunk Enterprise Security, ArcSight ESM, RSA NetWitness, Azure Sentinel, MISP, Suricata and others. It answers nothing about multi-factor authentication, encryption, patch management, backup and restore testing, access control, incident response procedures, staff awareness training, business continuity or supplier risk management, and it provides no certification such as ISO 27001 or SOC 2. It will also prompt a question you may not have faced before, because many questionnaires now ask for the country of origin of security suppliers. To close the technical gaps, the cheaper route is usually to stay inside the same family, adding endpoint and detection coverage from the Kaspersky Next range and Kaspersky CyberTrace for triage, rather than assembling parts from several vendors; where the origin question is a hard requirement in your customer base, no product choice inside the family will resolve it.
The decisive difference is how records are written and what has to match them. The standard Phishing URL Data Feed uses URL masks, so a single record can cover many related phishing addresses, but masked records need the Kaspersky CyberTrace matching engine to be evaluated correctly. The Phishing URL Exact Data Feed contains exact URLs, hosts and domains instead, and is intended for direct integration into security controls and threat intelligence platforms where masks or CyberTrace cannot be used. Both carry the same context fields. If your SIEM, firewall or platform can only ingest literal indicators, the Exact feed is the one to buy.
| Property | Phishing URL Data Feed | Phishing URL Exact Data Feed |
|---|---|---|
| Record type | URLs and masks | Exact URLs, hosts, domains |
| One record covers several addresses | ✓ | ✕ |
| Needs CyberTrace matching engine | For masks | ✕ |
| Direct import into any TI platform | Partial | ✓ |
| Context fields included | ✓ | ✓ |
This feed blocks nothing on its own. Kaspersky supplies text-based records only and all matching is performed by your tools, so without a SIEM, next generation firewall, proxy or mail gateway to load them into, the data has no effect. The masked records in the standard feed need the Kaspersky CyberTrace matching engine, and the free Community Edition of CyberTrace is capped at 250 events per second and one million loaded indicators across all sources, which the paid edition removes — a follow-up purchase that catches buyers out more often than any other. Coverage is confined to phishing web resources: malicious URLs, ransomware URLs, botnet command and control addresses, file hashes and vulnerabilities are separate feeds in the same range, each bought individually. No regional feature restriction applies to this feed itself, and it sits outside the American prohibition on Kaspersky cybersecurity software, but the German warning and public sector procurement rules described above may still rule the vendor out for some buyers regardless of technical fit.
CyberTrace is available in a free Community Edition, but it processes a maximum of 250 events per second and loads up to one million indicators from all threat intelligence sources combined, and it defaults to demo feeds with lower detection rates. Running commercial feeds such as this one in a production network requires the paid edition, which also adds multi-user and multi-tenancy handling for service providers.
None for the purpose of matching. Your systems download the feed over HTTPS or TAXII and compare it against your own logs locally, so the URLs and events being checked never leave your infrastructure. This is the main structural difference between a data feed and an endpoint product that reports telemetry back to the vendor.
Yes, provided your equipment supports it. The records can be turned into a dynamically updated deny list for a next generation firewall, secure mail gateway or web gateway, or matched through network traffic analysis. The blocking decision and its enforcement remain entirely with your own device.
keys.express and keys.discount are online platforms for product keys. The product keys available in our shops for Windows and other software are inexpensive, secure, legal and come with an activation guarantee.
Below you will find the most important legal information about our products.
We offer exclusively unused and non-activated product keys. The keys have never been redeemed for activation and are fully available to the purchaser for the first-time activation of the respective product. A key that has already been redeemed could no longer be used for a new activation and is therefore not offered by us.
Trading in these product keys is permissible in the European Union and in Switzerland under current case law, provided that the necessary conditions are met. These conditions are as follows:
This trade is legally permissible because the underlying license was already placed on the market with the consent of the rightholder within the EU/EEA or Switzerland in return for appropriate remuneration. As a result, the so-called principle of exhaustion has taken effect, which permits the resale of individual product keys — in particular those originating from volume license agreements. Microsoft or the respective software provider has already received appropriate remuneration for this.
keys.express and keys.discount ensure that the aforementioned conditions are met and that the lawful use of the software is guaranteed. The requirements arising from European legislation are also observed in Switzerland.
Important note: The acquisition of a product key through the transmission of a combination of numbers and letters in digital form does not, in itself, constitute a license for the lawful use of the program. The license only arises from the respective installation and the associated acceptance of the manufacturer's terms of use.
Further information can be found here: