What are the key advantages of Kaspersky Threat Data Feeds Transforms for Maltego?
Standalone tool – No central console, one analyst workstation.
Maltego add-on – Requires an existing Maltego client and licence.
Indicator enrichment – Verdicts for URLs, domains, IP addresses and hashes.
Graph pivoting – Follow download chains and hosting relationships visually.
Report links – Connects indicators to Kaspersky threat intelligence reports.
Important note – Provides no protection, detection or blocking.
Maltego transform set – Runs inside the Maltego desktop client, no agents installed.
Indicator enrichment – Adds verdicts and context to URLs, domains, IP addresses, hashes.
Relationship pivoting – Follow download chains, hosting and file relations on the graph.
Threat report links – Connects indicators to Kaspersky APT and financial threat reports.
Kaspersky Threat Lookup – Backed by observables Kaspersky has collected for twenty years.
Important – No agents, no console, no blocking; enrichment only.
This is an investigation add-on for the Maltego link-analysis client, documented by the vendor as Kaspersky Transforms for Maltego and sold in retail catalogues under the Threat Data Feeds name. There is no management console and no central policy: each analyst installs the transform set into their own Maltego client, so the management model is standalone per workstation.
Faster triage – Verdicts appear on the graph without switching to a portal.
Visual pivoting – One graph shows the infrastructure behind a single indicator.
Attribution context – Links indicators to named APT and financial crime campaigns.
Fewer tool switches – Replaces manual copy-paste into separate lookup portals during triage.
Known-good filtering – Legitimate object data separates clean files from unknown ones.
No infrastructure – Runs as a service with nothing to host locally.
The deciding factor is not headcount but whether someone in the organisation actually investigates indicators. This product produces no alerts of its own; it answers questions an analyst already has. Without a person who opens a graph and pivots through it, the licence sits unused.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | By sector |
| NIS 2 in the European Union | Rarely | By sector | By sector |
| Security questionnaire from large customers | Occasionally | ✓ | ✓ |
| Own analyst who investigates indicators | ✕ | Limited | ✓ |
| This product fits | ✕ | Limited | ✓ |
The reporting obligation introduced by the revised Information Security Act applies to operators of critical infrastructure, including energy and water supply, transport undertakings, listed hospitals, cloud and data centre providers, and cantonal and communal administrations; it does not apply to most ordinary companies. Affected organisations must report a qualifying cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further period to complete the initial report. Within that first day the reporting team has to describe what was attacked and by what means, and this is the narrow point where the product helps: an analyst can resolve a captured indicator to its hosting infrastructure, its download chain and any known campaign, and put that description into the report. It does not detect the incident, does not retain logs from your own environment, does not preserve evidence, and does not generate or submit the report itself, so on its own it satisfies none of the obligation. The detection and logging that produce a report in the first place must come from other systems. This text describes product capabilities and is not legal advice.
No software product makes an organisation compliant with the NIS 2 Directive, because the directive addresses management responsibility, organisation and process rather than tooling. NIS 2 requires a set of measure categories: risk analysis and information system security policies, incident handling, business continuity and crisis management, supply chain security, security in the acquisition and maintenance of systems, procedures to assess the effectiveness of measures, basic cyber hygiene and training, cryptography, access control and asset management, and multi-factor authentication. This product touches exactly one of them, and only partly: it supports the analysis stage of incident handling by adding external context to indicators an analyst has already collected. It contributes nothing to continuity planning, supply chain assessment, access control, cryptography, multi-factor authentication, asset management, training, or the documented evidence that measures are effective. Buyers evaluating it as a NIS 2 building block should treat it as an aid to one activity within one measure category, not as coverage of that category.
In March 2022 the German Federal Office for Information Security (BSI) issued a public warning against the use of Kaspersky anti-virus software, the first such warning it had ever published against a manufacturer's product segment. The warning remains in force in 2026; the BSI has confirmed it continues to maintain it and refers to the reasons given originally, which concern trust in the manufacturer's reliability and its ability to act independently rather than any specific defect found in the code. Kaspersky rejects the assessment, has publicly demanded that the warning be withdrawn, states that it has suffered substantial commercial damage, and has reserved the right to take legal steps. Separately, the United States prohibited the sale and distribution of Kaspersky products in 2024. Independent laboratory testing such as AV-TEST and AV-Comparatives evaluates Kaspersky detection products and does not assess this intelligence service, so it offers no evidence either way here. In practice this affects buyers in public sector procurement, operators of critical infrastructure, and suppliers whose large customers impose country-of-origin restrictions on vendors; a commercial organisation with no such requirement is not legally prevented from purchasing in Switzerland or the European Union. The decision belongs to the buyer and should be documented alongside any existing supply chain policy.
Partly, and only in one narrow area. It gives a defensible answer to items asking whether you subscribe to commercial threat intelligence beyond free sources, and whether your team can investigate and contextualise an indicator of compromise rather than simply record it. It answers nothing else. Questionnaires routinely ask about deployed endpoint protection, EDR coverage and retention, patching cadence, multi-factor authentication, encryption of laptops and removable media, centralised logging and log retention periods, backup and restore testing, vulnerability scanning, and periodic access reviews, and this product addresses none of them. The gaps sit almost entirely in endpoint protection and detection, which within the same vendor portfolio means the Kaspersky Next product line rather than a second intelligence purchase. Buyers who are subject to public sector procurement rules or customer-imposed vendor restrictions should assume they will need to source that endpoint layer from a different manufacturer, and should plan the questionnaire response around that split from the start rather than discovering it during an audit.
The decisive difference is which dataset answers your query. Demo access resolves transforms against the Kaspersky Open Threat Intelligence Portal, the free public lookup service, while Commercial access resolves them against the full Kaspersky Threat Intelligence Portal built on Threat Lookup. Demo access also caps how many relationship transforms can be run, which makes graph pivoting impractical beyond a short evaluation. Commercial access is what makes the product usable for daily casework, and it is also the level at which indicators can be tied to Kaspersky APT Intelligence and Financial Threat Intelligence reporting.
| Capability | Demo access | Commercial access |
|---|---|---|
| Backing data service | Open Threat Intelligence Portal | Threat Intelligence Portal |
| Relationship and pivot transforms | Capped | ✓ |
| Suitable for daily casework | ✕ | ✓ |
| Available in the United States | ✕ | ✕ |
This is an add-on and not a standalone purchase: it requires a working Maltego client with a valid Maltego licence, and commercial use requires Kaspersky Threat Intelligence Portal access, so a buyer who owns neither is looking at three separate acquisitions rather than one. Regional availability is restricted in a direction that surprises some buyers: Kaspersky products may not be sold or distributed in the United States following the 2024 prohibition, which matters for organisations with American subsidiaries or American parent companies even when the Swiss or European entity is free to purchase. The edition names in the retail title refer to Maltego Classic and Maltego XL, licence editions Maltego stopped selling in 2020 and does not renew, so anyone buying a new Maltego licence today receives a current plan instead and should confirm transform compatibility before ordering. The queries themselves leave your network, which is a genuine consideration when the indicator under investigation is itself sensitive. Finally, this is interactive analyst tooling rather than an automated feed, so it does not push indicators into a SIEM or firewall and will not reduce alert volume on its own.
The transform set is distributed through the Maltego Transform Hub and installs into the Maltego desktop client. Maltego Classic and Maltego XL, named in the retail product title, have not been sold since 2020 and cannot be renewed, although existing keys continue to work until the subscription ends. Buyers starting fresh should confirm with the vendor which current Maltego plan the transforms are supported on before purchasing.
Yes. When a transform runs, the request travels from the Maltego client to the Maltego Transform Distribution Server, then to the Kaspersky service, which queries the Threat Intelligence Portal and returns the result along the same path. Kaspersky encrypts the traffic but states explicitly that it is not responsible for data sent from the Maltego client to the Transform Distribution Server, so teams investigating confidential incidents should treat submitted indicators as disclosed to two external parties.
No, although the retail naming makes them look alike. Machine-readable Threat Data Feeds are a separate offering in the Kaspersky Threat Intelligence portfolio, designed to be ingested continuously by a SIEM or security platform. This product is the interactive Maltego integration: an analyst asks about a specific indicator and gets an answer on a graph. Organisations that want automated correlation across all their logs need the feed subscription instead of, or in addition to, this.