Threat Intelligence CyberTrace
A threat intelligence platform that offloads IOC matching from your SIEM.
Kaspersky CyberTrace integrates threat data feeds with your SIEM so analysts can use intelligence in their existing workflow without drowning the SIEM in indicators. It matches incoming logs against feeds, generates its own detection alerts, and deduplicates indicators across suppliers — significantly reducing SIEM load. It works with any feed (Kaspersky, other vendors, OSINT, or your own) in JSON, STIX, XML, and CSV. Faltrox deploys and tunes it.
Overview
What Threat Intelligence CyberTrace is
The growth in threat data feeds and sources makes it hard to know what is relevant, and the sheer number of indicators is hard for SIEMs and network controls to digest. CyberTrace solves both: it integrates up-to-the-minute machine-readable intelligence with existing controls so a SOC can automate initial triage while giving analysts enough context to identify what needs escalation.
It parses incoming logs and events, rapidly matches them against feeds, and generates its own threat-detection alerts — offloading correlation work from the SIEM. It integrates any feed from any source in JSON, STIX, XML, or CSV with out-of-the-box SIEM support, deduplicates indicators across suppliers, and provides a Research Graph, feed-effectiveness statistics, IOC tagging, historical correlation (retroscan), and multitenancy for MSSPs. Faltrox operates it as the intelligence layer in front of your SIEM.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Any Threat Feed
Integrates Kaspersky, other vendor, OSINT, and custom feeds in JSON, STIX, XML, and CSV.
SIEM Log Sources
Out-of-the-box integration with numerous SIEM solutions and log sources.
IOC Overload
Deduplicates indicators across suppliers and offloads matching so the SIEM is not overwhelmed.
Historical Events
Retroscan re-checks previously seen observables against the latest feeds to surface missed threats.
MSSP Multitenancy
Multitenancy supports MSSPs and large enterprises with multiple isolated tenants.
Feed Effectiveness
Usage statistics and an intersection matrix reveal which suppliers deliver the most value.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Aggregate
The SIEM aggregates event logs from network devices and IT systems and forwards them to CyberTrace.
- 02
Match
CyberTrace rapidly matches the incoming events against integrated feeds — offloading this work from the SIEM.
- 03
Detect
It generates its own detection events for matched indicators, enriched with deduplicated context from all suppliers.
- 04
Prioritise
IOC tagging and weighting let analysts sort and filter, and the Research Graph explores commonalities between detections.
- 05
Return
Detection events flow back to the SIEM and the CyberTrace web console for the analyst to investigate with full context.
Capabilities
Key capabilities
Feed-Agnostic Integration
Integrates any threat intelligence feed — Kaspersky, vendor, OSINT, or custom — in JSON, STIX, XML, and CSV.
SIEM Load Reduction
Parses logs and matches against feeds itself, sending only detection events to the SIEM and reducing its workload.
Indicator Deduplication
Presents all information about an indicator from every supplier on one page, so analysts see the full picture without duplication.
Research Graph
Visually explores data and detections stored in CyberTrace to discover threat commonalities.
IOC Tagging
Create weighted tags to mark, sort, and filter indicators by importance for streamlined management.
Historical Correlation
Retroscan analyses previously checked events against the latest feeds to find threats discovered only later.
Feed Effectiveness Stats
Usage statistics and a feed intersection matrix help choose the most valuable intelligence suppliers.
Multitenancy & API
Supports MSSP and large-enterprise multitenancy, with an HTTP REST API to look up and manage intelligence.
Works with
Part of the platform
Kaspersky products this pairs with, and the Faltrox services that operate it.
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Kaspersky Threat Intelligence CyberTrace for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01How does CyberTrace reduce SIEM load?
Instead of pushing every indicator into the SIEM for matching, CyberTrace parses the logs and performs the matching itself, then sends only the resulting detection events to the SIEM. That offloads the heavy correlation work and reduces load on both the SIEM and the analysts.
02Does it only work with Kaspersky feeds?
No — it is feed-agnostic. It integrates any threat intelligence feed from Kaspersky, other vendors, OSINT, or your own custom feeds, in JSON, STIX, XML, and CSV, with out-of-the-box support for numerous SIEMs and log sources.
03What is retroscan?
Historical correlation — it re-analyses observables from previously checked events using the latest feeds, so a threat that was unknown when an event first occurred is surfaced once intelligence catches up. It finds the breaches that were invisible at the time.
04Is it suitable for an MSSP?
Yes. Multitenancy supports MSSP and large-enterprise use cases with isolated tenants, and feed-effectiveness statistics help demonstrate and optimise the value of the intelligence delivered.
05How does Faltrox operate it?
We deploy CyberTrace in front of your SIEM, integrate the right feeds, tune tagging and weighting, and run the detection and prioritisation workflow — so your SOC gets intelligence-driven triage without the SIEM overload.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us