KasperskyThreat Intelligence

    Threat Intelligence CyberTrace

    A threat intelligence platform that offloads IOC matching from your SIEM.

    Kaspersky CyberTrace integrates threat data feeds with your SIEM so analysts can use intelligence in their existing workflow without drowning the SIEM in indicators. It matches incoming logs against feeds, generates its own detection alerts, and deduplicates indicators across suppliers — significantly reducing SIEM load. It works with any feed (Kaspersky, other vendors, OSINT, or your own) in JSON, STIX, XML, and CSV. Faltrox deploys and tunes it.

    Overview

    What Threat Intelligence CyberTrace is

    The growth in threat data feeds and sources makes it hard to know what is relevant, and the sheer number of indicators is hard for SIEMs and network controls to digest. CyberTrace solves both: it integrates up-to-the-minute machine-readable intelligence with existing controls so a SOC can automate initial triage while giving analysts enough context to identify what needs escalation.

    It parses incoming logs and events, rapidly matches them against feeds, and generates its own threat-detection alerts — offloading correlation work from the SIEM. It integrates any feed from any source in JSON, STIX, XML, or CSV with out-of-the-box SIEM support, deduplicates indicators across suppliers, and provides a Research Graph, feed-effectiveness statistics, IOC tagging, historical correlation (retroscan), and multitenancy for MSSPs. Faltrox operates it as the intelligence layer in front of your SIEM.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Any Threat Feed

    Integrates Kaspersky, other vendor, OSINT, and custom feeds in JSON, STIX, XML, and CSV.

    02

    SIEM Log Sources

    Out-of-the-box integration with numerous SIEM solutions and log sources.

    03

    IOC Overload

    Deduplicates indicators across suppliers and offloads matching so the SIEM is not overwhelmed.

    04

    Historical Events

    Retroscan re-checks previously seen observables against the latest feeds to surface missed threats.

    05

    MSSP Multitenancy

    Multitenancy supports MSSPs and large enterprises with multiple isolated tenants.

    06

    Feed Effectiveness

    Usage statistics and an intersection matrix reveal which suppliers deliver the most value.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Aggregate

      The SIEM aggregates event logs from network devices and IT systems and forwards them to CyberTrace.

    2. 02

      Match

      CyberTrace rapidly matches the incoming events against integrated feeds — offloading this work from the SIEM.

    3. 03

      Detect

      It generates its own detection events for matched indicators, enriched with deduplicated context from all suppliers.

    4. 04

      Prioritise

      IOC tagging and weighting let analysts sort and filter, and the Research Graph explores commonalities between detections.

    5. 05

      Return

      Detection events flow back to the SIEM and the CyberTrace web console for the analyst to investigate with full context.

    Capabilities

    Key capabilities

    Feed-Agnostic Integration

    Integrates any threat intelligence feed — Kaspersky, vendor, OSINT, or custom — in JSON, STIX, XML, and CSV.

    SIEM Load Reduction

    Parses logs and matches against feeds itself, sending only detection events to the SIEM and reducing its workload.

    Indicator Deduplication

    Presents all information about an indicator from every supplier on one page, so analysts see the full picture without duplication.

    Research Graph

    Visually explores data and detections stored in CyberTrace to discover threat commonalities.

    IOC Tagging

    Create weighted tags to mark, sort, and filter indicators by importance for streamlined management.

    Historical Correlation

    Retroscan analyses previously checked events against the latest feeds to find threats discovered only later.

    Feed Effectiveness Stats

    Usage statistics and a feed intersection matrix help choose the most valuable intelligence suppliers.

    Multitenancy & API

    Supports MSSP and large-enterprise multitenancy, with an HTTP REST API to look up and manage intelligence.

    Works with

    Part of the platform

    Kaspersky products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Kaspersky Threat Intelligence CyberTrace for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01How does CyberTrace reduce SIEM load?

    Instead of pushing every indicator into the SIEM for matching, CyberTrace parses the logs and performs the matching itself, then sends only the resulting detection events to the SIEM. That offloads the heavy correlation work and reduces load on both the SIEM and the analysts.

    02Does it only work with Kaspersky feeds?

    No — it is feed-agnostic. It integrates any threat intelligence feed from Kaspersky, other vendors, OSINT, or your own custom feeds, in JSON, STIX, XML, and CSV, with out-of-the-box support for numerous SIEMs and log sources.

    03What is retroscan?

    Historical correlation — it re-analyses observables from previously checked events using the latest feeds, so a threat that was unknown when an event first occurred is surfaced once intelligence catches up. It finds the breaches that were invisible at the time.

    04Is it suitable for an MSSP?

    Yes. Multitenancy supports MSSP and large-enterprise use cases with isolated tenants, and feed-effectiveness statistics help demonstrate and optimise the value of the intelligence delivered.

    05How does Faltrox operate it?

    We deploy CyberTrace in front of your SIEM, integrate the right feeds, tune tagging and weighting, and run the detection and prioritisation workflow — so your SOC gets intelligence-driven triage without the SIEM overload.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us