KasperskyThreat Intelligence

    Threat Intelligence Network Security Data Feeds

    Enrich your existing NGFW with Kaspersky IOC feeds — one link, under 30 minutes.

    Kaspersky Network Security Data Feeds empower your Next-Generation Firewall with real-time, vetted threat data to detect and block malicious activity more efficiently — without complex integration or costly upgrades. A single link in the firewall’s settings regularly uploads fresh lists of malicious, botnet, and phishing IPs and URLs. Most of the IOCs are unique and not detected by the NGFW vendor, closing blind spots. Faltrox configures and maintains it.

    Overview

    What Threat Intelligence Network Security Data Feeds is

    Vendor threat data feeds are the most-used intelligence source (80.5% of respondents in the SANS 2024 CTI survey), and the fastest way to raise an NGFW’s detection rate is to enrich it with vetted external intelligence. Kaspersky Network Security Data Feeds do exactly that, giving your firewall visibility into the blind spots its own vendor feed misses.

    It delivers three feeds — malicious/botnet/phishing URLs, the equivalent IPs, and a web-filtering feed of legitimate categorised domains — that upload via a single link in the firewall’s settings panel. Deployment takes under 30 minutes with no ongoing maintenance, and in practice detects one to three malicious connections a month (with spikes in high-risk environments) and blocks up to 30 otherwise-undetected threats weekly. It works with Cisco Firepower, FortiGate, Palo Alto, Check Point, Sophos, and Edge SWG. Faltrox sets it up and keeps it current.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Malicious URLs

    A feed of malicious, botnet, and phishing URLs uploaded straight into the firewall.

    02

    Malicious IPs

    The equivalent IP feed blocks connections to malware, botnet, and phishing infrastructure.

    03

    Web Filtering

    A web-filtering feed of legitimate categorised domains supports policy and reduces false blocks.

    04

    NGFW Blind Spots

    Most IOCs are unique to Kaspersky and not detected by the NGFW vendor, closing coverage gaps.

    05

    Existing Firewalls

    Works with Cisco Firepower, FortiGate, Palo Alto, Check Point, Sophos, and Edge SWG.

    06

    High-Risk Regions

    Coverage spans highly targeted regions, government entities, and critical infrastructure.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Collect

      Kaspersky gathers IOCs from 100M+ sensors, honeypots, spam traps, expert detection systems, partners, and OSINT.

    2. 02

      Vet

      Indicators are analysed by AI and human experts to produce reliable, low-false-positive threat intelligence.

    3. 03

      Connect

      A single link is added to the firewall’s settings panel — deployment takes under 30 minutes with no ongoing maintenance.

    4. 04

      Update

      The firewall regularly uploads fresh lists of malicious IPs and URLs automatically, staying current in real time.

    5. 05

      Block

      The NGFW blocks connections matching the feeds, catching threats its own vendor feed would miss.

    Capabilities

    Key capabilities

    Network Security URLs Feed

    Real-time feed of malicious, botnet, and phishing URLs for direct NGFW enrichment.

    Network Security IPs Feed

    The matching IP feed blocks traffic to malware, botnet, and phishing infrastructure.

    Web Filtering Data Feed

    A feed of legitimate categorised domains supports web-filtering policy and reduces false positives.

    Sub-30-Minute Deployment

    A single link in the firewall settings enables the feed in under 30 minutes with no ongoing maintenance.

    Unique Coverage

    Most Kaspersky IOCs are unique and undetected by the NGFW vendor, giving visibility into blind spots.

    Broad NGFW Support

    Works with Cisco Firepower, FortiGate, Palo Alto, Check Point, Sophos, and Edge SWG (ProxySG).

    No Costly Upgrades

    Raises detection rate without complex integration or hardware upgrades to the firewall.

    Global Sensor Reach

    Built from an infrastructure of 100M+ sensors across 200 countries, analysed by AI and human experts.

    Works with

    Part of the platform

    Kaspersky products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Kaspersky Threat Intelligence Network Security Data Feeds for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01Do we need a complex integration to use it?

    No — that is the point. A single link in the firewall’s settings panel is all it takes; deployment takes under 30 minutes with no ongoing maintenance required. It enriches your existing NGFW rather than replacing or upgrading it.

    02Which firewalls does it support?

    Cisco Firepower (6.2.3+ with the Threat Intelligence Director module), FortiGate (FortiOS 6.0+), Palo Alto, Check Point (Gaia R81.20 Titan+), Sophos (SFOS v21+), and Edge SWG/ProxySG — across a wide range of models.

    03Will it duplicate what our firewall already blocks?

    Largely no — most of the IOCs in Kaspersky feeds are unique and not detected by the NGFW vendor, so they provide visibility into blind spots. In practice this blocks up to 30 otherwise-undetected threats weekly in typical environments.

    04How does it stay current?

    The firewall regularly uploads fresh lists of IOCs from the feed automatically, so it stays current in real time without manual updates — drawing on Kaspersky’s 100M+ sensor infrastructure.

    05What does Faltrox handle?

    We configure the feed link on your firewall, validate the coverage against your environment, and monitor its effectiveness — a quick, low-maintenance enrichment we manage as part of your network defence.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us