Threat Intelligence Portfolio
Tactical, operational, and strategic intelligence from a world-leading research team.
Kaspersky Threat Intelligence gives you a comprehensive view of the global threat landscape — combining intelligence sources, threat data feeds, and in-house research, all analysed by the researchers trusted by INTERPOL and leading CERTs. It spans tactical, operational, and strategic intelligence: data feeds, Threat Lookup, CyberTrace, threat analysis and attribution, reporting, digital footprint, takedown, and Ask the Analyst. Faltrox operationalises it into your defence.
Overview
What Threat Intelligence Portfolio is
Adversaries use complicated kill chains, campaigns, and customised TTPs, so effective protection now requires intelligence — not just detection. Kaspersky Threat Intelligence delivers actionable insight across three levels: tactical (perishable IOCs that support SOC operations and incident response), operational (campaigns, TTPs, and actor attribution for L3 and IR analysts), and strategic (trends, motivations, and classifications for CISOs and boards).
The portfolio combines Threat Data Feeds, Threat Lookup, and CyberTrace for detection and triage; Threat Analysis (Research Sandbox, Attribution Engine, Similarity) for investigation; and Threat Intelligence Reporting (APT, Crimeware, ICS), Digital Footprint Intelligence, Takedown Service, and Ask the Analyst for response and strategy. It is all available through the Threat Intelligence Portal, drawing on 100M+ sensors, tracking 1,100+ threat actors, and releasing 200+ reports a year. Faltrox selects and operates the components that matter for your organisation.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Global Threat Landscape
A 360° view built from 100M+ sensors across 200 countries and world-class human research.
IOCs & Indicators
Deep, validated context on URLs, domains, IPs, hashes, and threat names via Threat Lookup.
Threat Actors & APTs
Tracking of 1,100+ threat actors and campaigns with attribution and 200+ reports a year.
Your Digital Footprint
Visibility into your external attack surface, data leaks, and dark-web chatter about you.
Suspicious Files
Research Sandbox, Attribution Engine, and Similarity analyse and attribute suspicious samples.
Compliance & Strategy
Strategic intelligence and reporting support risk assessment, compliance, and board decisions.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Collect
Data is gathered from trusted sources — the Kaspersky Security Network, crawlers, botnet monitoring, spam traps, research groups, and partners.
- 02
Refine
Everything is checked and cleaned in real time using sandboxing, statistical and heuristic analysis, similarity tools, behavioural profiling, and expert analysis.
- 03
Enrich
Feeds and lookups add contextual data — threat names, hashes, TTPs mapped to MITRE ATT&CK, geolocation — to confirm and prioritise threats.
- 04
Investigate
Threat Analysis tools sandbox, attribute, and find similarity for suspicious files, shortening response from months to minutes.
- 05
Act
Reporting, Digital Footprint, Takedown, and Ask the Analyst turn intelligence into strategy, mitigation, and response.
Capabilities
Key capabilities
Threat Data Feeds
Real-time IOC feeds on malicious IPs, URLs, and hashes integrate into SIEM, SOAR, and TIP to automate initial triage.
Threat Lookup
A web and RESTful-API service returning detailed, validated context on any URL, domain, IP, hash, or threat name.
CyberTrace
A threat intelligence platform that integrates any feed with SIEM, deduplicates indicators, and reduces SIEM load.
Research Sandbox
Cutting-edge dynamic analysis with anti-evasion and human-simulation to find zero-days, mapped to MITRE ATT&CK.
Attribution Engine
Links a suspicious file to known APT actors and campaigns using a 25-year genotype database, cutting IR time from months to minutes.
Intelligence Reporting
APT, Crimeware, and ICS reporting tracks with actor profiles, IOCs, and YARA/Sigma/Suricata rules mapped to ATT&CK.
Ask the Analyst
On-demand access to Kaspersky researchers for guidance on specific threats, malware, dark-web activity, or vulnerabilities.
Takedown Service
End-to-end managed takedown of malicious and phishing domains, delivered globally through law-enforcement and CERT partners.
Works with
Part of the platform
Kaspersky products this pairs with, and the Faltrox services that operate it.
Kaspersky products
Faltrox services
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Kaspersky Threat Intelligence Portfolio for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01What is the difference between tactical, operational, and strategic intelligence?
Tactical is perishable, low-level data (IOCs) that supports SOC operations and incident response. Operational covers campaigns, TTPs, and actor attribution for senior and IR analysts. Strategic covers trends, motivations, and classifications to support CISO and board decisions on risk and resourcing. The portfolio delivers all three.
02Do we take the whole portfolio or specific parts?
Specific parts. The portfolio is modular — feeds, Threat Lookup, CyberTrace, reporting, digital footprint, takedown, Ask the Analyst — and Faltrox selects the components that match your maturity and needs rather than defaulting to everything.
03Can it integrate with our existing tools?
Yes. Data feeds and lookups integrate with leading SIEMs (ArcSight, QRadar, MS Sentinel, Splunk) and TI platforms, and outputs export in STIX, OpenIOC, JSON, YARA, Snort, and CSV — so intelligence flows into the controls you already run.
04How current and broad is the intelligence?
It draws on an infrastructure of 100M+ sensors across 200 countries, tracks 1,100+ threat actors and campaigns, and releases 200+ private reports a year — including coverage of high-risk regions, government entities, and critical infrastructure.
05How does Faltrox use it for us?
We select the right components, integrate the feeds and lookups into your SIEM and SOC workflow, apply the reporting and digital-footprint findings to your defence, and use Ask the Analyst and Takedown where they add value — operationalising the intelligence rather than handing you a portal.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us