KasperskyThreat Intelligence

    Threat Intelligence Portfolio

    Tactical, operational, and strategic intelligence from a world-leading research team.

    Kaspersky Threat Intelligence gives you a comprehensive view of the global threat landscape — combining intelligence sources, threat data feeds, and in-house research, all analysed by the researchers trusted by INTERPOL and leading CERTs. It spans tactical, operational, and strategic intelligence: data feeds, Threat Lookup, CyberTrace, threat analysis and attribution, reporting, digital footprint, takedown, and Ask the Analyst. Faltrox operationalises it into your defence.

    Overview

    What Threat Intelligence Portfolio is

    Adversaries use complicated kill chains, campaigns, and customised TTPs, so effective protection now requires intelligence — not just detection. Kaspersky Threat Intelligence delivers actionable insight across three levels: tactical (perishable IOCs that support SOC operations and incident response), operational (campaigns, TTPs, and actor attribution for L3 and IR analysts), and strategic (trends, motivations, and classifications for CISOs and boards).

    The portfolio combines Threat Data Feeds, Threat Lookup, and CyberTrace for detection and triage; Threat Analysis (Research Sandbox, Attribution Engine, Similarity) for investigation; and Threat Intelligence Reporting (APT, Crimeware, ICS), Digital Footprint Intelligence, Takedown Service, and Ask the Analyst for response and strategy. It is all available through the Threat Intelligence Portal, drawing on 100M+ sensors, tracking 1,100+ threat actors, and releasing 200+ reports a year. Faltrox selects and operates the components that matter for your organisation.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Global Threat Landscape

    A 360° view built from 100M+ sensors across 200 countries and world-class human research.

    02

    IOCs & Indicators

    Deep, validated context on URLs, domains, IPs, hashes, and threat names via Threat Lookup.

    03

    Threat Actors & APTs

    Tracking of 1,100+ threat actors and campaigns with attribution and 200+ reports a year.

    04

    Your Digital Footprint

    Visibility into your external attack surface, data leaks, and dark-web chatter about you.

    05

    Suspicious Files

    Research Sandbox, Attribution Engine, and Similarity analyse and attribute suspicious samples.

    06

    Compliance & Strategy

    Strategic intelligence and reporting support risk assessment, compliance, and board decisions.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Collect

      Data is gathered from trusted sources — the Kaspersky Security Network, crawlers, botnet monitoring, spam traps, research groups, and partners.

    2. 02

      Refine

      Everything is checked and cleaned in real time using sandboxing, statistical and heuristic analysis, similarity tools, behavioural profiling, and expert analysis.

    3. 03

      Enrich

      Feeds and lookups add contextual data — threat names, hashes, TTPs mapped to MITRE ATT&CK, geolocation — to confirm and prioritise threats.

    4. 04

      Investigate

      Threat Analysis tools sandbox, attribute, and find similarity for suspicious files, shortening response from months to minutes.

    5. 05

      Act

      Reporting, Digital Footprint, Takedown, and Ask the Analyst turn intelligence into strategy, mitigation, and response.

    Capabilities

    Key capabilities

    Threat Data Feeds

    Real-time IOC feeds on malicious IPs, URLs, and hashes integrate into SIEM, SOAR, and TIP to automate initial triage.

    Threat Lookup

    A web and RESTful-API service returning detailed, validated context on any URL, domain, IP, hash, or threat name.

    CyberTrace

    A threat intelligence platform that integrates any feed with SIEM, deduplicates indicators, and reduces SIEM load.

    Research Sandbox

    Cutting-edge dynamic analysis with anti-evasion and human-simulation to find zero-days, mapped to MITRE ATT&CK.

    Attribution Engine

    Links a suspicious file to known APT actors and campaigns using a 25-year genotype database, cutting IR time from months to minutes.

    Intelligence Reporting

    APT, Crimeware, and ICS reporting tracks with actor profiles, IOCs, and YARA/Sigma/Suricata rules mapped to ATT&CK.

    Ask the Analyst

    On-demand access to Kaspersky researchers for guidance on specific threats, malware, dark-web activity, or vulnerabilities.

    Takedown Service

    End-to-end managed takedown of malicious and phishing domains, delivered globally through law-enforcement and CERT partners.

    Works with

    Part of the platform

    Kaspersky products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Kaspersky Threat Intelligence Portfolio for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01What is the difference between tactical, operational, and strategic intelligence?

    Tactical is perishable, low-level data (IOCs) that supports SOC operations and incident response. Operational covers campaigns, TTPs, and actor attribution for senior and IR analysts. Strategic covers trends, motivations, and classifications to support CISO and board decisions on risk and resourcing. The portfolio delivers all three.

    02Do we take the whole portfolio or specific parts?

    Specific parts. The portfolio is modular — feeds, Threat Lookup, CyberTrace, reporting, digital footprint, takedown, Ask the Analyst — and Faltrox selects the components that match your maturity and needs rather than defaulting to everything.

    03Can it integrate with our existing tools?

    Yes. Data feeds and lookups integrate with leading SIEMs (ArcSight, QRadar, MS Sentinel, Splunk) and TI platforms, and outputs export in STIX, OpenIOC, JSON, YARA, Snort, and CSV — so intelligence flows into the controls you already run.

    04How current and broad is the intelligence?

    It draws on an infrastructure of 100M+ sensors across 200 countries, tracks 1,100+ threat actors and campaigns, and releases 200+ private reports a year — including coverage of high-risk regions, government entities, and critical infrastructure.

    05How does Faltrox use it for us?

    We select the right components, integrate the feeds and lookups into your SIEM and SOC workflow, apply the reporting and digital-footprint findings to your defence, and use Ask the Analyst and Takedown where they add value — operationalising the intelligence rather than handing you a portal.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us