Connect with us

Hi, what are you looking for?

HEADLINES

New Kaspersky CyberTrace streamlines threat intelligence flows for better initial response to cyberthreats

If IoC from threat intelligence feeds are found in any log source within an organization’s environment, Kaspersky CyberTrace automatically sends alerts to SIEMs for ongoing monitoring and validation to reveal additional contextual evidence for the security incidents.

With the number of available threat intelligence sources continuing to grow, a third of Chief Information Security Officers (CISOs) feel under pressure as they cannot consume cybercrime intelligence easily or effectively. To help large companies overcome this challenge, Kaspersky Lab has launched Kaspersky CyberTrace –– a free threat intelligence fusion and analysis tool. It aggregates and evaluates disconnected data feeds to help identify what threats pose a danger to the organization and ensure security teams focus on the right areas.

The variety of threat intelligence sources available on the market doesn’t always translate into protection from cyberattacks, as organizations struggle to decide which are relevant and most important for them.  Security information and event management (SIEM) or network security controls get overloaded with a large number of Indicators of Compromise (IoC), and the fact that threat data is provided in different formats only worsens the situation.

To make it easier for enterprises to keep up to date with the latest threats, Kaspersky CyberTrace retrieves continuously updated threat data feeds from multiple threat intelligence sources – including Kaspersky Lab, other vendors, open source intelligence or even custom sources – and automatically and rapidly matches them with incoming security events, offloading SIEMs from this high-load operation.

If IoC from threat intelligence feeds are found in any log source within an organization’s environment, Kaspersky CyberTrace automatically sends alerts to SIEMs for ongoing monitoring and validation to reveal additional contextual evidence for the security incidents. The tool integrates smoothly with a variety of SIEMs, including IBM QRadar, Splunk, ArcSight ESM, LogRhythm, RSA NetWitness, and McAfee ESM, as well as other security controls such as firewalls and gateways.  

Kaspersky CyberTrace helps prioritize tasks by giving analysts a set of instruments for conducting alert triage and response through categorization and validation of identified matches. On-demand lookup of indicators or scanning of logs and files enables advanced in-depth threat investigation, which accelerates forensic and threat hunting activities. The tool also provides feed usage statistics to measure the effectiveness of feeds and their relevance for a certain environment.

Advertisement. Scroll to continue reading.

“Being aware of the most relevant zero-days, emerging threats and advanced attack vectors is key to an effective cybersecurity strategy. However, manually collecting, analyzing and sharing threat data doesn’t provide the level of responsiveness required by an enterprise. There’s a need for a centralized point for accessible data sources and task automation. Kaspersky CyberTrace helps organizations better understand their risks, increase the productivity of their security teams and ensure a more robust protection against cyberthreats,” said Sergey Martsynkyan, Head of B2B Product Marketing at Kaspersky Lab.

Kaspersky CyberTrace is available for customers for free globally and can be downloaded here.

Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

HEADLINES

Maya has already integrated National ID eVerify, the Philippine Statistics Authority’s identity-verification service, into its onboarding process. Since early this year, eligible customers have been...

HEADLINES

In 2025 alone, Converge denied nearly 12 billion entry requests to websites hosting dangerous, inappropriate, and harmful content that attempted to pass through its...

HEADLINES

The announcement represents one of the first major third-party technology integrations following the launch of Sophos Fusion, demonstrating Sophos' commitment to an open ecosystem...

HEADLINES

APAC consumers are more concerned about digital tech usage for crime than consumers globally (35% vs 32%). The awareness is highest in Thailand (39%),...

HEADLINES

“It is the time for Radenta to demonstrate that it is strongly committed to protecting client data,” remarks Nereo Bolante, Co-Director, Radenta Ethics, Compliance, and Governance Team...

HEADLINES

Attackers are operationalizing artificial intelligence (AI) to collapse attack workflows from weeks to days. The report finds that AI’s most immediate impact on cybercrime...

HEADLINES

The prominence of identity attacks in ransomware indicates a shift in method, as attackers increasingly recognize identity as a key component in ransomware delivery....

HEADLINES

Password guessing and valid account misuse rank among the most effective tactics used by cyber criminals in 2025. This trend reflects a strategic shift,...

Advertisement