How to integrate Kaspersky Threat Intelligence Portal with Splunk Phantom

 

Kaspersky Threat Data Feeds

 
 
 
 

How to integrate Kaspersky Threat Intelligence Portal with Splunk Phantom

Back to article list
Latest update: September 04, 2019 ID: 15266
 
 
 
 

Kaspersky Threat Intelligence Portal for Splunk Phantom is a Splunk Phantom app that allows you to look up threat intelligence information about IP addresses, URLs, domains, and hashes on Kaspersky Threat Intelligence Portal, and gives you access to Kaspersky Advanced Persistent Threat (APT) Intelligence reports within Phantom UI or as a steps in Phantom Playbooks.

Kaspersky application for Phantom has the following features:

  • Looking up indicators: IP addresses, URLs, domains, and hashes
  • Receiving Kaspersky APT Intelligence reports that contain information about high profile cyber-espionage campaigns
  • Receiving detailed information about indicators

For more information about the application (functionality, features) read its documentation (online HTML-format).

For documentation, refer to Online Help.

To download the application, click this link.

 
 
 
 
Was this information helpful?
Yes No
Thank you
 
 
 

 
 

How can we improve this article?

Your feedback will be used for content improvement purposes only. If you need assistance, please contact technical support.

Submit Submit

Thank you for your feedback!

Your suggestions will help improve this article.

OK