Working with indicators

Kaspersky CyberTrace uses the Elasticsearch database to store the indicators of compromise (IOC) from the threat intelligence feeds. This database is contained in the Kaspersky CyberTrace distribution package.

On the Kaspersky CyberTrace web user interface you can select the Indicators page. To access this page, you need to switch to the Data management mode.

This page allows you to do the following:

FalsePositive and InternalTI suppliers

The FalsePositive and InternalTI suppliers are built-in Kaspersky CyberTrace suppliers that you can add indicators to:

The InternalTI supplier indicators will have detections even if an indicator is from the false positives list.

In this section

Viewing indicators

Adding indicators to Internal TI list

Managing the Internal TI list

Deleting indicators

Searching for indicators in the table with indicators

Managing search requests

Browsing detailed information about indicators

Exporting indicators to CSV

URL normalization rules

Page top